forumNew topic

We're running a web pentest on our live site — how to write a test plan to avoid downtime?

CCaner B***Member
Job title
Data Analyst
Sector
Real estate
Organization type
20-person company
Joined
Nov 2025
Message
39
#1

We process an average of 750 orders a day on our B2C e-commerce platform, and most of our annual revenue depends on uninterrupted uptime. Industry compliance and our payment gateway provider require us to undergo an external penetration test. Because our staging environment doesn't completely mirror our live database and third-party integrations, the auditor is requiring the test to be conducted directly in production.

Management is terrified though. We're worried automated vulnerability scans or exploit attempts could lock the database mess up inventory levels, or cause downtime during customer checkouts. Last year, an acquaintance in the industry had their entire cart module crash during a live test.

How should we draft a test plan to run a web pentest on a production system without causing outages or data corruption? How do we put testing hours, out-of-scope areas, and emergency kill-switch clauses into the contract?

OOkan I***Member
Job title
Front office accounting
Sector
Cosmetics
Organization type
sole proprietorship
Joined
Nov 2023
Message
260
Most Helpful#2

Short answer: To prevent outages during a production web pen test, the test plan must explicitly exclude DoS and DDoS testing, restrict aggressive automated scans to off-peak hours, and define an emergency kill-switch mechanism triggered by a single order. You should also require a custom HTTP header to distinguish test traffic from real customers.

Your Rules of Engagement document must include these 4 essential points:

1) Scheduling and Rate Limiting: High-volume automated scanners should only run during your lowest-traffic window, between 01:00 and 05:00 at night. Daytime testing should strictly be limited to manual checks and low-frequency requests below a predefined rate limit.

2) Out-of-Scope Areas and Business Logic: Cart-filling loops that could cause database deadlocks, forms triggering SMS/email dispatches, and the live payment pipeline must be kept out of scope. Use a mock virtual POS or sandbox mode for checkout flows.

3) Custom HTTP Header and Whitelisted IPs: The testers' static public IP addresses must be whitelisted on your firewall, and they must append a custom header like 'X-Security-Test: VendorName' to every request. This keeps test traffic separated from real user traffic in your logs.

4) Emergency Kill-Switch: If server CPU usage exceeds 70% or system response times see noticeable latency spikes during the test, your on-call sysadmin must have the authority to halt the test immediately with a single phone call.

EEbru K***MemberCommunity member
Joined
Aug 2025
Message
113
#3

Watch out for form-filling features in automated scanners. If they hit your newsletter sign-up or contact forms, they can dump 20,000 dummy emails into your queue in 10 minutes and get your mail server blacklisted. Exclude those forms from the scan.

AAycan Ş***ExpertCommunity member
Joined
Apr 2026
Message
259
#4

Set up dedicated test accounts with preloaded balances for the testing team. Whatever you do, do not let them test deletions or reserve items in their carts against real inventory, or your stock will get locked up.

YYusuf Ç***ExpertCommunity member
Joined
Feb 2024
Message
419
#5

We ran a test on prod two years ago, and while checking for SQL Injection, the pentester fired off a sleep query. The database connection pool was exhausted in 3 minutes, and checkout threw errors on the live site for 20 minutes straight. Having an on-call devops person is non-negotiable.

İİlker P***Member
Job title
Graphic Designer
Sector
Education
Organization type
early-stage startup
Joined
Nov 2022
Message
162
#6

We scheduled ours between 02:00 and 06:00. On a site doing 1,000 orders a day, volume drops to maybe 15 orders overnight. If something locked up, the cost in lost sales was practically zero. Never run live tests during business hours.

FFatih G***Member
Job title
Production planning
Sector
IT services
Organization type
medium-sized business
Joined
Nov 2024
Message
31
#7

How will they test the payment gateway? Are they going to charge tiny amounts on live POS terminals, or are you setting up a sandbox gateway? If this isn't crystal clear in the contract, finance will have a meltdown.

UUğur Y***MemberCommunity member
Joined
Jun 2023
Message
38
#8

make sure you put a single authorized phone number in the test plan then i mean the moment anything feels off the pentester must shut down their tools as soon as that number calls to tell them to stop.

VVildan A***Member
Job title
System administrator
Sector
Cosmetics
Organization type
20-person company
Joined
Jan 2023
Message
32
#9

Not being able to match production with staging and doing a pentest on prod that basically turns into a stress test is such a classic thrill-seeking move unique to our industry. At least take a full backup an hour before the test so you don't wake up to a disaster scenario the next morning.

BBarış C***New member
Job title
Supply chain manager
Sector
Tourism
Organization type
two-branch business
Joined
Jul 2026
Message
249
#10

The test agreement to be drafted must clearly specify the responsibilities of both parties, explicitly stipulating that the contractor shall be liable for any commercial damages arising should the testing team deviate from the approved schedule and designated hours.

HHüsniye E***MemberCommunity member
Joined
Sep 2024
Message
260
#11

We experienced almost the exact same thing last year. When making a decision first look at what data you have on hand.

Proven by experience.

BBurhanMember
Job title
Retired Engineer
Joined
Aug 2024
Message
132
#12

There are three things to check when doing this. The real issue isn't the number, but what it's based on.

Just because everyone does it doesn't mean it's right. If I were you, I'd go this route.

OOkan U***Member
Job title
Data entry clerk
Sector
Retail
Organization type
workshop
Joined
Nov 2022
Message
84
#13

I agree.

TTolga M***Member
Job title
Courier coordinator
Sector
Sports and fitness
Organization type
300-person organization
Joined
Apr 2024
Message
66
#14

Three different views emerged, they all complement each other. If you get three different answers on a topic, the question was asked wrong.

Correct me if I'm wrong.

RReyhan K***Member
Job title
IT manager
Sector
Electrical-electronics
Organization type
regional distributor
Joined
Apr 2023
Message
93
#15

Following.

İİbrahim K***MemberCommunity member
Joined
Mar 2026
Message
4
#16

There are three things to check when doing this. If you scold false alarms, nobody will report again.

This is my opinion, I'm not claiming it's absolute truth.

GGürkan K***Member
Job title
Human Resources Specialist
Sector
Catering
Organization type
120-person company
Joined
Dec 2024
Message
157
#17

Exactly, and not many people know this. Trying to do this alone is the most expensive way.

KKübra Ö***VeteranCommunity member
Joined
Apr 2024
Message
317
#18

We experienced almost the exact same thing last year. Solutions that work at a small scale collapse when you grow; I learned this late.

Hope this helps.

FFiliz P***Member
Job title
Production Manager
Sector
E-commerce
Organization type
300-person organization
Joined
Jun 2025
Message
166
#19

I've been dealing with this for a long time. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Just leaving this note, it might be useful.

LLevent E***Member
Job title
Warehouse Manager
Sector
Healthcare services
Organization type
120-person company
Joined
Jul 2024
Message
108
#20

Thanks for writing this, that's the right way. Having backups accessible on the same network and with the same identity makes them part of the target.

Mistakes made on the web pentest test plan side are usually reversible but expensive. If you have questions, write them; I'll answer as best I can.

Reply