forumNew topic

Vulnerability scan is listed in the proposal but I don't get it: what is it, is it enough, or is a pentest mandatory?

NNecati D***MemberCommunity member
Joined
Oct 2023
Message
251
#1

We run an eight-person office in Milan exporting B2B machinery spare parts. We have a small web portal where our clients download technical drawings and place orders. Last week we got an annual infrastructure maintenance proposal from a local IT firm. Among the line items, they put 1,200 EUR per year for a "vulnerability assessment", and as an alternative, they proposed a comprehensive "penetration test" for 4,500 EUR.

I have to admit I'm not very familiar with technical terms. What exactly is this vulnerability scan, what runs in the background? Do they just run automated software and hand over a report, or does an actual expert examine the system?

For a business like ours that doesn't have massive databases or store credit cards, but does host client lists and technical drawings, does this 1,200 EUR scan provide sufficient protection, or would we just be buying into a false sense of security if we skip the pentest?

OOkan I***Member
Job title
Front office accounting
Sector
Cosmetics
Organization type
sole proprietorship
Joined
Nov 2023
Message
260
Most Helpful#2

Short answer: A vulnerability scan is a broad health check that scans and lists known security flaws in your servers and applications using automated tools; a pentest is a human-led simulation that tests whether a real attacker can exploit those flaws and breach your systems. For a B2B portal of your size, a regular vulnerability scan is a great starting point and surfaces most of your core risks without draining your budget.

In a vulnerability scan, software scans your system from the outside or inside, detecting unpatched libraries, forgotten open ports, default passwords, and known configuration mistakes. In the end, you're handed a list of vulnerabilities ranked by severity. However, this scan can't interpret how critical these flaws actually are to your specific business on its own; it just tells you they exist. A pentest, on the other hand, is a time- and labor-intensive process where an expert actively tries to use these vulnerabilities to get their hands on your technical drawings or client data.

For small businesses, the right approach is this: running automated scans quarterly for 1,200 EUR a year and having your sysadmin patch the critical vulnerabilities found is fantastic hygiene. Unless you store highly confidential patented blueprints on your portal or your clients contractually require an independent pentest report, there's no need to spend 4,500 EUR at this stage. Patch the basic holes with vulnerability scans first, and move on to pentesting as your budget and operations grow.

İİbrahim Y***Member
Job title
Marketing manager
Sector
Electrical-electronics
Organization type
20-person company
Joined
Nov 2023
Message
95
#3

Think of a scan like this: a security guard walking around the building checking from the outside whether every door and window is locked is a vulnerability scan. A pentest is them slipping through an unlocked window and trying to crack the safe on the desk. The scan in that quote will likely just check your ports and services against an off-the-shelf database.

PPerihan Y***MemberCommunity member
Joined
Aug 2024
Message
178
#4

We paid 1,100 EUR last year to start vulnerability scanning on our wholesale distribution site in Rome. The first report flagged 34 vulnerabilities, 6 of which were critical and stemmed from an outdated server plugin. We ran the updates, and by the next quarter, our critical vulnerability count dropped to zero. It was totally worth it for us.

OOnatMember
Job title
Tour Operator
Organization type
medium-sized business
Joined
Mar 2024
Message
112
#5

Before accepting the proposal, ask the firm: "Will you just dump a raw PDF on me after the scan, or does this include an hour of consulting where we sit down with our IT person to prioritize what needs patching?" If they're just going to throw an automated report over the fence and bounce, don't give them that money.

FFerhat E***MemberCommunity member
Joined
Jun 2024
Message
181
#6

Automated vulnerability scans generate a ton of false alarms. They can make even a harmless, minor header misconfiguration look like a high-risk emergency. If you don't have someone on your team who can read that report and sort out what's real from what's noise, you'll be left holding a useless document.

UUğur Y***VeteranCommunity member
Joined
Oct 2024
Message
3
#7

tbh if u dont store card details on the portal a pentest is an unnecessary expense for now... anyway doiing regular scans and keeping up with server updates saves like 90% of small companies anyway.

CCem B***MemberCommunity member
Joined
Jun 2022
Message
316
#8

Under Italian and European Union data protection regulations, you are legally obligated to implement technical measures to safeguard customer commercial data. Conducting regular vulnerability scans and archiving the reports establishes a valid, formal basis proving your proactive security efforts in the event of a data audit.

EEfe A***Member
Job title
System support specialist
Sector
Software
Organization type
8-person team
Joined
Jul 2022
Message
136

Doki · Infrastructure migration · 2025

#9

Do the technical drawings hosted on your portal belong to you, or are they proprietary designs belonging to your clients? If you are storing proprietary designs that constitute trade secrets of your clients, one of those clients might contractually require an annual penetration test; have you reviewed your contracts?

FFilizMember
Job title
Catering company
Organization type
sole proprietorship
Joined
Jun 2024
Message
78
#10

No need to overcomplicate things, just go with the 1,200 EUR package to keep your budget in check but make sure patching the flagged issues is clearly agreed on with the same team. Let them tidy up the system the first year, and if business picks up next year you can look into a pentest.

YYiğit K***Member
Job title
Supply chain manager
Sector
Glass
Organization type
workshop
Joined
Oct 2022
Message
47
#11

This thread is archived.

FFatma G***Member
Job title
Content Editor
Sector
Energy
Organization type
boutique agency
Joined
Aug 2024
Message
21
#12

same here.

AAli G***Member
Job title
Logistics planning
Sector
Electrical-electronics
Organization type
family business
Joined
Jul 2023
Message
1
#13

We experienced almost the exact same thing last year. If permission and scope aren't in writing, don't start that test.

If you post the result here, it will help others too.

MMustafa G***Member
Job title
Co-founder
Sector
Machinery manufacturing
Organization type
boutique agency
Joined
May 2022
Message
155
#14

Do you think this works at any scale? Everyone rushing into what is a vulnerability scan gets stuck at the same point.

If you have questions, write them; I'll answer as best I can.

GGürkan Y***Member
Job title
Store associate
Sector
Plastic
Organization type
cooperative
Joined
Jan 2023
Message
213
#15

Correct.

NNuri N***MemberCommunity member
Joined
Nov 2023
Message
4
#16

Three different views emerged they all complement each other. Don't rely on a single measure; go layer by layer.

If you get three different answers on a topic, the question was asked wrong.

DDoruk K***Expert
Job title
Quality Assurance Manager
Sector
Construction
Organization type
20-person company
Joined
Feb 2024
Message
28
#17

Let me share what happened to me; it might be useful. The biggest time-waster for us was not knowing who had the final say.

If you post the result here, it will help others too.

GGürkan A***MemberCommunity member
Joined
Apr 2022
Message
67
#18

I disagree with you on this point. The harder it is to reverse a decision, the slower you should make it.

Good luck with that.

UUfuk A***ExpertCommunity member
Joined
Dec 2024
Message
410
#19

It's rare to find an explanation this clear.

YYasemin T***New memberCommunity member
Joined
Aug 2026
Message
68
#20

sorry but this doesn't apply in every case.. and anyway mistakes made on the what is a vulnerabilty scan side are usually reversible but expensive.

this is my opinion I'm not claiming it's absolute truth.

Reply