forumNew topic

They brought up "penetration testing" — is it really necessary for our scale, what does it actually do?

DDoruk Ş***MemberCommunity member
Joined
Oct 2024
Message
218
#1

We are a wholesale spare parts business with 14 employees based in Bursa. About six months ago, we had a custom B2B dealer portal built where our clients can place orders, view their account balances, and check invoices. The agency that built the system reached out last week, saying that as part of annual maintenance, we need to have a penetration test performed, quoting an extra budget of 45.000 TL for it.

Frankly, I am not very technical. We already have a firewall and an SSL certificate on the server, and daily backups are taken. I briefly looked it up online, but the concepts seemed overwhelming. I can't tell whether this work proposed by the agency is genuinely a necessary security measure or just a standard upsell package targeted at small businesses.

What exactly does a penetration test cover, and for a portal serving a limited number of corporate clients like ours, is it worth incurring this cost?

BBerenMember
Job title
Product designer
Joined
Mar 2024
Message
112
Most Helpful#2

Short answer: A penetration test is a controlled cyberattack simulation where a qualified security professional acts as an authorized attacker to detect vulnerabilities in your system before malicious actors do. An SSL certificate or firewall only locks the front door; a penetration test checks whether the windows, ventilation vents, and back doors are locked by actively trying to breach them.

You can determine whether a penetration test is necessary for a B2B portal at your scale by looking at three criteria: 1) What data resides on the portal, 2) Whether the software is custom-built or a ready-made platform, 3) The legal and commercial risk a data breach would pose to you. If your dealers' statement transactions, tax numbers, account balances, and order histories are stored on the portal, an unauthorized party breaching another dealer's dashboard leads to severe administrative penalties under KVKK.

If the software was custom-coded from scratch, the likelihood of authorization flaws caused by developer oversights is quite high. In current market terms, 45.000 TL is a standard figure for a small-scope web application test; however, before paying that, you need to clarify the scope of the test. It is essential that the test does not merely consist of running an automated scanner and generating a report, but also includes manual business logic testing.

EEfe A***Member
Job title
IT manager
Sector
Livestock
Organization type
early-stage startup
Joined
Apr 2024
Message
2
#3

It makes no sense for the agency to run a penetration test on code they wrote themselves. You can't expect them to find and report their own mistakes. Even if you decide to go ahead with this test, get a quote from an independent firm that specializes exclusively in cybersecurity rather than the agency that developed the portal.

VVeli Ç***New member
Job title
Call center representative
Sector
Machinery manufacturing
Organization type
cooperative
Joined
Jun 2026
Message
387
#4

Penetration testing specifically checks for Broken Object Level Authorization, meaning unauthorized data access flaws. For instance, when dealer A logs in and changes the invoice number in the browser URL from 101 to 102, can they see dealer B's invoice? A firewall won't catch that; only a penetration test will.

KKorhanExpert
Job title
B2B Sales Manager
Joined
Sep 2023
Message
162
#5

Last year, we paid 35.000 TL to an independent expert to test our portal serving 20 dealers, similar in scale to yours. The resulting report revealed that two dealers could see each other's discount rates. If that leak had gotten out in the market, our commercial reputation would have been ruined. It was totally worth the money.

TTaner E***Member
Job title
Purchasing manager
Sector
Leather
Organization type
early-stage startup
Joined
Jun 2023
Message
132
#6

the agency will probably just run an automated tool and hand you a pdf export. like ask for a scope document check if it specifies how many hours of manual testing will be done imo.

edit: typed from phone, sorry for typos.

ÜÜmit K***Member
Job title
Operations manager
Sector
Jewelry
Organization type
a company within a holding
Joined
May 2022
Message
406
#7

Do you process credit card payments through the portal? If card details are stored on the system or routed through your own server instead of a hosted payment gateway, testing is an outright necessity, not a luxury.

ÖÖmer I***MemberCommunity member
Joined
Nov 2024
Message
1
#8

Before accepting the quote, ask the agency this: "Will this test be grey box or black box, and is remediation retesting included in the price once the detected vulnerabilities are patched?" Without a retest, the report ends up being useless scrap paper.

TTolga Ş***Expert
Job title
Production Manager
Sector
Livestock
Organization type
workshop
Joined
May 2023
Message
38
#9

Two years ago hackers breached the portal of an acquaintance who runs a textile wholesale business and sold their entire customer list and pricing sheets to a competitor. Neither backups nor SSL could save them. Ever since we have made security audits routine after every major release.

AAhmet Z***MemberCommunity member
Joined
Feb 2024
Message
25
#10

I have a question. Solutions that work at a small scale collapse when you grow; I learned this late.

Solutions that work at a small scale collapse when you grow; I learned this late. If you post the result here, it will help others too.

OOya Ç***Member
Job title
Quality control inspector
Sector
Media and publishing
Organization type
regional distributor
Joined
Oct 2023
Message
248
#11

saved. people defend habits, not processes. btw resistance comes from there.

İİlknur A***Expert
Job title
Quality Assurance Manager
Sector
Law
Organization type
cooperative
Joined
Mar 2023
Message
11

Doki · SEO consulting · 2023

#12

Quick summary for newcomers: An untested backup is not a backup.

Processes without records never improve, because you don't know what to fix. Good luck with that.

FFurkan K***MemberCommunity member
Joined
Nov 2023
Message
141
#13

I agree, and I'd like to emphasize that. Everyone rushing into what is penetration testing gets stuck at the same point.

That's all, sorry if I went on too long.

ÖÖzge T***Expert
Job title
Brand Consultant
Organization type
regional distributor
Joined
Jun 2023
Message
164

Doki · E-commerce infrastructure · 2023

#14

Do you think this works at any scale? The real issue isn't the number, but what it's based on.

I'm also curious if anyone does it differently.

KKoray Y***Member
Job title
Front office accounting
Sector
Paper
Organization type
family business
Joined
Dec 2024
Message
65
#15

The discussion got scattered, let me summarize. If you get three different answers on a topic, the question was asked wrong.

If you post the result here, it will help others too.

SSinan B***Expert
Job title
Product Manager
Sector
Media and publishing
Organization type
two-branch business
Joined
Apr 2025
Message
223
#16

I didn't know that.

BBetülExpert
Job title
Management consultant
Joined
Oct 2023
Message
164
#17

We've heard this a lot, but it never happened like that for us. An untested backup is not a backup.

If I were you, I'd go this route.

ÖÖzlemMember
Job title
Advertising agency
Organization type
20-person company
Joined
May 2024
Message
108
#18

Good call starting this thread.

HHavva Ç***Member
Job title
System administrator
Sector
Catering
Organization type
sole proprietorship
Joined
Apr 2023
Message
55
#19

Great work. If it's your first time, start small; scaling comes later.

If I were you, I'd go this route.

TTolgaNew member
Job title
Developer
Organization type
cooperative
Joined
Nov 2024
Message
41
#20

I have a question. Hasty decisions become decisions you have to fix six months later.

If you get three different answers on a topic, the question was asked wrong. Hope this helps.

Reply