forumNew topic

Should we get a penetration test, when, and what scope?

BBarış K***Expert
Job title
Corporate IT manager
Joined
Jun 2023
Message
172
#1

I'm a corporate IT manager. I'm going to present a penetration testing budget to the board and want to ask the right questions.

The quotes I'm getting right now vary wildly in price and their contents aren't comparable. One says "full-scope test," the other gives an "automated scan report," and the price difference is five times.

My request to friends experienced in this field: what should I ask, what should I request, and what output should I expect?

SSerkan G***Expert
Job title
Penetration testing specialist
Organization type
a company within a holding
Joined
Nov 2023
Message
154
Most Helpful#2

As someone who does penetration testing, let me first mention the most common misconception in my industry: calling an automated scan report a penetration test.

Automated scanning uses tools to scan for known vulnerabilities and generates a list. It's useful, cheap, and repeatable. But if the tester stops there, most findings in that report are unverified; the false positive rate is high. That's usually the explanation for the five-fold price difference.

Questions to ask to compare quotes:

Are findings manually verified? Meaning, is every item in the report written by demonstrating it's actually exploitable, or is just the tool's output being copied over?

What is the scope and who defines it? Are the addresses, applications, and included/excluded systems written down?

What type of test is it? Will it be done with no information, partial information, or full access? The three produce different durations and different findings.

Is retesting included? After you fix things, who verifies when that the same findings are closed? If it's not included, the report remains incomplete.

Who is the report for? A good report has both an executive summary and technical details; if they're written in the same tone, one of them is useless.

Finally, timing: get the test done before going live. Anything found after launch is more expensive and riskier to fix.

YYavuzExpert
Job title
Information Security Manager
Joined
Jul 2023
Message
168
#3

As the information security manager, I'd like to add a few points regarding the buyer's preparation.

First, written permission before testing. Touching a system outside the scope creates both technical and legal issues. The test window, communication channel, and emergency stop procedure must be in writing.

Second, when the test will be conducted. Testing during a busy period also brings the risk of actual downtime. Share this with business units in advance.

Third and most importantly: don't get a test done without allocating resources to close the findings. Sitting on an unclosed finding report is a worse position than not testing at all. When presenting the budget, itemize the remediation effort alongside the test cost.

DDefneMember
Job title
SOC Analyst
Organization type
a company within a holding
Joined
Feb 2024
Message
146
#4

A suggestion from the monitoring side: measure your own detection capability during the test.

Did your monitoring system notice when the tester tried to access the system, how long did it take, who got the alert? This info is sometimes more valuable than the vulnerability list in the report.

Practical method: ask the tester for a timestamped list of their actions. Then compare it with your own logs. You'll learn exactly which steps you missed.

TTuba E***Expert
Job title
Data protection consultant
Joined
Oct 2023
Message
158

Doki · Backup setup · 2024

#5

I'd also like to touch on the data protection side, because this stage is often skipped.

Personal data processing may come up during testing. Using real data in the test environment, copying production data, or adding screenshots to the report should be evaluated separately.

My recommendation is to add confidentiality and data processing clauses to the contract signed with the test provider, and to use masked data as much as possible. The report's retention period and destruction should also be in writing.

HHakan V***Member
Job title
Data Analyst
Organization type
regional distributor
Joined
Apr 2024
Message
104
#6

A question: how many man-days does the quote for a "comprehensive test" list?

Here's why: this job is measured by duration. A five-day test and a fifteen-day test won't find the same things, and most of the price difference is hidden there. Quotes without man-days can't be compared.

BBarış K***Expert
Job title
Corporate IT manager
Joined
Jun 2023
Message
172
#7

Thanks, I'm going to make this thread an appendix to my budget presentation.

When I asked the man-day question, two of the three quotes came back revised, one didn't reply. The comparison table is actually comparable now.

I also took Yavuz Bey's warning to "itemize the remediation effort" directly into the presentation. We got stuck exactly there last time.

HHasan E***Expert
Job title
Content Editor
Sector
Construction
Organization type
family business
Joined
Dec 2023
Message
88
#8

this approach has a cost which isn't discussed and mistakes made on the penetration test side are usually reversible but expensive.

this is my opinion I'm not claiming it's absolute truth.

PPerihan K***MemberCommunity member
Joined
Jan 2023
Message
152
#9

Exactly, and not many people know this. When making decisions, write down the worst-case scenario too, not just the best.

Hope this helps.

KKemal Ö***Member
Job title
Co-founder
Sector
Cleaning services
Organization type
300-person organization
Joined
Oct 2023
Message
28
#10

I didn't know that. Just because everyone does it doesn't mean it's right.

Proven by experience.

KKader Y***New member
Job title
Quality Assurance Manager
Sector
IT services
Organization type
boutique agency
Joined
Jun 2026
Message
126

Doki · Backup setup · 2026

#11

We experienced almost the exact same thing last year. If you don't write this down from the start, it leads to arguments later.

Good luck with that.

MMetin Y***Member
Job title
Accounting Manager
Sector
Construction
Organization type
120-person company
Joined
Dec 2024
Message
168
#12

I felt relieved reading this answer so its not just me. btw mistakes made on the penetration test side are usually reversible but expensive.

I'm also curious if anyone does it differently.

CCem K***Member
Job title
QA Tester
Sector
IT services
Organization type
chain store
Joined
Sep 2023
Message
138
#13

Let me summarize the topic, since several different answers were given. People defend habits, not processes. Resistance comes from there.

Mistakes made on the penetration test side are usually reversible but expensive. Good luck with that.

ÜÜlkü Ş***MemberCommunity member
Joined
May 2023
Message
346
#14

Thanks a lot, I'll try it today. Processes without records never improve because you don't know what to fix.

This is my opinion, I'm not claiming it's absolute truth.

SSelin T***Member
Job title
Intern
Sector
Logistics
Organization type
300-person organization
Joined
Sep 2022
Message
2

Doki · Corporate website · 2023

#15

I agree, and I'd like to emphasize that. If the notification path is long notifications don't arrive; missing notifications mean delayed incident detection.

The answer varies greatly by industry; there is no one-size-fits-all rule. btw of course, it varies if your situation is different.

PPerihan A***New memberCommunity member
Joined
Sep 2026
Message
7
#16

I felt relieved reading this answer so it's not just me... If 2FA is on, a stolen password alone is useless.

The real issue isn't the number, but what it's based on. Proven by experience.

FFurkanMember
Job title
Social media manager
Joined
May 2024
Message
132
#17

if you're going this route sort this out first. trying to do this alone is the most expensive way.

im also curious if aynone does it differently.

EEsra A***Member
Job title
Accounting Manager
Sector
Leather
Organization type
medium-sized business
Joined
Dec 2024
Message
41
#18

to get into the details: The biggest time-waster for us was not knowing who had the final say.

hope this helps.

IIrmak B***Expert
Job title
Finance Manager
Sector
Logistics
Organization type
a company within a holding
Joined
Jul 2023
Message
150
#19

To get into the details: People defend habits, not processes. Resistance comes from there.

Trying to do this alone is the most expensive way. Hope this helps.

SSinan T***Member
Job title
Marketing director
Sector
Packaging
Organization type
sole proprietorship
Joined
Aug 2024
Message
27

Doki · Log management setup · 2024

#20

I went through the same thing two years ago. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Reply