Explained

HackRisk or a penetration test: which do you need?

A penetration test is a human-led attempt to breach your systems, and the NCSC says it validates them only on the day of the test. HackRisk monitors your external exposure all the time, so the two do different jobs.

TL;DR

A penetration test is a time-boxed attempt by a qualified tester to breach a defined scope, using the tools and techniques an adversary might use. The NCSC describes it as a way of gaining assurance, similar to a financial audit, and says it can only validate your systems on the day of the test.

HackRisk is always-on, automated monitoring of your external exposure. It combines an external vulnerability scan, an external asset map and dark web monitoring in a single HackRisk Score, with full resolution advice for every issue on Core. Core also includes an internal vulnerability scan of 5 endpoints. The external scanning is read-only, and automated scanning cannot match the breadth and depth of manual testing.

The two work together. The NCSC advises manual testing such as penetration testing in addition to automated tools, and recommends vulnerability scans at least once a month so that pen tests can focus on complicated issues.

Why this question comes up

People often ask whether they have been tested. A pen test and a monitoring service both produce reports of findings, so they can look interchangeable. They do different jobs.

A pen test is a snapshot. The NCSC notes that it is not uncommon for a year or more to elapse between penetration tests. Vulnerabilities could exist for long periods without you knowing about them if a test is your only means of validating security.

Scanning alone is not a substitute. The NCSC says automated vulnerability scanning cannot compare to manual processes such as penetration testing when it comes to the breadth and depth of test coverage.

They are bought differently. A pen test is scoped by effort, usually given in resource days. HackRisk Core is a monthly subscription, and the prices are on the pricing page.

HackRisk monitors your external exposure all the time. A pen test gives you assurance in your vulnerability assessment and management processes. The rest of this page covers when each fits.

HackRisk in brief

HackRisk is a cyber risk monitoring platform for UK SMEs, built and run by the security experts at CyberLab. It scans your business from the outside, the way an attacker sees it, and turns everything it finds into one score: your credit score for cyber security.

Behind the score sits continuous monitoring of your external attack surface, dark web monitoring for stolen staff credentials, vulnerability scanning and supply chain checks. The results arrive as a report your board can actually read, with the fixes ranked by what needs attention first. Pricing is published: £49.99 a month for the Core plan on a 12-month commitment (£59.99 a month rolling), with a Cyber Essentials Readiness tier from £77 a month.

It starts with a free report. Enter your domain and you get a board-ready assessment within 24 hours, plus 30 days of full portal access, without handing over card details or sitting through a sales call.

HackRisk and penetration testing at a glance

Comparison areaHackRiskPenetration testing
What it isAlways-on, automated monitoring of your external exposure, with a score and reportA time-boxed, human-led attempt to breach a defined scope using an attacker's tools and techniques
Who does the workAutomated scanningNCSC advises qualified and experienced testers
How oftenAlways on, with regular automated reports, on-demand reports and instant email alerts (Core)Per engagement; NCSC notes a year or more between tests is not uncommon
CoverageExternal vulnerability scan, external asset map and dark web monitoring for one root domain on Core, plus an internal vulnerability scan of 5 endpointsSet in a scoping document: the technical boundaries, the types of test expected and the effort required
DepthRead-only external scanning that does not touch your production systemsGreater breadth and depth of coverage than automated scanning, according to the NCSC
OutputA HackRisk Score, every result unredacted and full resolution advice for every issue (Core)A report of issues found, a risk assessment for each, a way to resolve each, and an opinion on your vulnerability assessment process
CostFree report; Core £49.99/month on a 12-month commitment or £59.99/month rollingEffort is set in scoping, usually given in resource days
Best forKnowing your external exposure continuously and catching new issues between testsGaining assurance in your vulnerability assessment and management processes

How they fit together

Point in time versus always on

The NCSC says a penetration test can only validate that your systems are not vulnerable to known issues on the day of the test. The result describes that day.

HackRisk Core monitors one root domain continuously and sends instant email alerts, with regular automated reports and on-demand reports. It is meant to cover the time between tests, not to replace them.

Manual testing versus automated coverage

The NCSC states that automated vulnerability scanning cannot compare to manual processes such as penetration testing when it comes to the breadth and depth of test coverage.

The NCSC describes automated scanning as a cost-effective way of finding and managing common security issues without specialist security testers. HackRisk provides this through vulnerability scanning, recon scanning and dark web scanning.

Defined scope versus your external footprint

A pen test is scoped in advance. The NCSC recommends a scoping document that states the technical boundaries, the types of test expected and the effort required, usually in resource days. It adds that testers may identify systems outside the scope that affect security.

