forumNew topic

Someone is trying to sell us "pentest services" — what is this, and is it really necessary at our scale?

MMurat G***Member
Job title
Purchasing manager
Sector
Sports and fitness
Organization type
20-person company
Joined
Apr 2023
Message
2
#1

We are a 14-employee company in wholesale food and packaging. We launched a B2B ordering portal 8 months ago for our own clients. Around 650 dealers use this panel to check account balances, place orders, and pay by credit card via virtual POS. Last week, a cybersecurity firm called saying we urgently need a pentest package for our systems, otherwise we could have severe vulnerabilities. The proposal they sent is around 60,000 TL.

Frankly, I haven't quite grasped what a pentest actually is. How is it different from a regular antivirus or firewall? Do they genuinely attack the system like a hacker to find vulnerabilities, or do they just run an automated scanner and output a boilerplate report? For a small-to-medium wholesaler like us, is this a luxury expense or an absolute necessity to protect our system?

LLale Y***MemberCommunity member
Joined
Jul 2025
Message
378
#2

Don't fall for the salespeople's scare tactics right away. A pentest is definitely a useful audit, but vendors who use the "buy now or you'll go under" rhetoric rarely deliver quality work. Determine what you actually need first; don't blindly buy into their bundled package.

KKader Ş***ExpertCommunity member
Joined
Mar 2024
Message
67
Most Helpful#3

Short answer: A pentest (penetration test) is a manual and technical audit service where ethical security experts simulate a controlled cyberattack on your system just like an actual attacker to identify and report vulnerabilities. While a firewall locks the front door, a pentester actively checks if a thief can climb through the balcony or squeeze down the chimney.

Your setup has a critical footprint: account balances and order histories for 650 dealers, and most critically, virtual POS integration. If an authorization bypass vulnerability exists on your portal, one dealer could view another's discount rates or alter order totals. So for your scale, a pentest is not an unnecessary expense; it's essential to protect your trade and reputation. What you need to watch out for, though, is the quality of the service being quoted.

The market is flooded with drastically different proposals; some vendors simply run an automated vulnerability scanner, slap their logo on an English PDF export, and call it a day. A real penetration test manually digs into business logic flaws.

Here is the process I suggest when buying this service: 1) Ask the bidding vendor how many man-days the test will take and whether manual checks are included. 2) Keep costs optimized by scoping strictly to the B2B web portal and API endpoints. 3) Make sure your contract includes a free verification test (re-test) once your developer patches the findings.

CCeren G***Veteran
Job title
Board member
Sector
Printing
Organization type
8-person team
Joined
Oct 2022
Message
131

Doki · Penetration test · 2026

#4

You need to understand the difference between an automated vulnerability scan and a penetration test. Automated tools look for known CVEs, but they miss business logic flaws. For instance, tampering with an order ID from 105 to 106 to view someone else's invoice is something only a manual tester will catch.

GGoncaExpert
Job title
Health tourism
Organization type
sole proprietorship
Joined
Oct 2023
Message
162
#5

We paid 40,000 TL last year for a similarly scoped ordering panel. The test uncovered 2 critical authorization vulnerabilities. Our developer patched them in two days. If we'd been caught with those holes, competing dealers could have downloaded each other's custom price lists—totally worth the money.

NNuri Y***Expert
Job title
Store Manager
Sector
Leather
Organization type
300-person organization
Joined
Aug 2022
Message
95
#6

we got a similar email pitch and passed, had our dev run basic scans with open-source tools instead. does the trick for now, but having a pro do it is obviously a different league if you have the budget.

AAhmet A***MemberCommunity member
Joined
Oct 2023
Message
63
#7

Check the references of the company asking for 60.000 TL. Many agencies just run free tools downloaded off the internet for two hours and hand you an 80-page generic report. If the report doesn't contain a concrete analysis of your site's code or business workflows, your money is down the drain.

ÖÖmer Ö***Member
Job title
Social media manager
Sector
Printing
Organization type
chain store
Joined
Feb 2023
Message
64
#8

When evaluating the quote, make sure to clarify these three points: 1) Will it be done using a grey-box approach, meaning will test user accounts be provided? 2) Is there any risk of site downtime during the test? 3) Does the resulting report qualify as an independent audit document recognized under the Turkish Commercial Code or KVKK processes?

KKaan G***MemberCommunity member
Joined
Dec 2022
Message
1
#9

Don't sign a contract right away. Request scoping meetings from at least two other cybersecurity firms. Ask for a quote limited strictly to the B2B portal by providing two dealer test accounts, and keep the server infrastructure separate.

HHilal K***Member
Job title
Business Owner
Sector
Agriculture
Organization type
regional distributor
Joined
Mar 2024
Message
303
#10

Can I ask something, does our ordering system go down for a while during this test or can dealers keep placing orders in the background?

GGürkan B***Member
Job title
Business Owner
Sector
Glass
Organization type
300-person organization
Joined
Aug 2023
Message
106

Doki · Backup setup · 2024

#11

I went through the same thing. Taking measures without an inventory leaves doors you haven't seen open.

If you post the result here, it will help others too.

LLale A***Member
Job title
Site Manager
Sector
IT services
Organization type
cooperative
Joined
Jul 2023
Message
86
#12

We've heard this a lot, but it never happened like that for us. Processes without records never improve, because you don't know what to fix.

If you post the result here, it will help others too.

YYusuf E***Member
Job title
Gym owner
Organization type
workshop
Joined
Apr 2024
Message
66
#13

If I understood correctly, you're saying: Taking notes for two weeks yields better results than a six-month estimate.

If you post the result here, it will help others too.

EEmre Y***ExpertCommunity member
Joined
May 2025
Message
48
#14

The most overlooked point about what is pentest service is this: The real issue isn't the number, but what it's based on.

If you have questions, write them; I'll answer as best I can.

SSultan U***MemberCommunity member
Joined
Jul 2025
Message
402
#15

Could you elaborate on that? Processes without records never improve, because you don't know what to fix.

Forgotten test environments are more often the entry point than live systems. If I were you, I'd go this route.

YYavuz B***MemberCommunity member
Joined
May 2025
Message
59
#16

Thanks for writing this thats the right way. Payment information changes are never verified through the channel they came from.

HHatice Ş***Member
Job title
Human Resources Specialist
Sector
IT services
Organization type
early-stage startup
Joined
Sep 2025
Message
123
#17

We experienced almost the exact same thing last year. Just because everyone does it doesn't mean it's right.

Hope this helps.

VVahide V***Member
Job title
General Manager
Sector
Cosmetics
Organization type
workshop
Joined
Jul 2022
Message
1
#18

Just a heads-up. When we decide without measuring, we always end up in the same place.

If I were you, I'd go this route.

KKemal G***Expert
Job title
System support specialist
Sector
Cleaning services
Organization type
a company within a holding
Joined
Feb 2024
Message
377

Doki · Log management setup · 2024

#19

Following.

YYaseminMember
Job title
SME owner
Joined
Jul 2024
Message
98
#20

My question might sound amateurish, sorry about that. Taking notes for two weeks yields better results than a six-month estimate.

When you try to change everything at once nothing settles.

This topic has been closed.The moderator marked the topic as resolved. If you have a similar issue, you can open a new topic.
New topic