Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →A vulnerability scan is an automated tool that lists known weaknesses across systems, while a penetration test is a manual engagement where a human actively exploits weaknesses to prove real-world impact. Scans give breadth and run continuously; pen tests give depth and validation. Most mature security programs use both.
Think of the scan as a smoke detector and the pen test as a fire drill. The scan tells you where the risk likely is, cheaply and often. The pen test confirms what an attacker could actually do with it.
Compliance language sometimes blurs the two, so read requirements carefully. PCI DSS, for example, mandates both regular scanning and an annual penetration test, and they are not interchangeable.
traztech delivers scoping the right security testing for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
This comes up when a buyer or auditor asks for "a pen test" and somebody on the team offers a scan report instead. They are not interchangeable, and a reviewer who knows the difference will notice immediately.
The practical test is whether a human tried to chain findings into an actual compromise. If the output is a list of CVEs with severity scores and no exploitation narrative, it is a scan.
Generally no. Frameworks and buyers that ask for penetration testing expect human-led testing. Scanning usually satisfies a separate vulnerability management requirement.
Scan first. It is cheaper, it finds the obvious problems, and fixing those before a penetration test means you are paying a tester to find the things a scanner cannot.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
Before you go
Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.