Explaining scan vs pentest vs red team

These three terms get used interchangeably far too often, and it leads to organisations paying for the wrong thing.
A vulnerability scan is automated. It identifies known weaknesses against a database of signatures. It's fast, relatively cheap, and useful for maintaining visibility, but it doesn't tell you whether those weaknesses are actually exploitable in your environment.
A penetration test is manual, scoped, and consultant-led. A tester actively attempts to exploit identified weaknesses to determine real-world impact. It answers the question: what could an attacker actually do with this?
A red team simulation goes further still. It's an adversarial exercise with minimal prior disclosure, designed to test your detection and response capability, not just your technical controls. The goal isn't a list of vulnerabilities, it's an honest assessment of how your organisation would hold up against a determined, targeted attack.
All three have legitimate uses. The problem is when a scan gets dressed up as a pentest, or a pentest gets sold as a red team. If you're unsure which one your situation actually calls for, we're happy to talk it through before any commitment is made.
Concerned this affects you?
We can assess your exposure and tell you plainly where you stand.