"We need a security review." "Our insurer wants a risk assessment." "A customer is asking for a pen test." These three phrases get used interchangeably, and vendors don't help by blurring them on purpose. They are different exercises with different outputs, and buying the wrong one wastes money twice: once on the wrong engagement, and again on the one you actually needed.

Here's what each one is, how they compare, and how to decide which your business needs right now.

What a security review is

A security review is a management exercise. Someone, internal or external, steps back and looks at your whole program: what you protect, what's in place, what changed, and where the gaps are. It answers the question "is our program pointed at the right things?"

What you get:

  • A picture of your current posture across assets, access, vendors, incidents, policies and spend
  • A prioritized list of gaps with owners and rough costs
  • Direction for next year's budget and roadmap

It's the cheapest of the three, can be run internally, and is the right starting point if you've never had anything assessed. Our guide to running an annual cybersecurity review walks through the agenda.

What a risk assessment is

A risk assessment is a structured analysis of what could go wrong and how much it would matter. It identifies threats to your specific business, evaluates the likelihood and impact of each, checks the controls you have against them, and tells you where your exposure exceeds your tolerance.

What you get:

  • A risk register: ranked, business-specific risks rather than a generic findings list
  • An evaluation of existing controls against each risk
  • Treatment decisions you can defend: accept, mitigate, transfer or avoid
  • Evidence that satisfies insurers, enterprise customers and frameworks that require formal risk analysis

Unlike a review, which asks "how is the program doing," a risk assessment asks "what should the program be protecting against, and how well is it doing that?"

What a penetration test is

A penetration test is a controlled attack. Ethical hackers try to break into your systems the way a real attacker would, to find out whether your defenses actually work. It answers the most concrete question of the three: "can someone get in, and what can they reach if they do?"

What you get:

  • Proof of which weaknesses are exploitable, not just present
  • Attack paths: how a small foothold chains into real access
  • A report your customers, insurers and auditors accept as evidence of testing

One important distinction: a penetration test is not a vulnerability scan. Scanning lists potential weaknesses automatically; a pen test has humans exploit them. Our scanning vs. pen testing comparison covers that difference in detail.

Side-by-side comparison

Security review Risk assessment Penetration test
Core question Is our program pointed at the right things? What could hurt us most, and are we protected against it? Can someone actually break in?
Who does it You, your IT lead, or an advisor Typically an external assessor, sometimes internal with a framework External specialists, always
Method Interviews, document review, metrics Structured analysis of threats, likelihood, impact and controls Simulated attacks on real systems
Output Posture summary and prioritized gaps Risk register and treatment plan Exploited weaknesses and attack paths
Cost driver Mostly your own time Scope: systems, frameworks, sites in scope Scope: size and complexity of what's tested
Typical cadence Annually Annually or on major change Annually, or after significant changes
What it can't tell you Whether defenses hold up in practice Whether a specific weakness is exploitable Anything about systems outside the agreed scope

Notice what the table implies: none of these replaces another. They answer different questions, and mature programs run all three on a cycle.

Which one do you need?

Work through these in order.

Never had anything assessed?

Start with a security review. If patching, access control and backups are unproven, a penetration test will only confirm what you already suspect, at a much higher price. Get the fundamentals visible and funded first.

Is a customer, insurer or regulator asking?

Read the request literally; the words matter. "Risk assessment" usually means a formal risk analysis against a framework. "Penetration test" means a real test with a report, not a scan. "Security review" is the loosest term and often accepts either of the other two plus a management review. If the wording is ambiguous, ask the requester what report format they expect — it reveals which exercise they actually mean.

Want to know if your defenses actually work?

That's a penetration test. It's the only one of the three where someone tries to defeat your controls instead of documenting them. If you're paying for detection tools or an MDR service and want to know whether they catch anything, a test is how you find out.

Planning next year's budget?

That's the risk assessment. It converts "security wants money" into "these specific risks exceed our tolerance, and here's the cost to treat each one" — a conversation that goes much better with a risk register than with a tool quote.

Questions to ask before you buy

Whichever engagement you're buying, these keep the scope honest:

  1. What exactly will the deliverable say, and can we see a sanitized sample report?
  2. What is in scope, in writing, and what's explicitly excluded?
  3. Who does the work — the people selling it, or a subcontracted team?
  4. How will you verify findings before reporting them, so we're not paying for false positives?
  5. What do you need from our team, and how much of their time?
  6. Is a retest included after we fix what you find?
  7. Will the output satisfy the party driving this — our insurer, customer or auditor?
  8. What happens to our data and your notes when the engagement ends?

If you're not sure which engagement fits your situation, that conversation is free: get in touch and we'll tell you honestly — including when the answer is "you don't need a pen test yet."

Frequently asked questions

Is a security review enough, or do we also need a penetration test?

Start with the review. If it shows the basics are unproven — patching, access control, backups — fix those first; a penetration test of an unmanaged environment mostly confirms what you already know. Add a pen test when the fundamentals are in place and you want to know whether they hold up against a real attacker.

How much do these typically cost?

Costs scale with scope, not label. An internal security review is mostly your own time. A risk assessment is typically a fixed-fee engagement sized by systems and frameworks in scope. Penetration tests are priced by the size and complexity of what's being tested. Be suspicious of any price quoted before scope is agreed.

How often should each be done?

A security review annually, as a management habit. A risk assessment annually or when something major changes: new systems, mergers, new regulations. A penetration test annually or after significant changes to the systems in scope, and whenever customers, insurers or frameworks like PCI DSS require it.

Key takeaways

  • A review checks your program's direction, a risk assessment ranks what could hurt you, a pen test proves whether defenses hold.
  • None replaces the others; mature programs cycle through all three.
  • Never assessed anything before? Start with a review, not a pen test.
  • When someone else is driving the request, read the wording literally and ask what report they expect.
  • Get scope and deliverables in writing before comparing prices — the label alone tells you nothing about cost.