- Job title
- Human Resources Specialist
- Sector
- Consulting
- Organization type
- sole proprietorship
- Joined
- Jul 2024
- Message
- 48
We're an 8-person team in Chicago providing payroll and ops software to mid-market enterprise clients. Last week a major prospect we've been in talks with requested an up-to-date "penetration test report" before signing their annual contract. I don't come from a technical cybersecurity background; up until now we've just managed fine with standard firewalls and endpoint antivirus software.
I reached out to a few cybersecurity firms for quotes and proposals came back between 3,500 and 8,000 USD. I mean the consultants I spoke with keep throwing around technical jargon, and I still don't completely grasp what I'm actually paying for or what the scope of this work entails.
In plain English what exactly is a penetration test? Would an automated vulnerability scan report satisfy this requirement or does a human expert actually need to hack into the system? For a small shop like ours, is this truly a non-negotiable requirement at this stage?