forumNew topic

They told us to "get a web pentest" — what is this exactly, and is it really necessary for our website?

YYiğit K***New member
Job title
Marketing director
Sector
Sports and fitness
Organization type
workshop
Joined
Sep 2026
Message
7

Doki · Server maintenance contract · 2023

#1

We are a 5-person boutique design and decoration studio. We don't do online sales or take credit card payments through our site. It's just photos of our work, a contact form, and a WhatsApp button. Last week, we submitted a bid to supply furniture to a major hotel chain. Their corporate procurement department sent over a vendor security form asking for an up-to-date web pentest report for our website.

We had no clue what that meant, so we asked our web hosting provider. They told us web pentesting is something we'd have to get from an external cybersecurity firm. We reached out to one, and they quoted 25,000 TL just to scan a single site and produce a report.

What does this actually do for a basic portfolio site that doesn't even handle credit card info? What does a web pentest look for, and is it truly mandatory for small businesses like ours?

KKader A***Member
Job title
Store Manager
Sector
Cosmetics
Organization type
two-branch business
Joined
Nov 2022
Message
183
Most Helpful#2

Short answer: A web pentest (penetration test) is a controlled security assessment that looks at vulnerabilities in your site's code and host server from the perspective of an ethical hacker, reporting whether they can be exploited. Even if your site doesn't process payments, form fields, server configurations, and admin panel login pages fall directly within its scope.

Even simple portfolio sites carry specific risks attackers like to target. During a web pentest, security specialists test your contact forms to see if malicious files can be uploaded to the server. They check whether underlying software is up to date, test admin logins against brute-force attacks, and verify whether your site could be used as a stepping stone to launch attacks against other organizations.

The main reason hotels request this is to guard against indirect threats entering their network or hurting their reputation through vendors. If your site gets compromised, visitors could be redirected to malicious domains, or phishing content targeting hotel staff could be hosted there. If your budget is tight, let security firms know your site is just a few static pages and request a narrower vulnerability scan, which could bring the cost down to 10,000 TL to 15,000 TL.

EElif E***Member
Job title
Sales Manager
Sector
Logistics
Organization type
medium-sized business
Joined
Feb 2024
Message
38
#3

unfortunately, you run into bureaucratic roadblocks like this all the time with large enterprise clients. like it's not the buyer interested in your furniture who cares; their IT director makes that checklist mandatory and if you want the job, you usually have no choice but to get the report.

Correction: I misremembered the figure, it was a bit lower.

NNuri Y***ExpertCommunity member
Joined
Oct 2023
Message
246
#4

We faced the exact same demand last month for our 8-page brochure site. The first quote was 30,000 TL. We scoped it strictly to a single domain and static forms, got billed 12,000 TL for two days of work, handed over the report, and the contract was approved.

PPınar Ç***Expert
Job title
Call center representative
Sector
Livestock
Organization type
40-person manufacturing company
Joined
Jan 2022
Message
189
#5

Paying 25,000 TL for a pentest on a static site that doesn't process payments is a total waste of money. Send the hotel's procurement officer a formal letter explaining that the site has no user accounts or database and only features a contact form. They might give you an exemption.

ZZerrin M***MemberCommunity member
Joined
Feb 2024
Message
1
#6

The process roughly goes like this: 1) You provide the security firm with your site URL and stack details. 2) The experts perform simulated attacks on your site. 3) They compile discovered vulnerabilities and remediation steps into a report. 4) Your hosting provider patches the issues, and the final verification report is submitted to the client.

ZZuhalMember
Job title
Store Manager
Organization type
chain store
Joined
Jul 2024
Message
82
#7

Make sure to ask any firm quoting you how many days it will take to deliver the report and whether a re-test after fixing the vulnerabilities is included in the price. Some firms charge extra for that second review.

EEfe Y***Member
Job title
Site Manager
Sector
Leather
Organization type
boutique agency
Joined
Jul 2025
Message
367
#8

if it's literally just a contact form take it down and replace it with an email address. ask the client if that gets you out of the pentest requirement imo.

NNuri G***MemberCommunity member
Joined
Jun 2025
Message
158
#9

If the profit margin on the hotel contract easily covers the cost of this test, just get it done without dragging things out. Enterprises rarely make exceptions to security protocols, and if you push back, they might just go with another vendor.

AAyşe Ç***Member
Job title
Chief Information Security Officer
Sector
Construction
Organization type
cooperative
Joined
Feb 2025
Message
27
#10

There's a common mistake people make when doing this. Your time to detect an issue directly determines its cost.

Taking measures without an inventory leaves doors you haven't seen open. If you post the result here, it will help others too.

EEbru O***Member
Job title
Quality control inspector
Sector
IT services
Organization type
8-person team
Joined
Jan 2022
Message
139
#11

Good call starting this thread.

GGülayMember
Job title
Textile workshop
Joined
Oct 2023
Message
84
#12

There's also a measurement aspect to this. When making a decision, first look at what data you have on hand.

Proven by experience.

UUğur K***ExpertCommunity member
Joined
Mar 2023
Message
44
#13

Here's how it went for us. The real issue isn't the number, but what it's based on.

If I were you Id go this route.

FFiliz U***Member
Job title
Social media manager
Sector
Consulting
Organization type
two-branch business
Joined
Sep 2025
Message
1
#14

Could you elaborate on that? Everything goes well for the first three months; problems arise in the fourth.

Most time waste accumulates in tasks waiting for approval. Correct me if I'm wrong.

YYavuz B***MemberCommunity member
Joined
May 2025
Message
59
#15

Id appreciate it if you shared the outcome.

MMerve Y***New member
Job title
Production planning
Sector
E-commerce
Organization type
medium-sized business
Joined
Jul 2026
Message
313
#16

I have a question, don't want to go off-topic though. When you try to change everything at once, nothing settles.

BBeyza D***Member
Job title
Sales Manager
Sector
E-commerce
Organization type
a company within a holding
Joined
Jul 2023
Message
197
#17

The opposite happened to me, that's why I'm writing. Taking notes for two weeks yields better results than a six-month estimate.

That's all, sorry if I went on too long.

AAli A***ExpertCommunity member
Joined
Aug 2024
Message
287
#18

I'd say don't rush. Your time to detect an issue directly determines its cost.

TTolga T***Member
Job title
Software developer
Sector
Livestock
Organization type
a company within a holding
Joined
Jun 2023
Message
1
#19

Here's how it went for us. An untested backup is not a backup.

I'm also curious if anyone does it differently.

RRecep K***MemberCommunity member
Joined
Mar 2023
Message
41
#20

You're right I've been down that road too. If permission and scope aren't in writing don't start that test.

I'm also curious if anyone does it differently.

Reply