forumNew topic

Agency is suggesting a web pentest, how does it differ from a standard pen test and does a small site need it?

VVildan B***MemberCommunity member
Joined
Nov 2023
Message
21
#1

We run a Moscow-based B2B platform selling industrial spare parts. The site features a portal where dealers log in to view custom price lists, generate quotes, and place orders. During an annual maintenance meeting, our contracted cybersecurity agency recommended a «web pentest» package and quoted 240.000 RUB for the job.

We had already run a general network and server penetration test last year and patched a few simple open port issues that popped up. When I mentioned this to the agency, they said, 'That was an infrastructure test, a web pentest is an entirely different scope.' I'm not very technical, and I feel like we're being asked to pay twice for the same security audit.

What exactly is a web pentest, and how does it differ from a standard pen test? For a platform like ours with a few hundred corporate clients—hardly a massive public e-commerce store—is this expense truly necessary, or how can we define the right scope without blowing our budget?

YYiğit N***Member
Job title
Product Manager
Sector
E-commerce
Organization type
300-person organization
Joined
Sep 2024
Message
115
Most Helpful#2

Short answer: While a standard penetration test examines your server's operating system, firewall, and open network ports, a web pentest directly targets business logic flaws in your website's application code, authorization vulnerabilities, and database interactions. For a dynamic B2B portal handling dealer logins, discount tiers, and order data, a standard network test is definitely not enough.

Think of the difference like this: A standard network test checks whether the building's exterior doors, locks, and windows are secure. A web pentest walks inside the building to see if someone can trick the receptionist, enter an unauthorized room, or pull someone else's confidential files from under a desk. If a dealer on your site can tweak the ID in the URL to view a competitor's custom discounts, or tamper with the checkout total in their browser to place an order for 100 RUB, a network test will never catch that; only a web pentest will.

To scope this properly, tell the agency you want a 'grey box' test, meaning authenticated user testing. Have them test only the dealer login, quote generation workflow, and database queries rather than every single public page. That way, you bring that 240.000 RUB quote down to a more reasonable figure while neutralizing the financial risks that actually threaten your business.

EEsra U***MemberCommunity member
Joined
Feb 2026
Message
160
#3

A network test looks for open SSH ports and outdated Linux kernels. A web pentest looks at code-level flaws like SQL injection vulnerabilities, cross-site scripting risks, and session fixation bugs. If your portal runs on custom code, the logic flaws left behind by developers will only ever surface through a web pentest.

CCansuMember
Job title
Digital marketing specialist
Joined
Jan 2024
Message
128
#4

We paid 190.000 RUB for a web test on our own B2B system last year. Our server came back completely clean, but the web test caught a critical authorization flaw where dealers could view each other's account statements. Compared to the potential brand damage, it was completely worth the money.

NNeslihan T***Member
Job title
Clinic manager
Sector
Cosmetics
Organization type
120-person company
Joined
Aug 2023
Message
335
#5

Do you store payment card data on the site, or are orders simply billed to an open trade account? Also, is this dealer portal built on off-the-shelf software, or was it coded from scratch for you? Those details dictate whether the test is really necessary.

JJale Ç***MemberCommunity member
Joined
Nov 2024
Message
199
#6

Ask the agency for their methodology document before accepting the quote. Find out what standards they follow for their reports. If they're just going to run an automated vulnerability scanner and print out a report, 240.000 RUB goes straight into the trash; if they do manual testing for business logic flaws, then it's worth talking.

ZZehra C***Member
Job title
Software developer
Sector
Consulting
Organization type
8-person team
Joined
Mar 2023
Message
94
#7

A lot of security firms on the market just run an automated vulnerability scanner for two hours and sell you a 50-page PDF report calling it a pentest. If the proposal doesn't explicitly state 'manual business logic testing' do not pay that money under any circumstances.

BBeren V***Member
Job title
Technical service technician
Sector
Advertising and promotion
Organization type
120-person company
Joined
Mar 2024
Message
123
#8

the agency is right unfortunately network testing is one thing web pentest is another. anyway if dealers see custom pricing and one manages to steal anothers rates youre gonna have a huge headache. narrow down the scope and ask for a discount but dont skip the test entirely.

OOrhan Z***MemberCommunity member
Joined
May 2023
Message
254
#9

B2B databases contain client agreements that constitute trade secrets. Signing a comprehensive non-disclosure agreement prior to procuring web pentest services and stipulating in the protocol that testing must be conducted outside operational hours are essential for your legal security.

DDeniz A***ExpertCommunity member
Joined
Aug 2025
Message
164
#10

I'm curious too.

TTolgaNew member
Job title
Developer
Organization type
cooperative
Joined
Nov 2024
Message
41
#11

Thanks, this was very helpful.

LLale U***ExpertCommunity member
Joined
Aug 2025
Message
2
#12

We experienced almost the exact same thing last year. If you scold false alarms, nobody will report again.

Of course, it varies if your situation is different.

GGizem U***MemberCommunity member
Joined
Oct 2023
Message
55
#13

let me write how it's done in practice. i mean just because everyone does it doesn't mean it's right.

DDilekNew member
Job title
Pastry Shop
Organization type
a company within a holding
Joined
Nov 2024
Message
19
#14

absolutely. i mean if I were to add anything: The real issue isn't the number but what it's based on.

of course it varies if your situation is different.

GGamze Ç***ExpertCommunity member
Joined
May 2023
Message
20
#15

The answer above hits the nail on the head. Taking measures without an inventory leaves doors you haven't seen open.

That's all, sorry if I went on too long.

MMehmet Ç***MemberCommunity member
Joined
Apr 2023
Message
277
#16

Let me summarize whats been said so far... Taking measures without an inventory leaves doors you havent seen open.

Of course, it varies if your situation is different.

JJülide A***Member
Job title
Marketing manager
Sector
Real estate
Organization type
sole proprietorship
Joined
May 2024
Message
134
#17

I didn't know that.

PPolat M***MemberCommunity member
Joined
Nov 2025
Message
69
#18

I partly agree, partly disagree. If 2FA is on, a stolen password alone is useless.

Just leaving this note, it might be useful.

JJülide U***MemberCommunity member
Joined
Feb 2024
Message
346
#19

I've been dealing with this for a long time. People defend habits, not processes. Resistance comes from there.

Having backups accessible on the same network and with the same identity makes them part of the target. Proven by experience.

NNazlı P***Veteran
Job title
System support specialist
Sector
Chemistry
Organization type
20-person company
Joined
Dec 2023
Message
2
#20

I don't think this advice fits everyone. If you scold false alarms, nobody will report again.

If permission and scope aren't in writing, don't start that test. Correct me if I'm wrong.

Reply