forumNew topic

We were asked to get a penetration test done — what does a real-world example look like, and do we actually need it?

KKaan B***Member
Job title
Infrastructure engineer
Joined
Mar 2024
Message
108
#1

We are a 7-person team based in London developing B2B order and inventory management software. Last month, we sat down with an enterprise retailer that has 80 stores across the UK. We are on the verge of signing a licensing deal worth 52,000 GBP annually, but their IT security team added a prerequisite to the specs: an up-to-date penetration testing report from an independent cybersecurity firm.

Up until now, we've only run our own internal code reviews; our servers sit behind a firewall, we use SSL, and our database is encrypted. But we don't fully understand how these corporate-mandated penetration tests actually work or what they're truly looking for in practice.

How does this process work for a small SaaS startup? Does anyone have a real example of a pentest report, and what exactly are these ethical hackers hunting for in your system? Also, what does a test like this usually run, and is it worth taking on the expense before the contract is officially signed?

İİlker B***MemberCommunity member
Joined
Jan 2024
Message
400
Most Helpful#2

Short answer: A penetration test is a controlled audit where ethical hackers attempt to breach your system just like a real malicious actor to uncover and document vulnerabilities. Your enterprise client requiring this is standard vendor risk management, and it's practically mandatory to close enterprise B2B deals.

Let me explain with a concrete example: take the URL where a user views their order details in your web app, say something like orders/1042 in the browser. An ethical hacker logs in with low-privilege customer credentials and deliberately alters the number in the address bar to 1041. If your system fails to validate authorization server-side, they might suddenly see a competitor's invoice, item list, and totals. This is known as broken object level authorization (BOLA/IDOR), and it's one of the most common critical vulnerabilities in B2B software.

The process usually unfolds like this: First scope is defined; for instance, limiting it strictly to your web application and API endpoints. You provide the security firm with two separate test accounts. Over the course of 3 to 5 business days their testers evaluate your application using both automated scanners and tailored manual attacks.

As for the cost: for a B2B SaaS panel and API footprint of your size boutique cybersecurity firms in the UK typically charge between 2,500 GBP and 5,500 GBP for a 3-4 day engagement. Once the test concludes, you patch the findings, and the firm runs a free re-test to issue a clean final report.

BBurak U***Member
Job title
Marketing manager
Sector
Construction
Organization type
boutique agency
Joined
Jul 2025
Message
67
#3

Enterprise retailers are terrified of supply chain risk. If your database is going to hold their store inventory or revenue figures, they have to justify that to their board. Don't make the mistake of exporting an automated vulnerability scanner report and passing it off as a pentest; their InfoSec team will spot it on page one and it'll kill the deal.

DDamla Y***ExpertCommunity member
Joined
Feb 2025
Message
57
#4

We had our first pentest done last autumn for our logistics SaaS, roughly the same size as yours. It took 4 business days and cost us 3,200 GBP. They discovered 6 issues in total, one being critical. We were very confident in our code, but an information leak in our server response headers was revealing our exact database version. We patched everything in a week, and the client signed off on the contract the moment they saw the clean report.

FFikretMember
Job title
Industrial automation
Organization type
20-person company
Joined
Nov 2023
Message
118

Doki · Phishing awareness training · 2026

#5

Be very careful when drafting the scope agreement. Do not include your cloud infrastructure's hosting provider in the scope; only include your own custom code, authorization mechanisms, and APIs. Otherwise, they'll try to scan the cloud provider's services, doubling both the testing time and your budget.

SSinan Z***Member
Job title
Studio Founder
Sector
Media and publishing
Organization type
early-stage startup
Joined
Feb 2023
Message
165
#6

Don't jump on the first quotes sent by security firms. Many agencies ask for absurd prices like 10.000 GBP, only to run automated tools and call it a day. Get 2-3 different quotes from boutique, independent, certified senior experts instead. Make sure to confirm that the report will follow internationally recognized methodologies.

