In short
A penetration test is an authorised attempt by people to break into your systems; a vulnerability scan is software checking for known-bad versions. Buy both, for different reasons. Most Irish SMEs should test in this order: external attack surface, internal network, phishing, applications, then cloud and identity. Choosing a provider comes down to seven written questions, of which the most revealing is asking for a redacted sample report. Price is driven by host and application count, whether the internal network is in scope, whether testing is authenticated, and whether a retest is included. Annual is the sensible default, sooner after a move, a launch, a migration or an incident.
A penetration test is an authorised attempt to break into your systems, run by people, to find out what an attacker could reach. It is not a scan. The difference matters commercially, because a scan costs a few hundred euro and a test costs a few thousand, and buying the first while believing you bought the second is the most common mistake Irish SMEs make with security spend.
This guide covers what a test involves, the five types and which to buy first, how to choose a provider in Ireland, and what drives the price.
Penetration test or vulnerability scan?
Both are useful. They answer different questions.
| Vulnerability scan | Penetration test | |
|---|---|---|
| Run by | Software, automatically | People, with tools |
| Finds | Known-bad versions and misconfigurations | Chains of small issues that add up to access |
| Frequency | Continuous or monthly | Annual, or after significant change |
| Misses | Logic flaws, chained weaknesses, anything novel | Nothing you did not scope |
The clearest example is a broken access control. A scanner confirms your invoice portal is patched and the certificate is valid, and reports it clean. It cannot notice that changing the invoice number in the address bar returns another customer's invoice, because nothing about that request is malformed. It takes a person who understands the business rule to break it deliberately. We wrote that up in testing the software your business runs on.
Run scanning continuously. Test annually. They are not alternatives.
The five types, and which to buy first
Most Irish SMEs should buy them in this order.
- External attack surface testing. What an attacker can reach from the internet without help. Almost always finds something nobody knew was exposed: a VPN appliance from a previous provider, a forgotten test environment, a remote-desktop port opened during a busy week. Start here. What an attacker sees from the internet.
- Internal network penetration testing. Assumes somebody is already inside and measures how far they get. Flat networks are the most common finding and the one with the widest blast radius. How far a breach could spread inside.
- Phishing and social engineering testing. Whether your team can be tricked, measured rather than guessed, and turned into training. Whether your team can be tricked.
- Application security testing. For the portals and line-of-business software you or your customers depend on. Follows the OWASP testing guide. Testing the software your business runs on.
- Cloud and identity testing. Microsoft 365 and Azure configuration, conditional access, privileged roles and the paths between them. For most Irish SMEs this is now where the crown jewels sit. Your Microsoft 365 and cloud setup.
API testing sits inside application testing when the API belongs to your own software, and inside cloud testing when it is a platform API. Ask for it by name in scoping either way, because it is the part most often left out of a quote.
How to choose a provider in Ireland
Seven questions. Ask all seven in writing, of every provider on your shortlist, and compare the answers side by side rather than comparing prices.
- Who does the testing, and what do they hold? You want named testers with current certifications, whether that is OSCP, CREST registration or equivalent. "Our security team" is not an answer. Ask whether the work is subcontracted, and to whom.
- Can I see a redacted sample report? This is the single most revealing question. You are buying a report. If the sample is a reformatted scanner export with CVSS scores and no narrative, that is what you will get.
- Is a retest included? Fixing findings is the point. A test that does not confirm the fixes worked leaves you with a list and no closure. Get retest scope and timing in the quote, not as an extra.
- What is explicitly out of scope? Cheap quotes are usually cheap because something is missing: the internal network, the cloud tenancy, the APIs, the retest. Ask what is excluded and get it listed.
- What are the rules of engagement? Testing windows, escalation contacts, what happens if a tester finds an active compromise mid-test, and what they do rather than exploit. This should be a document, agreed before anyone starts.
- What insurance do you carry? Professional indemnity, and enough of it. A test that takes a production system down is rare and not impossible.
- Will the report survive a customer reading it? Increasingly the report goes to your customer's security team, not just to you. It needs an executive summary a non-technical director can act on and enough detail that a technical reviewer trusts it.
