forumNew topic

How does penetration testing actually work? I don't want to request quotes without understanding the end-to-end process

HHavva M***Expert
Job title
Front office accounting
Sector
Media and publishing
Organization type
chain store
Joined
Sep 2022
Message
197
#1

We're a 14-person B2B software company. We run a web application and supporting API services where we store employee data and order records for our clients. We recently sat down with an enterprise client, and prior to signing the contract, they made it a condition that we provide an independent penetration test report.

This is the first time we're procuring a service like this. We've received wild quotes ranging from 45,000 TL to 160.000 TL across the board, but since I don't know what these firms actually do or what they will need from us, I can't compare the proposals. One company says they'll wrap it up in two days, another says it takes two weeks.

What steps does a penetration testing process actually consist of in practice? What does our tech team need to prepare before testing kicks off, is there a risk of systems crashing during the test, and how does the process close out after the report arrives? Looking for advice from anyone familiar with the workflow.

GGizem K***Member
Job title
Data entry clerk
Sector
Chemistry
Organization type
early-stage startup
Joined
Apr 2023
Message
356
Most Helpful#2

Short answer: The penetration testing process consists of five main steps: scoping, reconnaissance and vulnerability scanning exploitation attempts, reporting, and retesting/verification. This isn't an automated scan; it's a controlled attack simulation where a specialized team tries to gain unauthorized access to your systems.

The first stage is the scoping meeting. You clarify which IP addresses, subdomains, API endpoints, or servers will be tested. Here you pick the testing methodology: black box where zero prior information is provided white box where full admin credentials are shared, or gray box where testers receive standard user privileges. For business applications, gray box testing typically delivers the best ROI.

In the second stage the team performs passive and active reconnaissance and analyzes system architecture. In the third stage, identified vulnerabilities are actively exploited—meaning privilege escalation, database injection, or session hijacking scenarios are tested. To prevent outages in production, the rules of engagement for these exploits must be spelled out in the contract. For critical systems, tests are usually run off-hours or against an exact staging replica.

In the final phase, the firm delivers a report categorizing findings by critical high, and medium severity. Once you receive the report, you're usually given a 15 to 30-day remediation window to patch the vulnerabilities. After that, the team performs a retest—either free of charge or for a nominal fee—to verify the holes are truly closed, then issues the final clean report. When collecting quotes, always confirm whether the retest is included.

TTolga A***MemberCommunity member
Joined
Nov 2023
Message
346
#3

Steer clear of vendors promising to wrap things up in two days. They're almost certainly just running an automated scanner in the background and slapping their logo onto the exported PDF. For custom APIs and dashboards built by a 14-person team, a proper gray-box test takes at least 5-7 business days.

Edit: asked below, I wrote the answer in the second message.

CCeren B***Member
Job title
Sales Manager
Sector
Law
Organization type
early-stage startup
Joined
Jan 2025
Message
282
#4

During the prep phase, make sure to ask the testing team for their static IP addresses. You'll need to whitelist those IPs in your firewall and WAF layers. Otherwise, your firewall will block their test IPs within the first minute and you'll waste precious days troubleshooting connectivity.

NNuri G***Member
Job title
Purchasing manager
Sector
Agriculture
Organization type
early-stage startup
Joined
Mar 2023
Message
62
#5

When comparing quotes, send these three questions to the firms in writing: 1) What industry certifications does the testing staff hold, and will they be conducting the tests directly themselves? 2) Is the testing methodology built around international standards? 3) Do we get a free re-test to verify once the vulnerabilities are patched?

SSinan B***Expert
Job title
Product Manager
Sector
Media and publishing
Organization type
two-branch business
Joined
Apr 2025
Message
223
#6

Last year we got this service for a similar setup with 2 web apps and 1 mobile app. We paid 65.000 TL, and the testing took 8 business days. They found 12 vulnerabilities in total, 3 of which were privilege escalation issues. Our developers patched the bugs in 10 days, followed by a 2-day verification test, and the report was closed out.

