forumNew topic

Vulnerability assessment methods: Which is enough for a small company before their first pentest?

PPerihan K***Member
Job title
Product Manager
Sector
Catering
Organization type
20-person company
Joined
Feb 2024
Message
220

Doki · Corporate website · 2024

#1

We're a team of 10 in Düsseldorf developing web-based middleware for B2B logistics operations. Our system runs on cloud servers and handles our clients' shipment data. Last week we were about to close a deal with a large enterprise client, but as part of their vendor security audit, they asked us for an up-to-date vulnerability assessment (Schwachstellenanalyse) report.

We spoke with two local cybersecurity consulting firms. One offered a 2,500 EUR package that just runs automated scanning tools and hands over a report. The other gave us a comprehensive 9,000 EUR quote covering source code review, architectural evaluation, and a manual penetration test.

For a 10-person software company of our scale, which of these vulnerability assessment methods is actually necessary? Is an automated scan enough to pass an enterprise audit, or should we jump straight into manual methods?

EEmre O***MemberCommunity member
Joined
Feb 2024
Message
104
Most Helpful#2

Short answer: For a 10-person B2B software company at this stage, you don't need purely automated scans, nor do you need a 9,000 EUR deep architectural review. The sweet spot is a hybrid vulnerability assessment where automated tools scan the attack surface, and an expert manually verifies any findings and tests basic business logic.

You need to understand the difference between the approaches: 1) Automated vulnerability scan (Schwachstellenscan): Quickly catches known CVEs, outdated libraries, and misconfigurations, but it can't detect business logic flaws or privilege escalation issues, and it spits out lots of false positives. Enterprise auditors usually reject raw automated reports. 2) Manual pentest: An expert looks for logical flaws and authentication bypasses just like a real attacker would. 3) Architecture and source code review is the most thorough, but also by far the most expensive.

In your situation, you should carefully read through the client's audit questionnaire. Usually, what they really want is a report showing that your public-facing web app and API endpoints were manually tested against the OWASP Top 10 risks, and that any critical findings were patched. A targeted hybrid web app assessment in the 3,500 - 5,000 EUR range is more than enough for a first audit.

FFeyza S***MemberCommunity member
Joined
Aug 2023
Message
251
#3

Automated scanners will catch SQL Injection or open ports, but they won't answer whether user A can view user B's invoice. In B2B logistics software, your biggest risk is multi-tenant privilege escalation. You can only catch that with manual testing.

ZZehra T***Member
Job title
Operations manager
Sector
Freight
Organization type
early-stage startup
Joined
Apr 2026
Message
68

Doki · Penetration test · 2025

#4

What does your client's security questionnaire say word for word? Sometimes they just ask "do you run regular vulnerability scans?", while other times they explicitly demand a third-party certified "Penetrationstest nach BSI" or something similar. Don't spend a dime until you clarify the requirements.

CCaner K***VeteranCommunity member
Joined
May 2023
Message
21
#5

For our team of 12, we paid 3,200 EUR for a 2-day hybrid web app test during our first audit. We patched the 2 high-severity findings within a week, got a re-test report, and the client signed off. 9,000 EUR is definitely overkill to start with.

MMert Y***Member
Job title
Purchasing manager
Sector
Accounting & advisory
Organization type
two-branch business
Joined
Mar 2023
Message
3

Doki · Log management setup · 2024

#6

Narrow the scope down. Don't give the agency your entire cloud infrastructure, just the web app where client data passes through and your API endpoints. Once you trim the scope, the required man-days and quote will drop by half.

İİbrahim T***New member
Job title
Graphic Designer
Sector
Energy
Organization type
chain store
Joined
Jun 2026
Message
90
#7

paying 2,500 eur just to get an automated scan output is throwing money away. they just pretty up a two-page report from an open-source tool any enterprise auditor will see right through it and reject it on the spot.

OOya O***Member
Job title
Accounting clerk
Sector
Media and publishing
Organization type
two-branch business
Joined
Dec 2024
Message
113
#8

Don't listen to agencies claiming an architectural review is "mandatory." Of course they want to sell you their most expensive tier. A full architecture audit on a 10-person company's codebase takes weeks and completely derails product development.

TTuğçe Y***Member
Job title
Quality Assurance Manager
Sector
Food wholesale
Organization type
regional distributor
Joined
Mar 2022
Message
329
#9

Make sure to confirm whether the quote includes a re-test. Once you fix the critical issues found in the report, the testing firm needs to issue a final executive summary confirming that those vulnerabilities were resolved.

KKadir A***Expert
Job title
Customer service representative
Sector
Food wholesale
Organization type
a company within a holding
Joined
Sep 2024
Message
392
#10

Let me summarize the topic, since several different answers were given. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

Proven by experience.

HHavva Ö***MemberCommunity member
Joined
Aug 2025
Message
25
#11

Don't miss this: If permission and scope aren't in writing, don't start that test.

This is my opinion, I'm not claiming it's absolute truth.

KKübra A***Member
Job title
Technical service technician
Sector
Automotive aftermarket
Organization type
120-person company
Joined
Aug 2025
Message
71

Doki · Phishing awareness training · 2026

#12

There's a trap here, let me mention it. The harder it is to reverse a decision, the slower you should make it.

Taking notes for two weeks yields better results than a six-month estimate. Hope this helps.

MMeryem K***Member
Job title
Graphic Designer
Sector
Leather
Organization type
family business
Joined
Jul 2025
Message
417
#13

Let me summarize the topic, since several different answers were given. An untested backup is not a backup.

SSultan T***Member
Job title
Social media manager
Sector
Insurance
Organization type
8-person team
Joined
Nov 2024
Message
19
#14

Same here. Start with a small trial; don't commit to everything at once.

Hasty decisions become decisions you have to fix six months later. Of course, it varies if your situation is different.

TTülay K***Member
Job title
Customer service representative
Sector
Packaging
Organization type
chain store
Joined
Apr 2023
Message
402
#15

Saved. If you don't write this down from the start, it leads to arguments later.

That's all, sorry if I went on too long.

KKerimMember
Job title
Trainer
Joined
Jul 2024
Message
116

Doki · Corporate website · 2025

#16

Saved.

BBurak B***Veteran
Job title
Software developer
Sector
Printing
Organization type
40-person manufacturing company
Joined
Mar 2023
Message
252
#17

my question might sound amateurish, sorrry about that and i mean if you get three different answers on a topic the question was asked wrong.

im also curious if anyone does it differently.

İİsmail Ş***MemberCommunity member
Joined
May 2025
Message
177
#18

There is something to watch out for. An untested backup is not a backup.

If you have questions, write them; I'll answer as best I can.

ŞŞerife B***Member
Job title
System administrator
Sector
Media and publishing
Organization type
chain store
Joined
Nov 2023
Message
51

Doki · Phishing awareness training · 2025

#19

I went through the same thing.

UUmut Ş***Expert
Job title
DevOps
Organization type
boutique agency
Joined
Aug 2023
Message
231
#20

Thanks a lot, I'll try it today.

Reply