A vulnerability scan is an automated check that lists known weaknesses, while a penetration test is a person actually trying to break in. Most small Texas businesses need the scan first, the test later, and a risk assessment in between to decide what matters.
I oversee how Uprite delivers managed IT and security, so I’m the one who hears about it when a customer, an insurer, or a regulator asks for “a test” and nobody in the room knows which kind they actually mean. This guide is for Texas owners and office managers who want to buy the right thing once. It sits inside our wider work on cybersecurity services in Texas, and the team behind our cybersecurity services in Houston follows the same order of operations described below.
The two words get used as if they mean the same thing. They don’t. One is cheap and repeatable. The other is a project with a signed permission letter.
What is the difference between penetration testing and vulnerability scanning?
A vulnerability scan uses software to check your devices and internet-facing systems against lists of known flaws and returns a ranked list. A penetration test uses a skilled person, with written permission, to exploit weaknesses and show how far an attacker could get. The scan finds. The test proves.
NIST draws the same line. Its glossary defines vulnerability scanning as “a technique used to identify hosts/host attributes and associated vulnerabilities,” and describes penetration testing in SP 800-115 as security testing in which evaluators “mimic real-world attacks.” That guide, the Technical Guide to Information Security Testing and Assessment, dates to 2008, and NIST still lists it as current.
Here’s the short version.
- Scan to find known weaknesses, on a schedule
- Assess risk to decide which weaknesses matter most
- Pen test to prove whether a weakness can be used against you
- Red team to find out whether anyone would notice
Which test answers which question?
Owners usually ask for the wrong product because the names blur together, so start from the question you actually need answered and then read across the row to see what each option delivers.
| Option | The question it answers | How it works | What lands on your desk | Typical rhythm |
|---|---|---|---|---|
| Vulnerability scan | Which known weaknesses are on my systems right now? | Automated tool checks devices, servers, and internet-facing addresses against lists of known flaws | A ranked list of flaws, often with false alarms to sort out | Often monthly or continuous, and at least every 6 months for firms under the FTC rule |
| Network assessment | What do I own, and where is it weak? | People inventory devices, pull firewall rules, and map what can reach what, without attacking anything | A diagram, an asset register, and a ranked fix list | Once to start, then after big changes |
| Risk assessment | What could hurt the business most, and how likely is it? | People review assets, threats, existing controls, and impact | A scored risk list and a plan | Usually yearly and after big changes |
| Penetration test | Can someone actually get in, and how far could they go? | A tester with written permission tries to exploit weaknesses | A report of what worked, the path taken, and how to fix it | Yearly where a rule demands it, or after major changes |
| Red team exercise | Would we notice a determined attacker? | A long simulated attack against people, process, and technology | An assessment of detection and response | Rare, mostly large organizations |
| Compliance audit | Do we match a written standard? | An auditor checks evidence against a checklist | A pass, a fail, and a list of missing documents | Set by the standard |
NIST describes a red team exercise as a “simulated adversarial attempt” to compromise an organization’s missions or business processes. That’s a bigger and costlier thing than a pen test. If you’re asking whether you need one, you almost certainly don’t yet. Not yet.

Where does a risk assessment fit?
It sits above both. A scan and a test look at technology, while a risk assessment asks what the business stands to lose and which weaknesses deserve money first, which is a different question entirely. Different job. Different owner.
NIST’s SP 800-30, the Guide for Conducting Risk Assessments, treats it as an input to leadership decisions rather than a technical report. Our walkthrough of how to conduct a cybersecurity risk assessment covers the steps, and I won’t repeat them here.
Here’s why the order matters. Scan results can run to hundreds of lines, and a risk assessment tells you which 10 of them matter to your business before anyone spends a dollar fixing the rest. A pen test then checks whether those 10 can really be used against you. Order matters.
Do you need a penetration test for compliance?
