- Job title
- QA Tester
- Sector
- IT services
- Organization type
- chain store
- Joined
- Sep 2023
- Message
- 138
We run a B2B wholesale platform that handles orders around the clock, with 15,000 active corporate users annually. A large enterprise client we just signed with is demanding a comprehensive penetration test report from an independent firm as a contractual requirement. Our software infrastructure was developed entirely in-house, but we have never had a professional, third-party pen test performed to date.
Because our site accepts orders 24/7, the biggest concern for both management and our technical team is that the servers might choke under heavy load, database tables might get corrupted, or users might be locked out during the assessment. We are currently interviewing cybersecurity firms, but we don't fully know how to manage the process once we sit down at the table.
How is a penetration test conducted, and what are the stages from day one through to the final deliverable? What terms should we negotiate with the testing vendor, and what technical precautions should we take on our side to guarantee zero downtime and zero data loss in production?