We're a tight three-person team in London (two developers plus myself) building a mobile app for local courier and delivery dispatch. Before rolling it out to enterprise clients, we wanted to get an independent penetration test done, but the quotes we've received range between 3,500 and 5,000 GBP. Our budget is pretty tight.
The consultant at the security firm was honest with me and said that once the test kicks off, even the simplest misconfigurations will clutter the report and eat up billable time. Basically, we don't want to burn cash having them uncover elementary vulnerabilities.
Before committing budget to an external pentest, we want to sit down with our devs and run through an in-house mobile app security checklist. What should we prioritize checking across code, network traffic, or on-device storage? Any pointers from people with experience here?