Blog Framework Contact Us

Are You Wasting Money on VAPTs?

A scan with a cover page is not a penetration test. Here is how to tell the difference, and how to make your next VAPT earn its fee.

July 23, 2026 8 min read ClarenSec Team
Banknotes burning: the cost of paying for a VAPT that delivers no real testing

Table of Contents

A finance director once forwarded us a VAPT report his bank had paid good money for the year before. Ninety-odd pages, a glossy cover, his logo top-right, a severity chart in three colours. It took us about twenty minutes to see that every finding in it had come straight out of an automated scanner, with nothing opened, exploited, or even confirmed by a person. The "critical" sitting at the top of the list was a false positive a senior penetration tester would have dismissed in ten seconds. He had renewed that contract three years running, which means he had bought the same scan three times and called it a penetration test each time.

This is the most common way Nigerian organizations waste money on security testing, and almost nobody who buys it realizes it is happening. The invoice says VAPT. What arrives is a vulnerability scan with a beautiful cover page. It looks like assurance, and it gives you a document you can hand to an auditor, but it tells you almost nothing about whether an attacker can actually get into your systems.


The Scan With a Cover Page

A vulnerability scanner is a useful tool. It runs through a list of known issues, checks software versions against a database, and reports anything that matches a signature. It is fast, it is cheap to run, and a competent tester uses one as a first pass. The problem begins when the scan is the whole engagement.

You can usually spot it in the report itself. The findings read like database entries because that is what they are. Severities are whatever the tool assigned. There is no narrative of how the tester moved through the network, because the tester never moved through anything. And the false positives are probably the biggest red flag.

A scanner cannot tell you that two medium-severity issues, chained together, hand an attacker your customer database. It cannot reason about your business logic. It does not know that your "internal only" admin panel is reachable from the guest network.

Where the Money Actually Goes

When a VAPT produces nothing useful, it usually fails in one of four ways.

Any one of these empties part of the budget. Together they produce the worst outcome in security: a false sense of security.

What a Real Test Produces

The point of a penetration test is to answer a question a scan cannot: given the way your systems actually fit together, what can someone do? Answering that takes a human working the way an attacker works, and it produces things a scan never will.

This is also where it matters who does the work. Methodology mapped to NIST SP 800-115, PTES, and the OWASP Testing Guide only delivers value when senior penetration testers are the ones running it, exercising judgement the framework cannot encode. A junior following a checklist will miss the chain that a senior tester spots early on.

Why This Bites Harder in 2026

The cost of an untested gap stopped being theoretical for Nigerian firms this year. The Sterling Bank data breach and the FCMB heist of about N677 million, attributed in reporting to the actor known as ByteToBreach, were not exotic nation-state operations. They were the kind of access a real test is built to find first.

For listed firms the gap also carries a compliance edge. The NGX requires Trading Licence Holders that run online trading portals to complete VAPT at least twice per year. If both of those engagements are scans with cover pages, you have met the letter of the obligation and gained almost none of its protection. You are paying twice a year to look tested.

How to Get Value From the Next One

You do not need to become a tester to do testing well. You need to ask a handful of questions before you sign, and to treat vague answers as the warning that they are.

summary.sh -- key takeaways
  • A scan with a cover page is not a penetration test. If no human exploited the findings, you paid tester rates for software output.
  • Four patterns drain the budget: an automated scan sold as a manual test, narrowed scope, findings with no proof of concept, and no retest after you remediate.
  • A real test proves impact and confirms the fix. Proof of concept, reproducible steps, the business-logic and chained findings a scanner cannot reach, and a retest in the contract.
  • Buy it well by asking up front: methodology mapped to OWASP, PTES, or NIST SP 800-115, a sample finding, scope and credentials in writing, and a contracted retest.

ClarenSec runs penetration tests that exploit what they find and prove it, then retest once you have fixed it. No scanner export with a cover page, and no findings your team cannot reproduce.

Before you renew with the vendor who sold you last year's report, ask us what a real engagement should cover.

Request a Scoping Call