Guide
Automated penetration testing: what it catches and what it misses
Automated penetration testing runs tools that probe your systems for known weaknesses. It is fast and repeatable, but it cannot understand your business logic, so it misses the findings that hurt most.
- Fixed fee before we start
- Named tester in writing
- Retest and attestation letter
What automated penetration testing does well
Tools are tireless. So they are good at broad, repeated checks across many hosts.
- Finding missing patches and known vulnerable versions
- Spotting weak TLS settings and missing headers
- Repeating the same checks every week
- Covering large numbers of hosts quickly
What automated penetration testing misses
A tool does not know that customer A must never see customer B's invoices. Therefore broken access control and business logic flaws usually go unnoticed. Also, tools rarely chain small issues together, while a person does that routinely.
Do you need more than automated penetration testing?
Tick each statement that applies. Two or more usually means a manual test is needed.
Your result appears here as you tick, so you can see what is still open.
Automated or manual: a side-by-side view
Both have a place, but they answer different questions.
| Automated | Manual pentest | |
|---|---|---|
| Speed | Hours. | Three to ten days, because a person tests. |
| Logic flaws | Rarely found. | The main focus, so usually found. |
| False alarms | Common. | Removed, because each finding is reproduced. |
| Audit weight | Often questioned. | Built for auditors and customers. |
When automated penetration testing is enough
It suits continuous hygiene between annual tests. For example, weekly scans of your external hosts catch new exposures early. However, when an auditor or enterprise customer asks for a penetration test, they almost always mean manual work.
Combining automated penetration testing with manual work
Run automated checks continuously, then commission a manual test each year and after major changes. So the tools keep the basics clean, while the person finds what tools cannot.
Automated penetration testing questions
Will auditors accept automated penetration testing?
Rarely on its own, because scan-only reports often fail when an auditor reads them closely.
Is automated testing a waste of money?
No. It is useful for continuous checks, but it is not a substitute for a manual test.
Do you sell automated scans?
No. Our packages are manual tests, although testers use tools for discovery.
What does a very low quote usually mean?
Anything under about $4,000 for a real app is almost certainly automated, so check the manual hours.
Related guides
Need more than automated penetration testing?
Send your scope and we quote a manual test with the hours in writing, so you know exactly what you are buying.
Get my fixed-fee quote