We run a Moscow-based B2B platform selling industrial spare parts. The site features a portal where dealers log in to view custom price lists, generate quotes, and place orders. During an annual maintenance meeting, our contracted cybersecurity agency recommended a «web pentest» package and quoted 240.000 RUB for the job.
We had already run a general network and server penetration test last year and patched a few simple open port issues that popped up. When I mentioned this to the agency, they said, 'That was an infrastructure test, a web pentest is an entirely different scope.' I'm not very technical, and I feel like we're being asked to pay twice for the same security audit.
What exactly is a web pentest, and how does it differ from a standard pen test? For a platform like ours with a few hundred corporate clients—hardly a massive public e-commerce store—is this expense truly necessary, or how can we define the right scope without blowing our budget?