- Job title
- Technical service technician
- Sector
- Jewelry
- Organization type
- 120-person company
- Joined
- Dec 2025
- Message
- 336
We're an 8-person software and data consultancy based in Cologne. We maintain two Linux application servers hosted for our clients, alongside our corporate website. Lately, security audit questionnaires from our German corporate clients have ramped up noticeably. We got a quote of 4,500 EUR for a full external penetration test, but our budget is a bit tight for that right now.
We'd like to run some basic vulnerability scanners internally to patch the most obvious holes beforehand. However, we don't have a dedicated cybersecurity specialist on the team; everyone is at a general developer or sysadmin level. We're worried about locking up databases on live servers, spiking server loads and taking down services, or firing uncontrolled requests at web forms and generating junk records.
What vulnerability analysis tools can a small technical team safely run on their own without risking production? What are the boundaries for safe scanning, and at what point should we definitely bring in an outside specialist?