Often not. Sometimes yes. It depends on which rule reaches you, and the answer varies more than most vendors admit. Here’s what the primary sources say.
| Rule that may apply | What it says about scanning and testing | Pen test named? |
|---|---|---|
| HIPAA Security Rule, current text | Requires an “accurate and thorough assessment of the potential risks and vulnerabilities” to patient data under 45 CFR 164.308, plus a periodic technical and nontechnical evaluation | Neither paragraph names one |
| HIPAA Security Rule, proposed update | HHS’s January 2025 proposal adds automated vulnerability scans at least every 6 months and penetration testing | Proposed only, not final |
| FTC Safeguards Rule | Requires continuous monitoring, or else annual penetration testing and vulnerability assessments at least every 6 months, under 16 CFR 314.4 | Yes, unless continuous monitoring is in place or the firm is exempt |
| CMMC and DFARS 7012 | NIST SP 800-171 asks you to scan for vulnerabilities periodically and when new ones are identified | Not in the scanning requirement, so check your contract |
| PCI DSS | Requirement 11 covers regular testing of systems and networks. The PCI Security Standards Council library lists v4.0.1 | Read your version and ask your acquirer |
| Texas breach law | Business and Commerce Code section 521.052 requires “reasonable procedures” to protect sensitive personal information | No |
Take the FTC row first, because it surprises people. The Safeguards Rule covers more than banks. The FTC lists tax preparation firms and mortgage brokers among the covered “financial institutions,” and coverage turns on activity, not job title, so a Texas CPA firm or a mortgage broker can be in scope without ever thinking of itself as a financial company. Many aren’t aware.
The exemption matters too. Under section 314.6, a firm that keeps customer information on fewer than 5,000 consumers is excused from the testing paragraph, section 314.4(d)(2). Many small firms qualify. Count first. Verify your number before paying for a test you may not owe.
On HIPAA, HHS proposed adding a penetration test requirement in January 2025, but the rule is not final, so the current text still governs for now. Any practice that waits for a final rule to start scanning will be starting late. Plan for scans now. Treat the pen test as likely, not certain.
On CMMC, Phase 1 self-assessments against NIST SP 800-171 and the DFARS clause already apply, and periodic scanning is part of that control set. Check your contract for when third-party assessment applies to you. That’s one reason to keep scan reports on file.
Cyber insurance is the last place a test request shows up. Your application and your broker decide. Ask before you buy anything.
What does each option cost?
Prices swing with scope. Treat every figure here as a starting point. Get written quotes. I’m only publishing numbers I can stand behind, so where a number is missing, it’s missing on purpose.
| Option | What we can say about cost |
|---|---|
| Vulnerability scan | Often bundled into a managed plan. Our MSSP Security Focus plan includes vulnerability scanning and starts at $40 per user per month. Stand-alone scanner pricing varies by vendor, so get quotes |
| Free scanning for internet-facing systems | CISA offers vulnerability scanning at no cost to eligible organizations, covering internet-accessible assets only. Check its eligibility terms, which list governments and critical infrastructure |
| Network assessment | We run ours at no charge |
| Risk assessment | We offer a no-charge cybersecurity risk assessment as a first step |
| Penetration test | A separate paid project. Our network assessment guide puts it at typically several thousand dollars, and scope drives the price |
| Red team exercise | Custom quotes only. Most small businesses never need one |
What drives a pen test quote? Mostly scope. The number of internet-facing systems, whether the tester works from outside or inside your network, whether custom web applications are included, and whether a retest is in the price. Two quotes can differ by thousands for that reason alone. Compare scope first.
For the security line items around these, see what cybersecurity costs in Houston, which breaks down per-user rates by regulatory burden.

When should you buy each one?
Buy in this order. Inventory, scan, fix, then test.
Buy a vulnerability scan when
- You can’t produce a list of what’s exposed to the internet
- A rule or a customer asks for scan reports
- You run a firewall, VPN, or remote access tool, since those edge devices are where attackers look
The numbers support it. The 2026 Verizon Data Breach Investigations Report puts exploited vulnerabilities at 31% of breaches, ahead of stolen credentials at 13%. A scan is the cheapest way to see those flaws before someone else does.
Buy a penetration test when
- A rule names it, as the FTC Safeguards Rule does for firms without continuous monitoring
- A customer contract requires proof
- You’ve just finished a major change, such as a new office network, a cloud migration, or a customer-facing web application
- You’ve fixed what your scans found and want independent proof that the fixes hold
Wait on a penetration test when
- You have no current device inventory
- Your last scan is old or has never been acted on
- Known critical flaws are still open
Paying a specialist to find a flaw your own scan already listed wastes the budget that should have gone toward fixing it, and it leaves the harder questions untested. Fix the obvious first. Then pay someone to find the rest. Simple.
