- Job title
- Accounting Manager
- Sector
- Consulting
- Organization type
- early-stage startup
- Joined
- Oct 2023
- Message
- 140
We run a B2B SaaS platform with an 18-person team, hosting enterprise client and financial data in our cloud infrastructure. Due to upcoming client security audits and our ISO 27001 certification process, we need to bring in a penetration testing service.
Evaluating vendors has been confusing. A boutique consultancy quoted 25.000 TL, mentioning certified engineers but offering no corporate accreditation. Another cybersecurity firm quoted 85.000 TL, emphasizing they are a Türk Standardları Enstitüsü (TSE) approved penetration testing provider and claiming this certification is mandatory for audits.
What credentials are we legally or operationally required to demand from pen testing vendors in the Turkish private sector? Does working with unaccredited firms cause issues during audits?