- Job title
- Product Manager
- Sector
- Healthcare services
- Organization type
- 20-person company
- Joined
- Jul 2022
- Message
- 292
Doki · Infrastructure migration · 2026
We run a B2B e-commerce platform based in Jeddah. We have nearly 300 wholesalers on our system, and our servers process both corporate payment details and supplier contracts. While planning our annual security budget, we received proposals from two different audit firms.
The first quoted 25,000 SAR for a standard web app and server penetration test, stating the scope would be completed in 5 business days and would scan for all known vulnerabilities. The second proposed a "red team cybersecurity exercise" for 75,000 SAR, spanning 4 weeks and covering social engineering, employee phishing, physical office security, and stealth database exfiltration scenarios.
That is a three-fold price difference. We have a 15-person technical team and a baseline firewall setup. At this stage, is a red team exercise an unnecessary luxury for a business like ours, or does it resolve critical risks that a standard pen test would inevitably miss?