forumNew topic

How does the penetration testing process work, and what do we need to prepare internally beforehand?

KKübra M***Member
Job title
Accounting Manager
Sector
Consulting
Organization type
early-stage startup
Joined
Oct 2023
Message
140
#1

We are a 15-person B2B SaaS startup. We are on the verge of signing an annual enterprise contract with a large retail chain, but their security team made it a mandatory contractual condition that we provide an up-to-date penetration testing report from an accredited third-party vendor. We have allocated around 70,000 TL for this assessment.

We have never conducted a formal security audit or pen test before. I started reaching out to cybersecurity firms for RFPs, but they all keep asking for technical details like "what is the testing scope how many target IPs need scanning, is this black-box or gray-box testing?" To be honest, I have no idea how to structure this scoping document.

What technical assets and details do we need to map out internally before asking for quotes and signing an engagement letter? From defining the scope to remediating vulnerabilities and receiving the final attestation, how is penetration testing conducted end-to-end?

İİlker G***Member
Job title
Board member
Sector
Livestock
Organization type
regional distributor
Joined
Apr 2026
Message
341
Most Helpful#2

Short answer: A penetration testing engagement consists of five main phases: scoping, rules of engagement (RoE) contract, active testing, reporting, and re-testing. Before requesting quotes, you need to compile a concrete inventory of web application target URLs, API endpoints, server IP counts, and whether the testers will evaluate authenticated user workflows.

The engagement officially kicks off when both parties sign a scope agreement detailing the rules of engagement. As the client, you provide the security firm with your public static IPs, target domains, and, if applicable, test accounts configured with distinct role permissions.

To satisfy an enterprise customer's vendor assessment, a "gray-box" methodology is standard; this gives testers high-level architectural context along with two active test profiles—typically one unprivileged user and one administrator. To avoid production downtime, you can schedule disruptive scans outside business hours or point the testing team at an identical staging environment.

Once tests wrap up, the vendor delivers a draft technical report categorizing vulnerabilities by CVSS severity. Your engineering team is usually given a remediation window of two to four weeks to patch critical and high-risk flaws. Finally, the testers perform a validation re-test to confirm the patches hold and produce a clean executive report suitable for your client.

UUğur E***MemberCommunity member
Joined
Jan 2023
Message
17
#3

If this is meant for enterprise client procurement, explicitly request a gray-box web application pen test. Black-box testing simulates an outside attacker with zero access, but it completely misses broken object-level authorization and privilege escalation flaws deep inside your application logic. Always provision at least two accounts with different user roles for the pen-test team.

EEmre Y***ExpertCommunity member
Joined
May 2025
Message
48
#4

Create a spreadsheet right now listing every public-facing server IP, your web app login URL and the count of underlying backend microservices. Hand that exact asset list over when you request quotes; firms will immediately understand the scope and you'll have pricing back within three days.

SSinan K***Member
Job title
Country Manager
Sector
Construction
Organization type
workshop
Joined
Jan 2024
Message
335
#5

Don't skip these four operational steps during prep: 1) Take full image/snapshot backups of your production instances. 2) Whitelist the testing team's public source IPs on your WAF and firewalls. 3) Rate-limit or mock out transactional email and SMS dispatchers in your staging environment. 4) Notify your cloud hosting provider of the testing schedule in advance.

LLale T***MemberCommunity member
Joined
Nov 2023
Message
7
#6

if u run this against production watch your database like a hawk but while testers fuzz innput fields with payloads, your system can accidentally blast out hundreds of dummy invoices or automated SMS notifications to real users. temporarily disable downstream notification microservices during the scan windows.

ÖÖmer Ş***Member
Job title
Project manager
Sector
Software
Organization type
chain store
Joined
Feb 2025
Message
179

Doki · Brand identity · 2025

#7

Does your corporate client only want your web app tested, or did they also require internal local network and employee phishing tests? If the scope is just your SaaS app, a 70.000 TL budget will be more than enough.

HHalilMember
Job title
Supply chain
Joined
Dec 2023
Message
114
#8

Last month we had a test done for a similar retail integration covering 1 web app and 6 external IPs. It took 5 days, and the draft report showed 2 critical and 4 medium vulnerabilities. Patching the flaws and finishing the retest took us 20 days in total.

NNeslihan E***Member
Job title
Board member
Sector
Security services
Organization type
8-person team
Joined
Apr 2025
Message
35

Doki · Corporate website · 2023

#9

There are firms out there that just run an automated vulnerability scanner, spit out a generic 100-page PDF, and call it a pentest. When getting quotes, make sure to get a written commitment that manual verification is performed and business logic flaws are checked.

OOnur M***Veteran
Job title
Chief Technology Officer
Sector
Electrical-electronics
Organization type
chain store
Joined
Aug 2024
Message
19

Doki · Penetration test · 2026

#10

In short, take an inventory of your IPs and URLs, agree on a gray-box methodology, set up a staging environment, back everything up, and definitely confirm that retesting is included in the price. The whole process usually wraps up within a month.

KKader K***MemberCommunity member
Joined
Apr 2024
Message
393
#11

I was thinking the same thing. If you get three different answers on a topic, the question was asked wrong.

I'm also curious if anyone does it differently.

TTunçExpert
Job title
SaaS Founder
Joined
Jul 2023
Message
186
#12

Let me clarify the technical side. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Good luck with that.

RRıdvan K***MemberCommunity member
Joined
Oct 2024
Message
2
#13

Generally correct, but one part is missing. Mistakes made on the how penetration testing is conducted side are usually reversible but expensive.

Most time waste accumulates in tasks waiting for approval. Proven by experience.

SSelin U***MemberCommunity member
Joined
Mar 2026
Message
2
#14

Noted, thanks.

BBeyza T***Member
Job title
Accounting Manager
Sector
Packaging
Organization type
120-person company
Joined
Sep 2022
Message
49

Doki · Interface design · 2023

#15

Saved.

BBurcu B***MemberCommunity member
Joined
Jan 2025
Message
264
#16

We experienced almost the exact same thing last year. Don't hesitate to ask; those who don't ask always pay more.

Just leaving this note, it might be useful.

BBeyzaMember
Job title
Small agency
Joined
May 2024
Message
104
#17

Don't miss this: An untested backup is not a backup.

That's all, sorry if I went on too long.

EErcan D***Member
Job title
Administrative manager
Sector
Software
Organization type
two-branch business
Joined
Jul 2022
Message
419
#18

I've been dealing with this for a long time. The biggest time-waster for us was not knowing who had the final say.

EEsra K***MemberCommunity member
Joined
Jul 2025
Message
1
#19

The most overlooked point about how penetration testing is conducted is this: Most time waste accumulates in tasks waiting for approval.

Of course, it varies if your situation is different.

BBanu Ş***Member
Job title
Pharmacist
Joined
Mar 2024
Message
81
#20

Absolutely. If I were to add anything: Your time to detect an issue directly determines its cost.

Processes without records never improve, because you don't know what to fix.

Reply