forumNew topic

6 things to do before getting a penetration test

SSerkan G***Expert
Job title
Penetration testing specialist
Organization type
a company within a holding
Joined
Nov 2023
Message
154
#1

Many people want testing, few are ready for it. In unprepared projects, half the findings are already known issues and the money is wasted.

One: provide the scope in writing. Which domains, which IP ranges, which applications. "Test everything" is not a valid scope.

Two: prepare the authorization document. If the system being tested isn't yours (cloud provider, hosting company), you need their permission too. This isn't a joke, it's a legal issue.

Three: test environment or production? If testing on production, specify the hours, who is on call, and who will roll back if something breaks — put it in writing.

Four: patch known vulnerabilities beforehand. Apply updates, change default passwords. Don't pay for these, they'll be found anyway.

Five: take backups and test if they restore properly. We don't want to test systems without backups.

Six: decide who will read the report. The report for the technical team and the summary for management are different documents.

Also, one more thing: never test without permission on any system that isn't yours. Try what you're curious about in an environment you set up yourself.

DDoki ekibiDoki team
Job title
Official account
Sector
Cybersecurity and digital
Organization type
Doki
Joined
Mar 2023
Message
310
Most Helpful#2

We agree with all six points, especially the second one.

Let's also add this: fixing and retesting after the test ends are separate tasks. Verifying that a finding is closed isn't the same as making the fix. When getting a quote, ask if retesting is included.

Also, no test issues a "system is secure" certificate. A test shows what was found within that scope on that date.

TTolgaNew member
Job title
Developer
Organization type
cooperative
Joined
Nov 2024
Message
41
#3

The fourth point is spot on. A third of our first report was due to missing updates. We were embarrassed.

MMerveMember
Job title
Operations manager
Organization type
cooperative
Joined
Mar 2024
Message
118
#4

Adding to the third point from an ops perspective: the person on call shouldn't have other tasks that day.

Here's what happened to us: the colleague on call had a shipping meeting on test day, and when the system slowed down, nobody noticed for twenty minutes. No one's fault, just a planning error.

FFerhat G***New memberCommunity member
Joined
May 2026
Message
180
#5

I have a question, don't want to go off-topic though. When you try to change everything at once, nothing settles.

I'm also curious if anyone does it differently.

PPolat E***Member
Job title
Technical service technician
Sector
Agriculture
Organization type
cooperative
Joined
Mar 2024
Message
273
#6

Following.

EElif Z***Expert
Job title
Production planning
Sector
Glass
Organization type
medium-sized business
Joined
Feb 2023
Message
164
#7

Quick summary for newcomers: Your time to detect an issue directly determines its cost.

This is my opinion, I'm not claiming it's absolute truth.

İİsmailMember
Job title
System administrator
Joined
Dec 2023
Message
128
#8

We got stuck at the same point for a while. Taking notes for two weeks yields better results than a six-month estimate.

If you post the result here, it will help others too.

BBeren B***MemberCommunity member
Joined
Oct 2023
Message
114
#9

We got stuck at the same point for a while. If 2FA is on, a stolen password alone is useless.

If you post the result here, it will help others too.

GGürkan Y***Member
Job title
Store associate
Sector
Plastic
Organization type
cooperative
Joined
Jan 2023
Message
213
#10

Thanks this was very helpful. Hasty decisions become decisions you have to fix six months later.

Having backups accessible on the same network and with the same identity makes them part of the target. Of course it varies if your situation is different.

EElif T***Member
Job title
Human Resources Manager
Sector
Freight
Organization type
120-person company
Joined
Sep 2024
Message
265
#11

This thread is archived.

KKadir Z***Member
Job title
Production Manager
Sector
Packaging
Organization type
300-person organization
Joined
Apr 2023
Message
123

Doki · Penetration test · 2025

#12

I agree, and I'd like to emphasize that. like mistakes made on the pentest side are usually reversible but expensive.

Hope this helps.

CCem T***Expert
Job title
Warehouse Manager
Sector
Real estate
Organization type
cooperative
Joined
Jul 2023
Message
22
#13

Don't miss this: An untested backup is not a backup.

HHasan Ö***MemberCommunity member
Joined
Dec 2024
Message
39
#14

great work. i mean if permission and scope aren't in writing don't start that test.

if you post the result here, it will help others too.

NNuri Y***Expert
Job title
Store Manager
Sector
Leather
Organization type
300-person organization
Joined
Aug 2022
Message
95
#15

Three different views emerged, they all complement each other. Hasty decisions become decisions you have to fix six months later.

Having backups accessible on the same network and with the same identity makes them part of the target. If I were you I'd go this route.

VVildan Ö***Member
Job title
Secretary
Sector
Retail
Organization type
family business
Joined
Dec 2024
Message
66
#16

thanks for posting and i mean if it's your first time, start small; scaling coes later.

the answer varies greatly by industry; there is no one-size-fits-all rule. this is my opinion, I'm not claiming it's absolute truth.

DDoruk Y***VeteranCommunity member
Joined
Dec 2023
Message
69
#17

I can't fully agree with this. Everything goes well for the first three months; problems arise in the fourth.

Hope this helps.

KKaan G***MemberCommunity member
Joined
Dec 2022
Message
1
#18

This is exactly what we experienced. The real issue isn't the number but what it's based on.

Hasty decisions become decisions you have to fix six months later. Proven by experience.

İİlknur A***New member
Job title
General coordinator
Sector
Textile
Organization type
early-stage startup
Joined
Jun 2026
Message
59
#19

Let me summarize what's been said so far. Trying to do this alone is the most expensive way.

Correct me if I'm wrong.

EEsra A***Member
Job title
Accounting Manager
Sector
Leather
Organization type
medium-sized business
Joined
Dec 2024
Message
41
#20

let me speak from the other side; Im on the supplier side and trying to do this alone is the most expensive way.

if 2FA is on, a stolen password alone is useless. tbh this is my opinion, I'm not claiming it's absolute truth.

Reply