HackRisk's recon scanning maps internet-facing assets, including forgotten infrastructure. The example report shows what that looks like.

Assurance versus day-to-day control

The NCSC compares a pen test to a financial audit. Your finance team tracks income and spending day to day, and an external audit checks that its processes are sufficient. In the same way, the NCSC says pen testing is a method for gaining assurance in your vulnerability assessment and management processes, not a primary method for identifying vulnerabilities.

HackRisk is the day-to-day control. The NCSC says a pen test report should include an opinion on the accuracy of your vulnerability assessment and advice on improving your internal vulnerability assessment process.

When you need a penetration test

Commission a penetration test when you want human-led assurance. Typical reasons:

  • You want assurance in your vulnerability assessment and management processes, which the NCSC describes as the purpose of a pen test.
  • You want manual testing in addition to automated tools, as the NCSC advises in its 10 Steps guidance on vulnerability management.
  • You are a central government department, a public sector body or part of the UK's critical national infrastructure. The NCSC developed the CHECK scheme specifically for these organisations.
  • You are an HMG organisation. The NCSC recommends that HMG organisations use testers and companies that are part of the CHECK scheme.

The NCSC says third-party penetration tests should be performed by qualified and experienced staff only. CREST accreditation validates a company's technical capabilities, processes and governance. CHECK is the scheme under which NCSC assured companies can conduct authorised penetration tests of public sector and CNI systems and networks.

When continuous monitoring fits

Continuous monitoring fits when you want to know your external exposure all year round, at a monthly price:

  • You want to see what an attacker can find about your business before committing to a scoped engagement. The free HackRisk Report arrives within 24 hours and needs no card details.
  • You had a pen test months ago and want to catch new issues, exposed services and leaked credentials between tests.
  • You want a single risk score plus a plain-English, board-ready report. The HackRisk Score page explains how the score works.
  • You want a report written for non-technical readers, with resolution advice for each issue.
  • You want to follow the NCSC's advice to run vulnerability scans at least once a month without operating scanning tools yourself.

The NCSC says automated scanning cannot match manual testing for breadth and depth, so HackRisk does not replace a pen test. HackRisk's external scanning is read-only. See pricing for what each plan includes.

Using both

The NCSC advises manual testing such as penetration testing in addition to automated tools. It also says that taking care of the low hanging fruit through regular vulnerability scanning lets penetration testing engagements focus on complicated security issues better suited to a human.

One practical sequence: start with the free HackRisk Report, fix what it finds, keep monitoring running, then commission a scoped penetration test for the systems that matter most.

Frequently asked questions

Does HackRisk replace a penetration test?

No. HackRisk is automated, always-on monitoring of your external exposure. A penetration test is a human-led attempt to breach a defined scope, and the NCSC says automated scanning cannot compare to manual testing for breadth and depth of coverage.

If I have a pen test, do I still need monitoring?

Usually, yes. The NCSC notes that a pen test only validates your systems against known issues on the day of the test, and that a year or more between tests is not uncommon. It recommends vulnerability scans at least once a month. Monitoring covers the time in between.

How often should I have a penetration test?

The NCSC says it is not uncommon for a year or more to elapse between tests, and that a pen test is a method for gaining assurance rather than your primary way of finding vulnerabilities. Regular scanning, at least monthly, covers the time between tests.

How much does a penetration test cost?

The NCSC says the output of scoping is a document stating the technical boundaries, the types of test expected and the amount of effort, usually given in resource days. HackRisk prices are published: Core is £49.99 a month on a 12-month commitment or £59.99 a month rolling.

What do CREST and CHECK mean?

CREST is a not-for-profit company, and its accreditation validates an organisation's technical capabilities, processes and governance. CHECK is the NCSC scheme under which assured companies can conduct authorised penetration tests of public sector and CNI systems and networks.

Does HackRisk try to exploit vulnerabilities?

HackRisk's external scanning is read-only and runs from the outside, and your production systems are never touched. By the NCSC's definition, a penetration test attempts to breach a system's security using the same tools and techniques as an adversary might.

See your score before you decide anything

The quickest way to compare is to see what HackRisk finds about your own business: your HackRisk Score and a board-ready breakdown of what attackers can see, within 24 hours.

Start Your Free TrialSee an example report

No card details, no sales call. Plans from £49.99 a month on a 12-month commitment, if you decide to keep monitoring.

Information about Penetration testing on this page was checked against ncsc.gov.uk and crest-approved.org on 6 October 2026. If you spot something out of date, tell us and we’ll correct it.