forumNew topic

How is a penetration test conducted — how do we manage the process without downtime on our live site?

CCem K***Member
Job title
QA Tester
Sector
IT services
Organization type
chain store
Joined
Sep 2023
Message
138
#1

We run a B2B wholesale platform that handles orders around the clock, with 15,000 active corporate users annually. A large enterprise client we just signed with is demanding a comprehensive penetration test report from an independent firm as a contractual requirement. Our software infrastructure was developed entirely in-house, but we have never had a professional, third-party pen test performed to date.

Because our site accepts orders 24/7, the biggest concern for both management and our technical team is that the servers might choke under heavy load, database tables might get corrupted, or users might be locked out during the assessment. We are currently interviewing cybersecurity firms, but we don't fully know how to manage the process once we sit down at the table.

How is a penetration test conducted, and what are the stages from day one through to the final deliverable? What terms should we negotiate with the testing vendor, and what technical precautions should we take on our side to guarantee zero downtime and zero data loss in production?

OOnur A***Member
Job title
Field sales representative
Sector
Paper
Organization type
regional distributor
Joined
May 2024
Message
207
Most Helpful#2

Short answer: A penetration test is a controlled audit where independent security professionals hunt for vulnerabilities across your systems within an approved scope, simulating real-world attacker techniques. To prevent downtime on a live system, the rules of engagement must be explicitly outlined by contract, denial-of-service tests must be strictly excluded, and the assessment should be conducted via a real-time technical bridge between teams.

The process typically follows these stages: First, scoping takes place; you determine which IP blocks, web apps, or API endpoints will be tested, and whether the approach will be black box (zero-knowledge, from the outside), grey box (with standard user credentials), or white box. Next, the testers look for business-logic flaws and vulnerabilities using a mix of automated scanners and manual methods, exploiting findings to confirm their actual severity. Once testing wraps up, vulnerabilities and remediation steps are detailed in an interim report. After your team patches the issues, a verification re-test is performed, followed by the delivery of the final clean report.

To prevent outages in production, you must enforce the following safeguards: 1) Explicitly state in the contract that DoS/DDoS scenarios and destructive database manipulations are strictly out of scope, 2) Schedule active testing for overnight hours when platform traffic hits its lowest trough, 3) Whitelist the testing firm's IPs on your firewall, but agree in advance on a strict requests-per-second rate limit so they don't exhaust server resources, 4) Set up a direct emergency comms channel between your sysadmin and the lead tester. You need to be able to pull the plug instantly if there is an unexpected spike in load.

HHakan A***Member
Job title
Software team lead
Sector
Catering
Organization type
20-person company
Joined
Oct 2023
Message
86
#3

The single most critical rule to avoid downtime is throttling the scan tools (rate limiting). Impose a hard ceiling of 5 to 10 requests per second on the testing team. Make it an absolute condition that bulk injection attacks against database-heavy search and filtering endpoints are done manually and under strict control.

ÖÖzge C***Expert
Job title
Accounting clerk
Sector
Leather
Organization type
cooperative
Joined
Jan 2023
Message
308
#4

Non-negotiable clauses for the pre-test specification: 1) DoS/DDoS and brute-force attacks will not be executed in production, 2) No deletion or alteration of records in the live database, 3) Testing is strictly restricted to the 01:00–06:00 window, 4) Any critical zero-day or high-severity flaw found must be reported immediately without waiting for the final report delivery.

PPolat A***MemberCommunity member
Joined
May 2024
Message
48
#5

During our first pen test, the tester ran an automated fuzzing run against our signup form and triggered our SMS verification gateway. It fired off 14,000 verification SMS messages in three hours, and our telecom provider blacklisted our account for suspected spamming. Make sure you mock or stub out third-party notification, SMS, and payment gateways before starting.

FFatih G***Member
Job title
Production planning
Sector
IT services
Organization type
medium-sized business
Joined
Nov 2024
Message
31
#6

Is your client asking for a TSE-accredited penetration test, or will a report from an internationally certified outfit (CREST, OSCP, etc.) suffice? That distinction completely changes which vendors you can source quotes from and how much you'll end up paying.

MMeryem Ö***Member
Job title
Export manager
Sector
Cleaning services
Organization type
40-person manufacturing company
Joined
Feb 2024
Message
13
#7

We ran a grey-box pen test on our B2B platform of comparable size. The entire engagement took 5 business days. They flagged 2 critical and 4 medium-severity vulnerabilities. Because we scheduled the runs during off-peak hours, server CPU utilization never crept past 40 percent and we saw zero downtime.

UUğur Ö***Member
Job title
Sales Manager
Sector
IT services
Organization type
regional distributor
Joined
Jan 2024
Message
5

Doki · Brand identity · 2026

#8

If your infrastructure permits spin up a staging environment that mirrors production 1:1 using an anonymized sanitized dump of the live database. Running the test there eliminates any risk to your live orders and active user sessions.

NNazlı G***Member
Job title
Accounting clerk
Sector
Agriculture
Organization type
medium-sized business
Joined
Nov 2023
Message
176
#9

Dont stress too much over it, no legit corporate pen tester is reckless enough to nuke a live production box. As long as you keep communications open and keep DoS strictly out of scope, the whole thing will go off without a hitch.

Edit: asked below, I wrote the answer in the second message.

MMustafa T***ExpertCommunity member
Joined
Apr 2026
Message
150
#10

Before any testing kicks off, an NDA and a formal Authorization Letter (Rules of Engagement) must be executed with physical wet signatures. Drawing clean boundaries around legal liability and keeping absolute emergency stop authority on your end is non-negotiable from an information security governance standpoint.

KKaan Ş***New member
Job title
Intern
Sector
Textile
Organization type
two-branch business
Joined
Aug 2026
Message
2
#11

There is something to watch out for. People defend habits, not processes. Resistance comes from there.

PPınar K***MemberCommunity member
Joined
Feb 2026
Message
17
#12

We need to take it step by step. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Hope this helps.

AAhmet A***MemberCommunity member
Joined
Oct 2023
Message
63
#13

Following.

İİlaydaMember
Job title
Customer Support Manager
Joined
May 2024
Message
124
#14

I didn't know that.

ZZehra T***Member
Job title
Operations manager
Sector
Freight
Organization type
early-stage startup
Joined
Apr 2026
Message
68

Doki · Penetration test · 2025

#15

The opposite happened to me, that's why I'm writing. Forgotten test environments are more often the entry point than live systems.

Proven by experience.

PPolat T***VeteranCommunity member
Joined
Dec 2023
Message
363
#16

We got stuck at the same point for a while. If 2FA is on, a stolen password alone is useless.

Just leaving this note, it might be useful.

BBurcu V***Member
Job title
Field sales representative
Sector
Automotive aftermarket
Organization type
120-person company
Joined
May 2023
Message
2
#17

I dont think this advice fits everyone. If 2FA is on, a stolen password alone is useless.

TTülay A***MemberCommunity member
Joined
Sep 2022
Message
147
#18

Thanks for writing this, that's the right way. If you scold false alarms, nobody will report again.

Of course, it varies if your situation is different.

UUğurMember
Job title
Outdoor advertising
Organization type
regional distributor
Joined
Feb 2024
Message
94
#19

I think differently. Solutions that work at a small scale collapse when you grow; I learned this late.

If I were you I'd go this route.

GGizem M***Member
Job title
Industrial engineer
Organization type
chain store
Joined
Jun 2024
Message
96
#20

Could you elaborate on that? The answer varies greatly by industry; there is no one-size-fits-all rule.

I'm also curious if anyone does it differently.

Reply