The accreditation question is worth expanding, because "CREST penetration testing" is a common search and a common misunderstanding. CREST accredits companies and registers individual testers. It is a genuine quality signal and it is not a legal requirement in Ireland. Some regulated buyers insist on it, most SME buyers do not. Ask what your customers require before you pay for it.
What it costs, and what moves the price
Four things drive the number: how many live hosts and applications are in scope, whether the internal network is included, whether testing is authenticated (testing as a logged-in user finds far more and takes longer), and whether a retest is included.
For reference, our own full test, covering everything internet-facing, the internal network, applications, people, and the Microsoft 365 and cloud setup, is a fixed-price package from €3,995. Smaller scopes are scoped and priced individually. Any provider who quotes without asking about your host count and your application count is quoting for something other than what you have.
Be careful with quotes far below that range. They are usually an authenticated scan with a covering letter, and they will not satisfy a customer who reads the report properly.
How often, and when
Annually is the sensible default for an SME. Test sooner than that when:
- You have moved office, changed internet provider, or replaced the firewall.
- You have launched or significantly changed a customer-facing application.
- You have migrated to a new Microsoft 365 tenancy or changed identity provider.
- You have been through an incident.
- A customer contract or an insurer requires evidence dated within the last twelve months.
Between tests, keep vulnerability scanning running. The gap between annual tests is where the newly published vulnerabilities land.
Testing and compliance
A penetration test supplies evidence for several obligations at once. It supports the testing expectations behind NIS2, Cyber Essentials, ISO 27001 and PCI DSS, and it is increasingly a cyber-insurance prerequisite rather than a discount.
Two cautions. A test is evidence, not compliance: no framework is satisfied by a test alone. And the report has a shelf life, usually twelve months, so check the date your customer or insurer expects before you rely on last year's.
For where testing fits in the wider NIS2 picture, see our NIS2 guide.
Related reading
- What an attacker sees from the internet
- How far a breach could spread inside
- Whether your team can be tricked
- Testing the software your business runs on
- Does NIS2 apply to my Irish business, and what does it require?
Related services
Scoping a test
A scoping call takes fifteen minutes and produces a written scope and a fixed number. Offices in Cork and Kilkenny, testing for SMEs across Ireland.
What is the difference between a penetration test and a vulnerability scan?
A scan is software checking your systems against a database of known vulnerabilities. A test is people attempting to break in, chaining small weaknesses into real access. A scanner will confirm a portal is patched and report it clean while missing that changing the invoice number in the address bar returns another customer's invoice, because nothing about that request is technically malformed. Run scanning continuously and test annually. They are not alternatives.
How much does a penetration test cost in Ireland?
Four things drive the price: how many live hosts and applications are in scope, whether the internal network is included, whether testing is authenticated as a logged-in user, and whether a retest is included. Our own full test, covering everything internet-facing, the internal network, applications, people and the Microsoft 365 and cloud setup, is a fixed-price package from 3,995 euro. Quotes far below that are usually an authenticated scan with a covering letter.
Do I need a CREST-accredited penetration testing provider in Ireland?
Not usually. CREST accredits companies and registers individual testers, and it is a genuine quality signal, but it is not a legal requirement in Ireland. Some regulated buyers insist on it; most SME buyers do not. Ask what your own customers and insurers require before paying for it. What matters more for most businesses is named testers with current certifications, a sample report you have read, and a retest included in the price.
How often should we run a penetration test?
Annually is the sensible default for an SME, with vulnerability scanning running continuously in between. Test sooner after you move office or change firewall, launch or significantly change a customer-facing application, migrate to a new Microsoft 365 tenancy or identity provider, or go through an incident. Reports typically have a twelve-month shelf life with customers and insurers, so check the date they expect.
Does a penetration test make us NIS2 compliant?
No. A test supplies evidence for the testing expectations behind NIS2, Cyber Essentials, ISO 27001 and PCI DSS, and it is increasingly a cyber-insurance prerequisite. It is one control among the ten categories NIS2 Article 21 lists. No framework is satisfied by a test alone.
Will a penetration test disrupt our business?
It should not. Scope, timing and rules of engagement are agreed in writing before anyone starts, including testing windows, escalation contacts, and what a tester does rather than exploit if they find an active compromise mid-test. Ask for the rules of engagement as a document. A provider who cannot produce one has not thought about it.