- Job title
- Product Manager
- Sector
- Catering
- Organization type
- 20-person company
- Joined
- Feb 2024
- Message
- 220
Doki · Corporate website · 2024
We're a team of 10 in Düsseldorf developing web-based middleware for B2B logistics operations. Our system runs on cloud servers and handles our clients' shipment data. Last week we were about to close a deal with a large enterprise client, but as part of their vendor security audit, they asked us for an up-to-date vulnerability assessment (Schwachstellenanalyse) report.
We spoke with two local cybersecurity consulting firms. One offered a 2,500 EUR package that just runs automated scanning tools and hands over a report. The other gave us a comprehensive 9,000 EUR quote covering source code review, architectural evaluation, and a manual penetration test.
For a 10-person software company of our scale, which of these vulnerability assessment methods is actually necessary? Is an automated scan enough to pass an enterprise audit, or should we jump straight into manual methods?