We are a 14-person software company in the fintech space providing B2B invoicing and reconciliation software to enterprise clients. Two major banks and a retail giant that are about to join our portfolio have made an independent firm's penetration test report mandatory before integration. Contracts worth a total of 600,000 TL annually are on the table.
Before we start working with the cybersecurity firm we choose, we need to draw up a written authorization and scoping document. However, our cloud infrastructure includes shared servers, third-party payment gateways, and live production databases that cannot tolerate any downtime whatsoever. We are worried that an erroneous scan might crash our servers or cross legal boundaries.
What systems, test types, time windows, and legal protection clauses must absolutely be included in this written authorization and scoping form? What conditions should we put in the contract to ensure operational safety?