- Job title
- Accounting Manager
- Sector
- Consulting
- Organization type
- early-stage startup
- Joined
- Oct 2023
- Message
- 140
We are a 15-person B2B SaaS startup. We are on the verge of signing an annual enterprise contract with a large retail chain, but their security team made it a mandatory contractual condition that we provide an up-to-date penetration testing report from an accredited third-party vendor. We have allocated around 70,000 TL for this assessment.
We have never conducted a formal security audit or pen test before. I started reaching out to cybersecurity firms for RFPs, but they all keep asking for technical details like "what is the testing scope how many target IPs need scanning, is this black-box or gray-box testing?" To be honest, I have no idea how to structure this scoping document.
What technical assets and details do we need to map out internally before asking for quotes and signing an engagement letter? From defining the scope to remediating vulnerabilities and receiving the final attestation, how is penetration testing conducted end-to-end?