resources

Audit or
penetration test?

Both put your security to the test, but they don’t answer the same question.
An audit asks “is it compliant and well designed?”; a penetration test asks “is it actually exploitable?”

the audit

The audit: checking the design

A security audit assesses organisation, configuration and architecture against a reference framework (best practices, CIS, ANSSI requirements…). It looks broadly: configuration review, rights and accounts, hardening, patch management. The audit answers “are the right measures in place and correctly set up?”. It covers a wide area, including zones an attacker wouldn’t immediately reach.

the penetration test

The penetration test: proving exploitability

A penetration test takes the attacker’s point of view. It looks for what is actually exploitable, chains weaknesses and demonstrates concrete impact: access to data, takeover, bypassing a business control. It goes deep on a defined scope, but doesn’t claim an audit’s exhaustiveness. For the full definition, see what is a penetration test.

which one

Which one to choose?

  • You’re starting your security journey or aiming for compliance: often begin with an audit, to map and prioritise.
  • You want to know what an attacker would get on a specific application or infrastructure: a penetration test is more telling.
  • You need to prove your security to a client, insurer or auditor: the pentest, with its retest, provides datable evidence.

The two are complementary: the audit gives the overview, the pentest confirms what really matters. In practice, the choice is decided in a few minutes of discussion about your context and goal.

In doubt, describe your situation: I’ll tell you plainly which of the two serves your goal, without selling you the more expensive one. See also how much a penetration test costs.

Let's discuss your needs

Audit or pentest: describe your goal, I’ll point you the right way. Single day rate of €1,100 (excl. VAT).

Reply within a few business days, no commitment.