- Job title
- Call center representative
- Sector
- Livestock
- Organization type
- 40-person manufacturing company
- Joined
- Jan 2022
- Message
- 189
We are a 4-person consulting and booking business based in London. We requested a penetration testing quote from an external professional cybersecurity firm for our web application, where we store our clients' corporate data and booking records. They came back with a £4,500 bill.
Our budget is tight, and we're worried that after spending this money, the firm will just report basic things like "your admin password is weak" or "your SSL certificate is misconfigured." We're not ruling out an audit completely, but we want to patch the low-hanging fruit ourselves before splashing cash on an external specialist.
Our technical team has a basic understanding of servers and code. Is there an actionable website security checklist we can work through step by step prior to an external audit to catch critical vulnerabilities beforehand?