We are an 18-person B2B software company based in Austin. We have around 45 servers and service endpoints in our cloud infrastructure. Our enterprise clients' security teams have started requesting quarterly vulnerability scan reports from us.
Looking at the market, we found two main options. The first is buying an annual license for enterprise vulnerability scanning tools. We received quotes around 5,500 USD for the annual license. The second is purchasing a scanning service from a cybersecurity firm, which costs 1,200 USD per quarter, totaling 4,800 USD annually.
Financially they are very close, but we don't have a full-time security specialist in-house, so this will fall squarely on our two infrastructure developers. If we buy the tool ourselves, will the setup and report interpretation overwhelm us, or is it better to learn the tool in-house instead of paying a third party every time?