forumNew topic

Asked for a penetration test — what’s the difference between that and a pen test, which one should I get?

CCanMember
Job title
SEO Specialist
Joined
Mar 2024
Message
172
#1

We're a 25-person automotive supplier based in Bursa. One of our major OEM clients requested a security test report on our systems as part of their annual vendor audits.

So we reached out to an IT security firm. The quote they sent over lists two separate line items: the first is labeled "Sızma Testi" for 35,000 TL, and the second is labeled "Penetrasyon Testi" for 65,000 TL. When we asked their rep, they claimed these involve different levels of depth and that we should pick based on what our client wants, but they couldn't give us a clear technical distinction.

Don't both terms mean the exact same thing? What is the actual difference between them, and which one do we need to pass a corporate audit in our situation?

İİsmail V***Member
Job title
Board member
Sector
Advertising and promotion
Organization type
boutique agency
Joined
May 2023
Message
2
Most Helpful#2

Short answer: Penetration testing and intrusion testing are the exact same thing; intrusion testing is simply the direct Turkish equivalent of the English term 'penetration test'. Any consulting firm presenting these to you as two distinct services with separate quotes is either oblivious to basic terminology or assuming you do not know any better and trying to squeeze extra budget out of you.

Here's the reality: the actual distinction in IT security is between a "vulnerability assessment" and a "penetration test." Most likely, their cheaper option is a vulnerability scan that runs automated software to list known vulnerabilities across your systems. Their expensive option is a true penetration test where a specialist actively attempts to exploit those flaws, exfiltrate data, and escalate privileges. Splitting these into two services and calling one "sızma" and the other "penetrasyon" is utterly unprofessional.

If your automotive OEM client is asking for a report for an audit, they definitely aren't asking for an automated scan—they want a comprehensive penetration test compliant with TSE standards or international methodologies. Go back to that firm and demand a written explanation of the methodology differences between both items. Honestly, since trust is already broken, I'd suggest skipping them entirely and getting direct penetration test quotes from other accredited security firms with a clearly defined scope (like the number of external IPs, internal servers, and web interfaces).

KKaan D***Member
Job title
Secretary
Sector
Education
Organization type
workshop
Joined
Jul 2024
Message
2
#3

The oldest trick in the book: 35 thousand lira when written in Turkish, 65 thousand lira when using fancy foreign buzzwords. Throw in "ethical hacking" as another line item and they'd probably push the bill to 100k. I'd run far away from that company.

BBurcu A***Member
Job title
IT Manager
Sector
Automotive aftermarket
Organization type
workshop
Joined
Jun 2024
Message
49
#4

The real distinction in the industry is between automated scanning and manual exploitation. An automated scan just probes ports with tools and spits out a report. In an actual penetration test, an ethical hacker pushes every discovered vulnerability to its limits. Your client will definitely want a full pen test report that covers verification and privilege escalation steps.

SSelim K***Member
Job title
Sales Manager
Sector
Media and publishing
Organization type
120-person company
Joined
Mar 2025
Message
305

Doki · SEO consulting · 2024

#5

What specific standard does your client's audit specification outline? Corporate companies usually require a TSE-certified pen test or adherence to a specific methodology. Also, how many external IPs and internal servers need to be tested?

HHilal B***ExpertCommunity member
Joined
Feb 2026
Message
66
#6

We went through a similar vendor audit. We had a pen test done for 16 external IPs and 2 web portals. We paid 38,000 TL, it took 4 business days, and they delivered a 32-page technical report with proof of concepts. The OEM approved it without any issues.

HHande A***MemberCommunity member
Joined
May 2023
Message
377
#7

Ask any new vendor these three questions: 1) Does the test include manual validation? 2) How many systems are covered in the scope? 3) Do you provide a free re-test after we patch the findings? Go with whoever gives you straight answers.

HHasan S***MemberCommunity member
Joined
Jan 2024
Message
114
#8

they're the exact same thing mate. they put a separate prce just because one sounds more foreign and corporate, don't pay that higher price. get quotes from two other companies and you'll see what i mean.

EEsra D***Member
Job title
SME Consultant
Joined
Feb 2024
Message
124
#9

One thing to watch out for: once the test wraps up, they usually give you 15 to 30 days to fix the reported vulnerabilities. After you patch them, the firm must come back and issue a final sign-off report confirming the issues have been resolved. Make sure this re-test is included in the quoted price.

KKader Y***New memberCommunity member
Joined
Jun 2026
Message
26
#10

is there any risk that our systems might crash or production might halt during this test? if our accounting server locks up all our invoicing comes to a dead stop.

UUfuk B***MemberCommunity member
Joined
Feb 2024
Message
1
#11

If I understood correctly you're saying: Having backups accessible on the same network and with the same identity makes them part of the target.

If 2FA is on, a stolen password alone is useless. This is my opinion, I'm not claiming it's absolute truth.

ZZeynep K***MemberCommunity member
Joined
Feb 2024
Message
41
#12

Thanks, this was very helpful. Processes without records never improve, because you don't know what to fix.

People defend habits not processes. Resistance comes from there. This is my opinion I'm not claiming it's absolute truth.

TTaner B***MemberCommunity member
Joined
Jun 2023
Message
4
#13

Good call starting this thread.

MMurat T***New member
Job title
Graphic Designer
Sector
Furniture manufacturing
Organization type
chain store
Joined
Sep 2026
Message
9
#14

I agree. Taking measures without an inventory leaves doors you haven't seen open.

Just leaving this note it might be useful.

NNazlı K***MemberCommunity member
Joined
Apr 2024
Message
104
#15

I agree with this. anyway processes without records never improve, because you dont know what to fix.

The harder it is to reverse a decision the slower you should make it. If you have questions write them; I'll answer as best I can.

ÖÖzgür D***Member
Job title
Front office accounting
Sector
Automotive aftermarket
Organization type
20-person company
Joined
Oct 2022
Message
2
#16

I've been dealing with this for a long time. Most incidents start with a leaked password, not a vulnerability.

ÖÖzgür Y***MemberCommunity member
Joined
Mar 2022
Message
385
#17

This thread is archived. Don't rely on a single measure; go layer by layer.

If you have questions, write them; I'll answer as best I can.

ZZehra D***Expert
Job title
IT manager
Sector
Food wholesale
Organization type
120-person company
Joined
Feb 2025
Message
44

Doki · Server maintenance contract · 2024

#18

I'll argue the opposite, don't get mad. If 2FA is on, a stolen password alone is useless.

I'm also curious if anyone does it differently.

EEfe K***Member
Job title
Operations manager
Sector
Leather
Organization type
a company within a holding
Joined
Aug 2024
Message
236
#19

I think it's hard to be that definitive about what is a penetration test. If you get three different answers on a topic, the question was asked wrong.

Just leaving this note, it might be useful.

GGizem K***Member
Job title
Human Resources Manager
Sector
Logistics
Organization type
workshop
Joined
Nov 2022
Message
49
#20

Let me summarize the topic since several different answers were given. If you get three different answers on a topic, the question was asked wrong.

Reply