We run a 14-person B2B platform based in Milan managing wholesale and ordering processes. Last week, we reached the annual supply contract renewal stage with a major nationwide enterprise client in Italy. Their procurement department sent us a security questionnaire and made it a requirement to provide an independent penetration test report completed within the last 12 months.
Our in-house sysadmin says we run weekly automated vulnerability scans and that they always come back clean. However when we requested a quote from a local cybersecurity firm, they came back with a hefty figure of around 5,500 EUR for the web app and API endpoints. What exactly is a penetration test, and how does it differ from automated scans to justify such high fees? For a business of our scale, is this truly an unavoidable requirement or is there a more reasonable way to handle the process?