Three products that get sold under one name
Three very different products get sold under the words 'security assessment', and the price difference between them is tenfold. Knowing which one you are buying, and which one you actually need, is the whole game.
A vulnerability scan is automated software that checks your systems against a list of known weaknesses. A security audit is a human review of how your technology and habits are actually configured, backed by evidence. A penetration test is a skilled person actively trying to break in, with your permission. Vendors blur these constantly, sometimes by accident and sometimes because a 400 dollar scan report looks impressive when it's priced at 4,000.
I hold a Security+ certification and do this work for small businesses, so let me lay out what each one really involves.
What a vulnerability scan is, and what it misses
A vulnerability scanner points at your network, your website, or your computers and compares what it finds against a database of known flaws. It is fast, cheap, and genuinely useful. Standalone scanning tools run roughly 100 to 500 dollars a month, and many IT providers bundle scanning into their monthly service.
What a scan gives you: a list of missing patches, outdated software, and exposed services, usually ranked by severity.
What it misses:
- Configuration problems. A scanner can see that your email service exists; it cannot tell you that half your staff has no multi-factor authentication, or that an ex-employee still has admin access.
- Context. Scanners produce false positives and flag issues that don't matter for your setup, so raw reports overwhelm people. A 40-page scan report with no human interpretation mostly produces guilt, not security.
- Process. No scanner knows whether your backups restore, who can wire money on an emailed request, or where the office password spreadsheet lives.
A scan is an ingredient, not a meal.
What a real audit adds
An audit is human work built on top of whatever the tools find. When I audit a small business, the deliverables look like this:
- Configuration review. Someone actually logs into your Microsoft 365 or Google admin panel, your firewall, your website hosting, and checks the settings against good practice: MFA enforcement, admin account count, sharing rules, mail security records.
- Evidence collection. Every finding comes with proof: a screenshot, an export, a setting name. 'Your email security is weak' is an opinion. 'Your domain has no DMARC record, which lets anyone send email as you' is a finding. DMARC is the DNS record that tells other mail servers to reject mail forging your domain.
- Manual validation. The scan's important findings get checked by hand, so you're not chasing false positives.
- A remediation plan. Findings ranked by real risk to your business, with a fix, an owner, and a rough effort estimate for each. The top five items should be doable in days, not quarters.
For a small business, a proper audit typically runs 2,000 to 10,000 dollars depending on how much there is to review. If a quote at that price does not include configuration review and a prioritized fix list, ask what you are paying for.
Where penetration testing fits
A penetration test is a person with attacker skills genuinely trying to get in: guessing passwords, probing your website, sometimes phishing your staff if you've agreed to that scope. Real ones typically start around 5,000 dollars and climb fast.
Honest advice: most small businesses do not need a pen test first. If an audit would find twenty unlocked doors, paying a professional to prove that one of them opens is poor sequencing. Pen tests earn their cost when a customer or regulator requires one, or when you've already done the audit-and-fix cycle and want validation that it worked.
Choosing the right scope for your size
Here is how I'd choose scope by situation:
- Under 10 people, never assessed: skip straight to an audit of identity, email, devices, and backups. This is where nearly all small-business incidents start.
- 10 to 50 people with an IT provider: audit annually with an independent party, not the provider grading its own homework, and run scanning continuously.
- Handling regulated or government-adjacent data: your compliance framework may dictate the scope, so get someone who knows that framework specifically.
- Just been through an incident or a scare: audit first, fix the top findings, then consider a pen test to validate.
What to do next
Practical next steps:
- Ask whoever handles your IT one question: when were our security settings last reviewed by a human, and can I see the evidence? The answer tells you a lot.
- If the answer is vague, get a scoped audit quote covering identity, email, devices, backups, and your website. Get the deliverables in writing: evidence-backed findings plus a prioritized remediation plan.
- Fix the top five findings before spending another dollar on assessment.
- Put scanning on a monthly cadence and the human audit on an annual one.
HashWhales does exactly this kind of scoped audit for DMV small businesses, and the first conversation about what scope you actually need costs nothing.
