The two halves
Vulnerability Assessment (VA)
A broad, largely automated discovery exercise. Scanners examine your networks, servers and applications against databases of known weaknesses — missing patches, outdated software, weak configurations, exposed services — and produce a ranked list. It answers "what could be wrong?"
Penetration Testing (PT)
A focused, human-led exercise. A tester attempts to exploit those weaknesses the way a real attacker would, chaining minor issues into meaningful compromise and probing business logic that tools cannot understand. It answers "what would actually happen?"
Our VAPT vs vulnerability scanning page covers this distinction in more depth, including how to tell whether you are being sold a genuine test.
What a real engagement includes
| Type | What it covers |
|---|---|
| Network penetration testing | Internal and external testing of firewalls, servers, devices and services |
| Web application testing | Injection, broken authentication, access-control flaws, business logic |
| Wireless testing | Wi-Fi authentication, segregation, rogue access points |
| Configuration review | Firewall rules, server hardening, Active Directory posture |
| Red teaming | Goal-based adversary simulation across people, process and technology |
How an engagement runs
- Scoping — agreeing targets, boundaries, timing and rules of engagement in writing. Nothing proceeds without documented authorisation.
- Reconnaissance — mapping what is actually exposed, which frequently differs from what the client believes.
- Assessment — automated discovery across the agreed scope.
- Exploitation — manual, careful validation of which findings are genuinely exploitable.
- Post-exploitation — determining how far access could extend, without causing disruption.
- Reporting — an executive summary plus technical detail, each finding rated by real business risk with clear remediation steps.
- Retest — verifying that fixes actually worked. An engagement without a retest leaves you guessing.
What a good report looks like
- Prioritised by business impact, not just raw CVSS scores.
- Reproducible — your team can follow the steps to confirm each finding.
- Actionable — specific remediation, not "apply best practice".
- Honest about scope — clear on what was and was not tested.
- Readable by two audiences — management needs risk; engineers need detail.
How often should you test?
A practical baseline is at least annually, plus after any material change: a new application, a cloud migration, a network redesign, a merger, or a significant infrastructure upgrade. Fast-changing or higher-risk environments benefit from more frequent testing, complemented by continuous vulnerability scanning between engagements.
The bottom line
VAPT converts "we think we are secure" into "we tested, and here is the evidence". The assessment finds the weaknesses; the penetration test proves which ones matter. For most businesses it is the most direct way to understand real exposure rather than theoretical risk.