OOkan T***VeteranCommunity member
Joined
Jan 2023
Message
7
#7

the first time we had this done they tested on the production db and almost all the test records got completely messed up. honestly definitely dont let them use the live database for testing or clone an exact copy and have it tested in a staging environment otherwise youre gonna have a massive headache.

VVolkan Ö***Expert
Job title
Intern
Sector
E-commerce
Organization type
early-stage startup
Joined
Oct 2022
Message
51
#8

Is your client asking for the full test report or just the executive summary page? Handing over the technical report containing details of every single finding to a client is risky from a security policy standpoint; make sure to request an executive summary format when getting quotes.

HHakan B***Expert
Job title
Human Resources Specialist
Sector
Plastic
Organization type
early-stage startup
Joined
Jan 2026
Message
409
#9

Make sure to include the testing hours and an emergency contact person in the contract. You need a direct line of communication so that if there's an unexpected system freeze or high load, the test can be halted instantly with a single phone call.

EErcan B***Member
Job title
Graphic Designer
Sector
Security services
Organization type
boutique agency
Joined
Mar 2026
Message
46
#10

if I understood correctly you're saying: The biggest time-waster for us was not knowing who had the final say.

hope this helps.

YYasemin K***MemberCommunity member
Joined
Jan 2024
Message
82
#11

I've been dealing with this for a long time. If 2FA is on, a stolen password alone is useless.

Proven by experience.

NNazlı T***MemberCommunity member
Joined
Apr 2025
Message
217
#12

My question might sound amateurish, sorry about that. Just because everyone does it doesn't mean it's right.

Correct me if I'm wrong.

DDamla C***Member
Job title
Customer Relations Manager
Sector
Printing
Organization type
300-person organization
Joined
Nov 2022
Message
229
#13

I'm writing this so you don't make the same mistake. People defend habits, not processes. Resistance comes from there.

Any unwritten clause becomes a point of disagreement later, as both sides remember it differently. If you post the result here, it will help others too.

TTülay E***Veteran
Job title
Accounting clerk
Sector
Freight
Organization type
40-person manufacturing company
Joined
Sep 2023
Message
97

Doki · Corporate website · 2026

#14

I felt relieved reading this answer, so it's not just me. Everything goes well for the first three months; problems arise in the fourth.

Everything goes well for the first three months; problems arise in the fourth. If you post the result here, it will help others too.

AAslı U***MemberCommunity member
Joined
Apr 2026
Message
61
#15

I'm a small business, let me explain from my side. If permission and scope aren't in writing, don't start that test.

This is my opinion, I'm not claiming it's absolute truth.

MMelis T***Member
Job title
Country Manager
Sector
Advertising and promotion
Organization type
20-person company
Joined
Apr 2025
Message
1
#16

Let me share my experience. Your time to detect an issue directly determines its cost.

If you post the result here, it will help others too.

ZZeynep B***Member
Job title
Marketing manager
Sector
Leather
Organization type
a company within a holding
Joined
May 2025
Message
254
#17

i partly agree, parttly disagree and like if you scold false alarms nobody will report again.

this is my opinion, I'm not claiming it's absolute truth.

PPolat Y***ExpertCommunity member
Joined
May 2023
Message
54
#18

The most overlooked point about penetration testing process steps is this: The real issue isn't the number, but what it's based on.

Trying to do this alone is the most expensive way. Good luck with that.

UUfuk Ç***MemberCommunity member
Joined
Mar 2024
Message
36
#19

to get into the details: Mistakes made on the peenetration testing process steps side are usually reversible but expensive.

if you scold false alarms nobody will reort again... tbh proven by experience.

OOsman K***VeteranCommunity member
Joined
Feb 2026
Message
279
#20

heres how it went for us. payment information changes are nevr verified through the channel they came from.

hope this helps.

Reply