We run an eight-person office in Milan exporting B2B machinery spare parts. We have a small web portal where our clients download technical drawings and place orders. Last week we got an annual infrastructure maintenance proposal from a local IT firm. Among the line items, they put 1,200 EUR per year for a "vulnerability assessment", and as an alternative, they proposed a comprehensive "penetration test" for 4,500 EUR.
I have to admit I'm not very familiar with technical terms. What exactly is this vulnerability scan, what runs in the background? Do they just run automated software and hand over a report, or does an actual expert examine the system?
For a business like ours that doesn't have massive databases or store credit cards, but does host client lists and technical drawings, does this 1,200 EUR scan provide sufficient protection, or would we just be buying into a false sense of security if we skip the pentest?