
A vulnerability scan is automated, runs in hours, and tells you what known weaknesses exist. A penetration test is manual, takes days, and tells you what an attacker could actually do with them. They are priced differently, scoped differently, and answer different questions. Buying the wrong one is the most common mistake Philippine organisations make when they start taking security assessment seriously.
The short answer
If you have never assessed your environment, start with scanning and configuration review. It is cheaper, repeatable, and will surface more real risk in a typical SME than a penetration test will.
Commission a penetration test when you need to demonstrate to a regulator, a client, or a board that a specific system withstands a determined attacker — or when a contract requires one. It is a validation exercise, not a discovery exercise.
What a vulnerability scan actually does
A scanner compares your systems against a database of known weaknesses: unpatched software, default credentials, exposed services, weak cipher suites, misconfigurations with published advisories.
It runs in hours rather than days. It can run weekly. It produces a list ranked by severity score.
What it cannot do is tell you whether any of those findings matter in your environment. A scanner reports a missing patch on a server; it does not know that the server sits behind a firewall, holds no sensitive data, and would gain an attacker nothing. Equally, it may score a finding as medium that is in fact the first link in a chain leading straight to your domain administrator account.
Scanners produce findings. Judgement produces risk.
What a penetration test actually does
A tester works the way an attacker works. They chain findings together, test whether a theoretical weakness is exploitable in practice, and report what could realistically be achieved — data accessed, systems controlled, persistence established.
The output is not a list. It is a narrative: here is how we got in, here is how far we got, here is what we could have taken.
That takes days of skilled human effort, which is why it costs considerably more. It also requires a signed authorisation defining exactly what is in scope, when testing may occur, and what is explicitly excluded.
The authorisation requirement is not paperwork
Under the Cybercrime Prevention Act of 2012, accessing a computer system without right is a criminal offence. Written authorisation from someone with authority to grant it is what separates a penetration test from an intrusion.
A legitimate provider will insist on a scope document before touching anything. It should name the systems in scope, the testing window, the techniques permitted and excluded, an emergency contact, and confirmation that the signatory owns or controls the systems.
If a provider is willing to start testing without that, treat it as disqualifying. It tells you what their practice looks like when nobody is watching.
Reading a quotation
Some signals worth checking before you compare prices.
- Duration. A penetration test delivered in four hours is a scan with a different label. Manual testing of even a modest environment takes days.
- Deliverable. Ask to see a redacted sample report. A scanner export with a cover page is not a penetration test report. You are looking for narrative, evidence, and reasoning about exploitability.
- Credentials. OSCP, CREST, GPEN or equivalent. Ask who specifically will perform the work, not what the company holds.
- Insurance. Professional indemnity cover appropriate to testing engagements.
- Retest. Is a verification retest after remediation included, or billed separately? A finding you have not confirmed fixed is a finding you still have.
What most Philippine SMEs actually need first
In our experience assessing Microsoft 365 and Azure environments, the findings that carry real risk are rarely exotic. They are configuration gaps that no penetration test is needed to discover:
- Legacy authentication protocols still accepting basic authentication, bypassing MFA entirely
- Conditional access policies left in report-only mode after a pilot, enforcing nothing
- Global Administrator accounts well beyond the number anyone can justify
- Applications holding tenant-wide Graph permissions that nobody reviews
- Guest accounts able to enumerate the full directory
- Departed staff whose accounts remain enabled months later
None of these require an adversary to find. They require someone to look. A configuration review will surface them in a day, at a fraction of the cost of a penetration test, and remediating them removes more actual risk than most test reports do.
This is not an argument against penetration testing. It is an argument about sequence. Testing an environment that has never been configuration-reviewed produces a report full of findings you could have fixed beforehand — and you pay premium rates to be told about them.
A sensible progression
- Configuration and posture review. What is actually enforced in your tenant, versus what your policy says. Start here.
- Continuous vulnerability scanning. Ongoing, automated, covering patching and exposed services.
- Remediation. Fix what the first two found. This is where the risk reduction happens.
- Penetration test. Once the obvious is closed, commission testing to validate what remains — and to demonstrate that validation to whoever is asking.
Frequently asked questions
How much does a penetration test cost in the Philippines?
It varies widely with scope, but the useful comparison is days of skilled effort. If a quotation implies fewer days than the scope plausibly requires, the price difference is explained by less testing rather than better value.
How often should we run vulnerability scans?
Continuously or at least monthly for internet-facing systems, and after any significant change. Scanning is cheap enough that infrequent scanning is a false economy.
Does the Data Privacy Act require penetration testing?
The Data Privacy Act requires reasonable and appropriate organisational, physical and technical security measures, and does not prescribe a specific testing regime. What the National Privacy Commission expects to see is evidence that you assessed your risks and acted on the findings. A documented configuration review with remediation records demonstrates that; an untested policy document does not.
Can a vulnerability scan replace a penetration test?
No, and the reverse is also true. A scan finds known weaknesses broadly and cheaply. A test determines exploitability narrowly and expensively. They answer different questions, and a mature programme uses both.
What is a red team engagement?
A step beyond penetration testing: objective-based, covert, and testing your detection and response capability as much as your technical controls. It presumes you already have detection worth testing, which most organisations commissioning their first assessment do not.
Where to start
Onprem2Cloud IT Solutions Co. is a Microsoft Cloud Solution Provider based in Muntinlupa City, serving businesses and government agencies across Metro Manila and beyond. We run cloud security posture assessments for Microsoft 365 and Azure environments — privileged role review, conditional access and MFA coverage, legacy authentication, application permissions, and guest and service accounts — mapped to the CIS Microsoft 365 Foundations Benchmark and the technical measures the National Privacy Commission expects.
The output is a findings report ranked by exploitability with specific remediation steps, not a scanner export. Get in touch to discuss an assessment of your environment.
What's happening
Our latest news and trending topics
