We are a 7-person team based in London developing B2B order and inventory management software. Last month, we sat down with an enterprise retailer that has 80 stores across the UK. We are on the verge of signing a licensing deal worth 52,000 GBP annually, but their IT security team added a prerequisite to the specs: an up-to-date penetration testing report from an independent cybersecurity firm.
Up until now, we've only run our own internal code reviews; our servers sit behind a firewall, we use SSL, and our database is encrypted. But we don't fully understand how these corporate-mandated penetration tests actually work or what they're truly looking for in practice.
How does this process work for a small SaaS startup? Does anyone have a real example of a pentest report, and what exactly are these ethical hackers hunting for in your system? Also, what does a test like this usually run, and is it worth taking on the expense before the contract is officially signed?