We have a custom-built web portal where we handle B2B wholesale orders and our dealers check their balances and submit orders. We have around 250 active dealers on the portal and an operations team of 4. Last week, we reached the stage of finalizing a 1,800,000 TL annual supply contract with a major corporate client.
As a contractual condition, the client's information security and risk department asked us for an "up-to-date web application pentest / penetration test report conducted by an independent cybersecurity firm." I called two security firms for quotes; one quoted 35,000 TL, the other 55,000 TL.
We aren't a bank or a massive tech company, just an ordinary SME minding our own business. What exactly is a pentest, and how does it differ from an automated virus or vulnerability scan? Is this genuinely a mandatory, necessary expense for a business of our size, or is it just corporate bureaucracy from big enterprises?