mark.thompson business editor
Choosing the lowest-cost penetration testing service can expose an organization to severe vulnerabilities, as bargain offerings often deliver significantly narrower assessments that fail to uncover how real attackers might exploit system flaws, according to experts. Cybersecurity threats now extend far beyond large enterprises, increasingly targeting small and medium-sized businesses.
Data from the Anti-Money Laundering Competency Centre shows that Lithuanian companies lost approximately 900,000 euros in fraud cases linked to compromised email accounts during just the first half of 2025. These recurring incidents highlight a persistent trend where security gaps are frequently discovered by malicious actors rather than internal IT security teams. Meanwhile, the National Cyber Security Centre (NKSC) in Lithuania registered 2,888 cyber incidents in 2025, marking a decrease of one-fourth compared to the previous year.
Distinguishing Automated Scans From Manual Penetration Tests
A critical distinction for organizations is understanding that automated vulnerability scanning is not a full penetration test. While automated tools quickly check systems against known vulnerability databases and serve as a useful component of a security process, they evaluate each problem in isolation and cannot fully replicate real attacker behavior. Automated scans can also generate false positive reports where identified risks do not actually exist in the real environment and require manual verification.
In contrast, a manual penetration test determines what an attacker could realistically achieve using those gaps by chaining multiple minor weaknesses together into a single attack path. Vendors offering only automated scanning essentially sell a much narrower service, which accounts for major price differences among provider proposals. Organizations are advised to clarify beforehand whether manual testing is included, who specifically will perform the work, and whether tasks will be outsourced to subcontractors whose qualifications are difficult to verify.
Cybersecurity Risks Threaten Business Continuity and Financial Stability
Cybersecurity risks have evolved beyond a purely technical responsibility, occupying the third position among significant global risks according to international research data presented by Viktorija Vaškūnė, head of the competency center at Greco Lietuva. Cybersecurity incidents can halt corporate operations as rapidly as a fire or natural disaster, directly impacting business continuity, reputation, and financial stability. Geopolitical tension and conflicts serve as contributing factors to the rise in attacks.
European regulations emphasize two key areas: the General Data Protection Regulation (GDPR), which protects personal data, and the NIS2 directive, which safeguards organizational systems and business continuity. Organizations handling sensitive data during penetration tests, such as administrator-level credentials or unpatched vulnerabilities, must also evaluate their own security maturity through information security management systems like the ISO/IEC 27001 standard or equivalent approved measures.
Additional insights on preparing infrastructure and assessing digital resilience are detailed further in resources provided via Verslo Žinios, highlighting the importance of thorough supplier evaluation. Ultimately, experts emphasize that an effective organizational resilience strategy relies on three interconnected pillars: prevention, preparedness, and cyber insurance.