- Job title
- IT manager
- Sector
- Construction
- Organization type
- workshop
- Joined
- Aug 2026
- Message
- 292
Doki · Interface design · 2025
We run a B2B e-commerce site based in Chicago supplying wholesale packaging and supplies to restaurants. We get around 45,000 unique monthly visitors and do about $20,000 in online orders. Our stack runs on a popular open-source CMS.
Yesterday a cybersecurity agency called claiming our site is vulnerable and tried to sell us a recurring vulnerability scanning package for $150 a month. The sales rep tried to scare us by saying "Google could blacklist your site at any moment, if your customers see a red warning screen you'll lose all your traffic."
What I'm wondering is: can't we just monitor our site's security for free through Google's own webmaster tools, Search Console, and transparency tools? Will Google alert us in time if we get malware or hacked, or are these kinds of paid scanning services genuinely necessary?