- Job title
- Social media manager
- Sector
- E-commerce
- Organization type
- 120-person company
- Joined
- Feb 2022
- Message
- 14
Doki · Log management setup · 2025
We are a 45-person company developing B2B logistics software. We have a 3-person system and software team managing our infrastructure. We get a penetration test from an external vendor every year, and last year we budgeted around 65.000 TL for it.
The security firm we requested a quote from this year told us that a standard pentest isn't enough anymore, insisting we definitely need to run a "red team" simulation, and quoted a comprehensive package priced at 260.000 TL. Their rationale is that targeted attacks are on the rise, so we need to test human and process vulnerabilities, not just software flaws.
When I look it up online, the definitions feel too academic. What exactly is a red team, and how is it different from a standard pentest? For an SME like us without an internal SOC or blue team monitoring alerts 24/7, is this budget truly worth it, or is the vendor just upselling?