GlossaryAttack surface and pentesting

Vulnerability scanning

Short answer

Vulnerability scanning is the automated process of checking systems, networks and applications for known security weaknesses, such as missing patches, outdated software and insecure configurations. It produces a list of findings, usually rated by severity, that feeds the remediation process.

Types of scan

External scans look at systems exposed to the internet, as an attacker would. Internal scans run inside the network and find weaknesses an intruder or insider could use. Authenticated scans log into systems and see far more than unauthenticated ones. Web application scanners focus on websites and APIs.

Scanning vs pentesting

A scan is automated, broad and frequent, and finds known issues. A penetration test is carried out by people, goes deeper, chains weaknesses together and tests what an attacker could actually achieve. They complement each other: scanning keeps a continuous view, pentesting validates it periodically.

From findings to fixes

Scanners often produce long lists, and many findings are not urgent. Prioritising by CVSS score alone leads to wasted effort. Combining severity with exposure, evidence of active exploitation and the importance of the asset gives a short list of what to fix first through patch management. Each finding is a known vulnerability, usually identified by a CVE.

Where it shows up in compliance

ISO 27001 (Annex A 8.8), the ENS, NIS2 and SOC 2 expect regular identification of vulnerabilities. PCI DSS requires quarterly external scans by an approved vendor, as well as internal scans.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub