forumNew topic

Clients want a network penetration test report, what exactly gets checked in our infrastructure during this?

IIrmak V***Member
Job title
Front office accounting
Sector
E-commerce
Organization type
a company within a holding
Joined
Feb 2025
Message
312
#1

We are a 12-person team based in Moscow providing B2B logistics integration software. We have 3 cloud servers, a small local network at our main office, and a VPN setup for remote employees. We spend around 75,000 RUB per month on server infrastructure.

Two large enterprise retail clients we want to work with requested a network penetration test report from an independent third party as part of their vendor info-sec evaluation. The first security firm we got a quote from asked for 300,000 RUB just for an external network test and said it would take two weeks.

Honestly, what does the process actually entail for an infrastructure this size? What will the testers actually check on our systems, is there any risk of them crashing things, and what standards does the report need to meet to convince enterprise clients?

SSinanMember
Job title
Software instructor
Joined
Dec 2023
Message
186

Doki · E-commerce infrastructure · 2025

Most Helpful#2

Short answer: A network pen test is a process where security pros run controlled attacks against your systems to identify exposed entry points misconfigurations, and unauthorized access vulnerabilities. The assessment your clients are asking for usually verifies whether your public-facing IPs and external services comply with enterprise security standards.

The process generally consists of three main phases: scoping active testing, and reporting. First, the rules of engagement are documented; defining which IP blocks will be scanned testing hours and guardrails to prevent downtime. During the external test, testers examine open ports, unpatched services, SSL/TLS encryption flaws, VPN gateways, and firewall rules using both manual and automated methods. The goal isn't to break the system, but to identify and document entry points an attacker could exploit.

In the reporting phase, discovered vulnerabilities are categorized as critical, high, medium and low. A report that satisfies enterprise clients can't just be an automated scanner export; it must include how the vulnerability could be exploited, the business impact, and recommended technical remediation steps.

For a small setup, 300,000 RUB for external-only testing is a steep opening quote; similar footprints with 3-5 IPs usually get audited for between 150,000 and 220,000 RUB. When signing the contract, make sure to demand a free retest clause after you patch the findings in the report.

ZZeynep E***Member
Job title
Customer service representative
Sector
Energy
Organization type
regional distributor
Joined
Apr 2025
Message
53
#3

Did the info-sec questionnaire from your clients specifically ask for an "external network" or an "internal network" test? Enterprises often just send out generic boilerplate forms. If the API endpoints and web services handling client data are strictly hosted in the cloud, you can cut costs by excluding the office LAN from scope.

EEsra U***MemberCommunity member
Joined
Feb 2026
Message
160
#4

Key things they'll check: exposed SSH and RDP ports, VPN cipher suites, DNS zone transfer issues, and outdated web server software. Testers don't take systems down; if they find a flaw, they capture proof via screenshots before attempting privilege escalation or data extraction, and stop there.

ÖÖzgür B***MemberCommunity member
Joined
Feb 2023
Message
34
#5

Ran into the exact same requirement last year, paid 180,000 RUB for our Moscow-based 4-server environment. Testing took 4 business days, report took 3 days. They found 2 medium-severity auth flaws and an outdated library. We patched them, had them re-test, and the client approved the report without friction.

HHatice A***MemberCommunity member
Joined
Dec 2023
Message
2
#6

Watch out for shops quoting 50,000 to 70,000 RUB. Most of them just run an automated scanner and hand over the raw PDF output as their "report." Security auditors on the enterprise side will spot that immediately and reject it.

PPerihan K***MemberCommunity member
Joined
Jan 2023
Message
152
#7

Make sure to get these three clauses in writing before signing: 1) Testing must happen outside business hours and align with backup windows, 2) Immediate notification if a critical vuln is discovered during testing, 3) A free one-time retest within 30 days of fixing the issues.

ÖÖmer D***Member
Job title
Field sales representative
Sector
Automotive aftermarket
Organization type
medium-sized business
Joined
Aug 2024
Message
341
#8

definitely take fresh snapshot backups of all vms before the test starts. also don't push any major updates or deploy code on designated testing days, it messes up the traffic logs.

IIrmak B***Member
Job title
Data Analyst
Sector
Furniture manufacturing
Organization type
sole proprietorship
Joined
Feb 2025
Message
46
#9

It pays to ask for the auditing firm's staff certifications. Having technical personnel with internationally recognized ethical hacking or network security credentials ensures your audit report gets fast-tracked by your enterprise client's info-sec board.

NNazlı P***Veteran
Job title
System support specialist
Sector
Chemistry
Organization type
20-person company
Joined
Dec 2023
Message
2
#10

Noted, thanks.

KKader K***MemberCommunity member
Joined
Apr 2024
Message
393
#11

Here's how it went for us. Payment information changes are never verified through the channel they came from.

When making a decision, first look at what data you have on hand. Proven by experience.

KKadir G***VeteranCommunity member
Joined
Feb 2023
Message
14
#12

Timely topic.

HHilal Ö***Member
Job title
Social media manager
Sector
Tourism
Organization type
boutique agency
Joined
Apr 2024
Message
215
#13

We need to make a distinction here. Everything goes well for the first three months; problems arise in the fourth.

Of course, it varies if your situation is different.

KKadir E***Member
Job title
Administrative manager
Sector
Logistics
Organization type
a company within a holding
Joined
Jul 2024
Message
10
#14

Just a heads-up. An untested backup is not a backup.

Trying to do this alone is the most expensive way. If I were you, I'd go this route.

FFiliz A***ExpertCommunity member
Joined
May 2025
Message
14
#15

Could you elaborate on that? Most time waste accumulates in tasks waiting for approval.

That's all, sorry if I went on too long.

RReyhan N***MemberCommunity member
Joined
May 2022
Message
223
#16

You're right. Security isn't absolute; it's about making attacks not worth the effort.

FFeyza V***Expert
Job title
QA Tester
Sector
Food wholesale
Organization type
a company within a holding
Joined
Jun 2023
Message
54
#17

I completely agree. Your time to detect an issue directly determines its cost.

Having backups accessible on the same network and with the same identity makes them part of the target.

DDamla Z***MemberCommunity member
Joined
Oct 2024
Message
202
#18

I'm curious too. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Your time to detect an issue directly determines its cost. Just leaving this note, it might be useful.

İİlker A***MemberCommunity member
Joined
Feb 2023
Message
292
#19

I've been down this road, let me tell you. Everything goes well for the first three months; problems arise in the fourth.

Proven by experience.

AAli O***Member
Job title
Human Resources Specialist
Sector
Jewelry
Organization type
cooperative
Joined
Apr 2025
Message
360
#20

I'm a small business, let me explain from my side. Just because everyone does it doesn't mean it's right.

Reply