- Job title
- Graphic Designer
- Sector
- Machinery manufacturing
- Organization type
- early-stage startup
- Joined
- Mar 2026
- Message
- 38
We are a 16-person SaaS startup offering B2B logistics and fleet tracking software. We process vehicle routing and shipment data for around 140 enterprise clients on our cloud servers. Every year, we regularly outsource a standard penetration test with an average budget of 70,000 TL. These tests usually scan and report vulnerabilities in our web interface and APIs.
Last week, a cybersecurity consultancy approached us pitching an "AI-driven red team" service instead of a traditional pentest. They want 190,000 TL on an annual subscription model, claiming the AI will constantly run autonomous attack scenarios and social engineering attempts. For an SMB like us with our own small server cluster and standard REST APIs, is this actually necessary, or is it just classic pentesting wrapped in marketing fluff?