forumNew topic

They asked for a "pentest / penetration test" — what does it mean, and does a small business like ours really need one?

SSerkan G***MemberCommunity member
Joined
Feb 2023
Message
13
#1

We have a custom-built web portal where we handle B2B wholesale orders and our dealers check their balances and submit orders. We have around 250 active dealers on the portal and an operations team of 4. Last week, we reached the stage of finalizing a 1,800,000 TL annual supply contract with a major corporate client.

As a contractual condition, the client's information security and risk department asked us for an "up-to-date web application pentest / penetration test report conducted by an independent cybersecurity firm." I called two security firms for quotes; one quoted 35,000 TL, the other 55,000 TL.

We aren't a bank or a massive tech company, just an ordinary SME minding our own business. What exactly is a pentest, and how does it differ from an automated virus or vulnerability scan? Is this genuinely a mandatory, necessary expense for a business of our size, or is it just corporate bureaucracy from big enterprises?

NNevinMember
Job title
Language school
Joined
Apr 2024
Message
92
Most Helpful#2

Short answer: A pentest, or penetration test, is a legal, controlled security audit where authorized security specialists target your systems just like a cyberattacker to identify existing vulnerabilities. It's not just for mega-corporations; it's essential for any system that handles dealer data, account balances, or order details, and it's a standard supplier requirement in enterprise deals.

This audit is completely different from an automated virus scan. Vulnerability scanners only check for known, standard flaws; during a penetration test, experts look for business logic flaws. For instance, vulnerabilities like a dealer altering a URL parameter to view a competing dealer's account statement or tampering with product prices in the cart before checking out can only be discovered through human-driven manual testing.

Your enterprise client demanding this isn't pointless red tape. In supply chain attacks, hackers don't go after the big target directly; they exploit vulnerabilities in smaller vendors that exchange data with them. The corporate client has to make sure no one can pivot into their own network or data through your portal.

For a portal your size, the testing process usually takes 3 to 5 business days. Once the test wraps up, discovered vulnerabilities are reported by risk severity. After your developer patches them, the security firm runs a verification re-test and hands over a clean executive summary report stating "vulnerabilities resolved," which you can then submit to your client.

ZZafer B***Member
Job title
Customer service representative
Sector
Insurance
Organization type
chain store
Joined
Nov 2023
Message
34
#3

When there's a 1,800,000 TL annual contract on the table, don't view a 35,000 TL penetration test as an expense. Audit teams at enterprise clients will never sign a contract without this report. If you refuse, they walk away and the deal goes straight to a competitor who checks that box.

RRıdvan Ç***Member
Job title
Graphic Designer
Sector
Machinery manufacturing
Organization type
early-stage startup
Joined
Mar 2026
Message
38
#4

Define the scope carefully when getting quotes. To keep the cost down, only include the web portal domain your dealers access and the API endpoints; exclude your office network or company mail servers. Make sure the test is performed using a "gray box" approach with an actual dealer user account provided to them.

BBeyza V***Member
Job title
Information Security Specialist
Sector
Education
Organization type
workshop
Joined
Aug 2023
Message
160
#5

Last year we paid 40,000 TL to get one done just to land a deal with a supermarket chain. During the test, it turned out a dealer could download another dealer's entire order history by changing a single parameter. Thank goodness we did it; the commercial reputation hit we'd have taken with our dealers from a data leak would have cost way more than that.

GGökhan C***Member
Job title
Studio Founder
Sector
Education
Organization type
chain store
Joined
Jan 2023
Message
64
#6

Things to watch for when signing with the firm: 1) Put it in the contract that the assigned specialist holds valid cybersecurity certifications (TSE or international equivalents). 2) Ask them to run the tests outside business hours or on a staging server so they don't lock up your database. 3) Confirm that the re-test after remediation is included in the price.

VVildan D***Member
Job title
Quality control inspector
Sector
Electrical-electronics
Organization type
regional distributor
Joined
Apr 2024
Message
160

Doki · Phishing awareness training · 2024

#7

There are plenty of firms out there that just run an automated tool and hand you a 15-page English printout calling it a report. If you drop 35,000 TL on what turns out to be an off-the-shelf scanner dump, the client's infosec team will reject it instantly. Ask the quoting firm point-blank how many hours of manual business logic testing they will perform.

SSenaMember
Job title
Graphic Designer
Organization type
two-branch business
Joined
Jul 2024
Message
86
#8

whatever you do do not send the initial report to the client then the first report is definitely gonna have critical vulnerabilities flagged in red. i mean your dev will fix them the security firm will re-check and sign off and then you send the clean executive summary to the client.

EElif U***Member
Job title
Data entry clerk
Sector
Accounting & advisory
Organization type
workshop
Joined
Oct 2023
Message
93
#9

Corporate entities requiring independent security audits from vendors is a compliance obligation under KVKK and information security management standards. The cost of the requested assessment represents reasonable operational due diligence when weighed against the administrative fines and civil liability that could stem from a potential data breach.

UUfuk B***Member
Job title
Field sales representative
Sector
Paper
Organization type
chain store
Joined
Nov 2024
Message
2
#10

Send the scope in writing to the firm offering 35,000 TL and lock in a contract that includes the re-test. Then send an official note to your client immediately saying "Our penetration test has been scheduled and the report will be delivered to you within 10 days." That way, the contract timeline on the client side stays on track without delays.

ZZehra Y***Member
Job title
Country Manager
Sector
Tourism
Organization type
family business
Joined
Jul 2024
Message
9

Doki · Phishing awareness training · 2024

#11

I'm a small business, let me explain from my side. Security isn't absolute; it's about making attacks not worth the effort.

EEsra D***MemberCommunity member
Joined
Sep 2024
Message
102
#12

Great work.

PPınar Ç***Expert
Job title
Call center representative
Sector
Livestock
Organization type
40-person manufacturing company
Joined
Jan 2022
Message
189
#13

There's a trap here, let me mention it. Don't rely on a single measure; go layer by layer.

MMetin Z***MemberCommunity member
Joined
Nov 2024
Message
249
#14

My perspective changed after experiencing that. Your time to detect an issue directly determines its cost.

Mistakes made on the what is a pentest penetration test side are usually reversible but expensive.

SSena K***Member
Job title
Accounting clerk
Sector
Media and publishing
Organization type
boutique agency
Joined
Feb 2025
Message
2
#15

I'd say don't rush. When making decisions, write down the worst-case scenario too, not just the best.

Correct me if I'm wrong.

YYiğit Y***New member
Job title
Secretary
Sector
Logistics
Organization type
chain store
Joined
May 2026
Message
17
#16

You're right, I've been down that road too. Don't hesitate to ask; those who don't ask always pay more.

İİlker P***Member
Job title
Graphic Designer
Sector
Education
Organization type
early-stage startup
Joined
Nov 2022
Message
162
#17

This is exactly what we experienced. Mistakes made on the what is a pentest penetration test side are usually reversible but expensive.

Security isn't absolute; it's about making attacks not worth the effort.

MMurat K***Member
Job title
Human Resources Manager
Sector
Freight
Organization type
early-stage startup
Joined
Aug 2025
Message
333

Doki · Brand identity · 2023

#18

i feel the same way. if you don't write this down from the start it leads to arguments later.

of course, it varies if your situation is different.

NNuri G***MemberCommunity member
Joined
Jun 2025
Message
158
#19

I'd appreciate it if you shared the outcome. If 2FA is on, a stolen password alone is useless.

NNecati Ş***VeteranCommunity member
Joined
Nov 2024
Message
91
#20

exactly, and not many people know this. just because everyone does it doesn't mean it's right.

Reply