Types of scan
External scans look at systems exposed to the internet, as an attacker would. Internal scans run inside the network and find weaknesses an intruder or insider could use. Authenticated scans log into systems and see far more than unauthenticated ones. Web application scanners focus on websites and APIs.
Scanning vs pentesting
A scan is automated, broad and frequent, and finds known issues. A penetration test is carried out by people, goes deeper, chains weaknesses together and tests what an attacker could actually achieve. They complement each other: scanning keeps a continuous view, pentesting validates it periodically.
From findings to fixes
Scanners often produce long lists, and many findings are not urgent. Prioritising by CVSS score alone leads to wasted effort. Combining severity with exposure, evidence of active exploitation and the importance of the asset gives a short list of what to fix first through patch management. Each finding is a known vulnerability, usually identified by a CVE.
Where it shows up in compliance
ISO 27001 (Annex A 8.8), the ENS, NIS2 and SOC 2 expect regular identification of vulnerabilities. PCI DSS requires quarterly external scans by an approved vendor, as well as internal scans.