EElif B***Member
Job title
Store associate
Sector
Chemistry
Organization type
workshop
Joined
May 2023
Message
55

Doki · SEO consulting · 2024

#7

For a contract that brings in 52.000 GBP annually, a testing cost of around 3.000 GBP is definitely a customer acquisition cost worth paying. Plus, once you have this report, you'll be able to present it as proof of trust to other enterprise clients you negotiate with over the next 12 months.

NNecati Ş***VeteranCommunity member
Joined
Nov 2024
Message
91
#8

what happens if vulnerabilities are found during the test and we cant patch them right away? anyway does the security firm send the report directly to the client or do they give it to us first?

Correction: I misremembered the figure, it was a bit lower.

FFiliz P***ExpertCommunity member
Joined
Nov 2024
Message
14
#9

The standard process consists of 4 steps: 1) Scoping and signing an NDA, 2) Attack simulation in a staging environment (a cloned server with no live data), 3) Handing over an interim report listing the vulnerabilities to your team for remediation, 4) Verifying the fixes and preparing the final clean report to be submitted to the client.

SSelin B***Member
Job title
Graphic Designer
Sector
Energy
Organization type
a company within a holding
Joined
Jun 2022
Message
29
#10

Let me share what happened to me; it might be useful. like most incidents start with a leaked password, not a vulnerability.

Proven by experience.

KKadir E***Member
Job title
Administrative manager
Sector
Logistics
Organization type
a company within a holding
Joined
Jul 2024
Message
10
#11

How did you solve this? If you don't write this down from the start, it leads to arguments later.

When making a decision, first look at what data you have on hand. That's all, sorry if I went on too long.

RRecep T***New member
Job title
Field sales representative
Sector
Logistics
Organization type
a company within a holding
Joined
Aug 2026
Message
39

Doki · Backup setup · 2023

#12

I think it's hard to be that definitive about penetration test example. If you scold false alarms, nobody will report again.

If I were you, I'd go this route.

HHüseyin K***MemberCommunity member
Joined
Jan 2024
Message
368
#13

Noted, thanks.

NNazlı T***New member
Job title
Accounting clerk
Sector
Seafood
Organization type
40-person manufacturing company
Joined
May 2026
Message
32
#14

I'm curious too. When we decide without measuring, we always end up in the same place.

Security isn't absolute; it's about making attacks not worth the effort. I'm also curious if anyone does it differently.

AAycan Ö***MemberCommunity member
Joined
Jul 2023
Message
321
#15

Thanks for posting. If it's your first time, start small; scaling comes later.

Everyone rushing into penetration test example gets stuck at the same point. Proven by experience.

KKaan O***MemberCommunity member
Joined
Feb 2023
Message
16
#16

I partly agree, partly disagree. If you get three different answers on a topic, the question was asked wrong.

Solutions that work at a small scale collapse when you grow; I learned this late. Of course, it varies if your situation is different.

SSerkan U***Member
Job title
Site Manager
Sector
Education
Organization type
medium-sized business
Joined
May 2025
Message
312
#17

Let me share my experience. Everyone rushing into penetration test example gets stuck at the same point.

This is my opinion I'm not claiming it's absolute truth.

EEbru K***MemberCommunity member
Joined
Aug 2025
Message
113
#18

I agree, and I'd like to emphasize that. The answer varies greatly by industry; there is no one-size-fits-all rule.

Of course, it varies if your situation is different.

FFatih K***Member
Job title
Human Resources Manager
Sector
Accounting & advisory
Organization type
20-person company
Joined
Jan 2023
Message
37

Doki · Vulnerability scanning · 2024

#19

Great work.

RRıdvan A***Veteran
Job title
Software developer
Sector
Leather
Organization type
two-branch business
Joined
Jan 2024
Message
12
#20

The answer above hits the nail on the head. When making decisions write down the worst-case scenario too not just the best.

Payment information changes are never verified through the channel they came from. Proven by experience.

Reply