Skip to content
RO
← All writing

Security audit or vulnerability scan?

  • security
  • audit
  • windows
  • cyber-essentials
  • vulnerability-scanning

An insurer, a customer or your own board asks whether your Windows machines are secure. You ask around, and somebody offers you a scan.

A scan is not an audit. They get sold under the same word, which is how people end up holding a 200-page PDF that answers a question nobody asked.

What a vulnerability scan does

A scanner works from outside the machine. It sends traffic at your network, finds what answers, and compares the software versions it sees against a database of known flaws. That is useful for one job: finding things you didn’t know were exposed to the internet.

The trouble is everything else. Scanners guess. A service reports a version number, the scanner matches it to a list, and out comes a “medium severity” finding for a flaw that a vendor backported a fix for years ago. Multiply by four hundred and you have the report people dread. Nobody can tell which of the four hundred is real without checking each one by hand.

It can also be noisy in a way that costs you. Aggressive scans have locked out accounts, tripped endpoint protection and knocked over old line-of-business software that was never built to be poked. If you’ve ever had a scan scheduled for a quiet weekend that never arrived, that’s why.

What a Windows audit does instead

My audit goes the other way. It runs on the machine and asks Windows how it is configured, rather than guessing from the network. Registry values, local group memberships, the encryption state of the drives, whether legacy protocols such as SMBv1 are still switched on, what the password and lockout policy says, what is listening and why.

It only reads. Nothing is installed as a service, nothing is written, no setting is changed. I wrote about why I made that a hard rule, including the four things Windows will never tell me, so I won’t repeat it here. The short version is that read-only can run on a Tuesday afternoon without anybody noticing.

The part that matters most for this comparison is the evidence. Every finding carries what it was read from. If the report says SMBv1 is enabled, it shows you the registry value and the path. Your IT person can open regedit and look. That turns a report you have to believe into one you can check in under a minute, and it ends most arguments with an outgoing IT supplier before they start.

Side by side

Vulnerability scanWindows audit
Looks fromOutside, over the networkInside, on the machine
AnswersWhat can be reached and what version it isHow it is actually configured
Disruption riskReal, and worse on old softwareNone, it only reads
FindingsLots, many theoreticalFewer, each with its evidence
Good atSpotting forgotten exposed servicesEncryption, admin rights, policy, legacy protocols
Blind toAnything not listening on the networkAnything not on the machine’s own configuration

Neither replaces the other. Mine can’t see a firewall rule you forgot about on a router, and a scanner can’t tell you the laptop in finance has an unencrypted drive. If you need both, buy both. Just don’t let one be sold to you as the other.

Where Cyber Essentials comes in

Most people asking me for an audit are really asking whether they’d pass Cyber Essentials, or whether they can answer an insurer’s questionnaire honestly. So findings are mapped to the relevant Cyber Essentials control, to show where you stand before you pay an assessor.

I can’t certify you. Only an IASME-licensed certification body can, and I’m not one. Going in unprepared is how businesses fail it twice, and that is what the mapping is for. If that’s your situation, how to pass Cyber Essentials first time is the companion piece.

What you get, and what it costs

A plain-English report. Findings rated by severity, each with its evidence, written so whoever already looks after your IT can fix them without me. Then a re-audit that runs the same checks again and shows what changed, which is the only way I know to tell remediation from a closed ticket.

Price is fixed per audit and depends on how many machines are in scope. Re-audits cost less. I quote after I know the machine count, because a published number would be wrong for nearly everybody. There’s no retainer, and you’re under no obligation to have me do the fixing. If I do, that is a separate quote.

One thing to ask whoever is pricing this for you: does your tool write anything to the machines, and can I see a single finding with its evidence before I sign? Two questions. They sort the field faster than a feature list.

If what you’ve been quoted is actually a penetration test, check whether you need one yet. It answers a different question again. The audit itself is on the security service page.