Not sure where you stand? Our network assessment gives you the inventory and ranked findings that make a later test cheaper and sharper.
How do you scope and buy a penetration test?
This is where owners get burned. A bad engagement produces a scan report with a nicer cover. That’s the trap. Use this list when you collect quotes.
- Write the goal in 1 sentence, such as “show whether an outsider can reach customer records”
- List what’s in scope and what’s off limits, including cloud services you don’t control
- Get the rules of engagement in writing, with dates, hours, and an emergency contact
- Sign an authorization letter before anything starts
- Ask who performs the work, and whether they’re independent of the people who run your IT
- Confirm the price includes a retest after you fix the findings
- Ask for a sample report with plain-language findings and a ranked fix list
NIST SP 800-115 covers how to plan and run technical tests, analyze the findings, and develop mitigation strategies. That’s a useful test of any vendor. If they can’t describe their method in plain words, keep looking. No exceptions.
What should you do with the results?
Fix in order of exposure and exploitation. Internet-facing flaws first. Anything already known to be exploited next.
CISA gives a fair yardstick. Its Binding Operational Directive 26-04, issued in June 2026, gives federal agencies 3 days for internet-facing flaws that are already being exploited and hand an attacker total control, and 14 days or less for other known exploited flaws. Private firms aren’t bound by it. It still tells you what fast looks like. Speed counts.
Then rescan. A fix isn’t done until a second scan confirms it. Don’t skip that. Keep both reports, since an assessor or an insurer may ask for them later.

Where does Uprite fit, and when don’t you need us?
We’re a 42-person managed IT and cybersecurity team serving Texas businesses since 1999, with teams for Houston, Dallas, and San Antonio. Vulnerability scanning sits inside our security plans. We also run a no-charge network assessment and a no-charge risk assessment.
I don’t want to overstate the rest. Around a penetration test, our role is to help you decide whether you need one, write the scope, and turn the findings into a fix list your own team can actually work through. Ask any provider, us included, who performs the test and whether they’re independent of your IT team.
You may not need us. If your IT person already scans monthly and files the reports, spend your money on the fixes. If you’re weighing the whole security picture instead, work through our Houston SMB cybersecurity checklist, which applies to firms anywhere in the state.
Questions Texas owners ask before buying a test
Is a vulnerability scan the same as a penetration test?
No. A scan is automated and lists known weaknesses. A penetration test is run by a person who tries to exploit them with written permission. The scan is cheaper and repeatable, while the test costs more and proves whether a weakness can really be used.
How often should a small business run a vulnerability scan?
At least every 6 months if the FTC Safeguards Rule covers you, and more often if you can manage it. Many managed security plans scan continuously or monthly. Rescan after any major change and after you fix serious findings.
Do I need a penetration test for HIPAA?
Not under the current text. The Security Rule requires a risk analysis and periodic evaluation, and neither paragraph names a penetration test. HHS proposed adding one in January 2025, but the rule isn’t final, so confirm with your compliance advisor.
Does the FTC Safeguards Rule require a penetration test?
Yes, for covered firms without continuous monitoring. Section 314.4 requires annual penetration testing plus vulnerability assessments at least every 6 months. Firms holding customer information on fewer than 5,000 consumers are exempt from that paragraph under section 314.6.
What should a penetration test report include?
A plain-language summary, the scope and dates, each finding ranked by severity, the steps the tester took, and specific fixes. Ask for a sample report before you sign. A retest that confirms your fixes should be in the price.
Can I run my own penetration test?
You can run scans on systems you own. Exploit testing is different. Get written authorization first, and read the testing rules of any cloud provider that hosts your systems. Testing something you don’t control can break contracts or laws.
Will cyber insurance require a penetration test?
It depends on the carrier and your size. Applications often ask about security controls, so read yours and ask your broker which proof is expected. A recent scan report is a far smaller purchase than a test.
Not sure whether you need a scan, an assessment, or a test? We’ll look at what you have, tell you which one fits your rules and your budget, and put the reasoning in writing. You keep the findings either way.
Get an Assessment








