Resources from
the field.

Practical writing for pentest companies and their clients: how to scope, fix and prove.

← All articles Strategy4 min readCerberos Nexus team

Pentest or continuous project?

A pentest answers a point-in-time question. A continuous project keeps scanning on a cadence. Most clients need both.

In short
  • A penetration test is depth at a point in time: testers chain weaknesses and show the real impact.
  • A continuous project is breadth over time: scheduled scanning in cycles, with every finding followed from scan to scan.
  • Compliance often asks for both, such as an annual pentest and quarterly PCI ASV scans.
  • The best programmes keep both in one record.

Security testing budgets are usually spent on one of two things: a penetration test of something important, or recurring vulnerability scanning of everything. Both are useful, and they answer different questions. Choosing well starts with knowing which question you are asking.

Two different questions

A penetration test answers a point-in-time question: how secure is this system today, and what could an attacker actually do with it? Testers work through a methodology, chain weaknesses together and show the impact. It is the right tool before a launch, after a major change, for an audit, or when a customer asks for evidence.

A continuous project answers a different question: what has changed since the last scan? Vulnerability assessments and PCI ASV scans run in cycles on a set cadence, so new exposure is found between pentests rather than at the next annual test.

What a pentest gives you

  • Depth: business logic flaws, access control between roles and chained attacks that scanners cannot find
  • Judgement: a tester assesses real impact, not just a scanner's severity label
  • Evidence: a report with steps to reproduce and recommendations, and retests that prove the fixes

Its limitation is time. The day after the test ends, new code, new hosts and new vulnerabilities start to appear.

What a continuous project gives you

  • Coverage of the wider estate, cycle after cycle
  • Tracking: the same issue on the same host is followed across scans, so each cycle shows what is new, what keeps coming back and what looks fixed
  • A clear status for every cycle and, for PCI ASV, a passing quarter that can be attested

Its limitation is depth. Scanning finds known weaknesses and misconfigurations; it does not chain them together or understand the business.

A penetration test compared with a continuous project
AspectPenetration testContinuous project
ShapeOne project with a start and an endCycles that repeat on a cadence
FindsExploitable weaknesses, logic flaws and attack chainsKnown vulnerabilities and misconfigurations across many hosts
CadenceAnnually, or after significant changeMonthly to annually; PCI ASV is quarterly
Proof of a fixA retest of the original findingA verification scan, confirmed by an analyst
Typical driverLaunches, audits and customer assuranceHygiene, compliance scanning and a large estate

Choosing a cadence

For continuous projects, the cadence should follow how quickly the estate changes:

  • Monthly for internet-facing estates that change often, or where new vulnerabilities in common software need catching quickly
  • Quarterly for PCI ASV scanning, where it is required, and for stable internal estates
  • Twice a year or annually for small, slow-changing environments, usually alongside a pentest

Within each cycle, verification scans confirm fixes without waiting for the next primary scan.

When you need both

Many compliance programmes ask for both. PCI DSS requires external vulnerability scans by an Approved Scanning Vendor every quarter, and penetration testing at least once every 12 months and after significant change. ISO 27001 and SOC 2 audits typically look for ongoing vulnerability management alongside periodic independent testing.

A practical pattern is a scoped pentest of the most important applications each year and after major releases, plus continuous scanning of the wider estate in between. The pentest finds what scanning cannot; the scanning keeps the estate from drifting between tests.

If the budget only allows one, ask which failure would hurt more: an exploitable flaw in your most important application, or an unpatched host somewhere in a large estate. The answer usually points to the right starting place.

Signs the mix is wrong

  • Every pentest report opens with missing patches and default credentials. The estate needs continuous scanning, so testers can spend their time on what scanners miss.
  • Scans come back clean, but each pentest still finds serious logic or access control flaws. Scanning alone is not enough for those applications.
  • Nobody can say what is open across both. The results live in too many places.

Run both from one record

Whichever mix you choose, keep the results in one place. When pentest findings and scan findings live in different spreadsheets and PDFs, nobody can answer the simple questions: what is open right now, and what is overdue? In Cerberos Nexus, pentests and continuous projects run side by side, and the client follows both in the same Client Portal.

Ready when
your auditor is.

See your engagements, findings and retests come together in one record, on a workflow like yours.