We are an 8-person team based in Paris running a B2B e-commerce platform for wholesale orders. The site stores current account details, past invoices, and order details for our corporate clients. Last week, we received a quote of 4,500 EUR from an independent third-party expert for a comprehensive web penetration test. Honestly, with our current cash flow, that budget is a bit of a stretch for us right now.
Before accepting the quote, we want to at least scan for and patch obvious vulnerabilities, basic misconfigurations, and simple flaws on our own. The developer on our team knows general web development, but isn't a security specialist. We’d like to kick off the process with a pre-audit we can conduct ourselves.
What should our DIY site security testing cover, and which checks can we verify using free or basic methods? Also, at what point do these self-tests fall short and professional services become inevitable?