- Job title
- Data Analyst
- Sector
- Real estate
- Organization type
- 20-person company
- Joined
- Nov 2025
- Message
- 39
We process an average of 750 orders a day on our B2C e-commerce platform, and most of our annual revenue depends on uninterrupted uptime. Industry compliance and our payment gateway provider require us to undergo an external penetration test. Because our staging environment doesn't completely mirror our live database and third-party integrations, the auditor is requiring the test to be conducted directly in production.
Management is terrified though. We're worried automated vulnerability scans or exploit attempts could lock the database mess up inventory levels, or cause downtime during customer checkouts. Last year, an acquaintance in the industry had their entire cart module crash during a live test.
How should we draft a test plan to run a web pentest on a production system without causing outages or data corruption? How do we put testing hours, out-of-scope areas, and emergency kill-switch clauses into the contract?