The three different processes are known as a vulnerability assessment, penetration test and a risk analysis. Knowing the difference is critical when hiring an outside firm to test the security of your infrastructure or a particular component of your network. A risk analysis doesn’t require any scanning tools or applications its a discipline that analyzes a specific vulnerability (such as a line item from a penetration test) and attempts to ascertain the risk including financial, reputational, business continuity, regulatory and others to the company.”]

