- Job title
- Intern
- Sector
- Advertising and promotion
- Organization type
- two-branch business
- Joined
- Mar 2025
- Message
- 406
We're a boutique brand making and selling natural cosmetics online. We get around 15,000 unique visitors a month. For checkout, we use a third-party virtual POS infrastructure, so credit card details aren't stored on our servers. Last week, as part of a B2B supply contract we're negotiating with a corporate partner, they asked us for an up-to-date "pentest report" of our systems.
While looking into it, we got a quote from a cybersecurity firm; they quoted us 45,000 TL for a web app and server penetration test. Since our budget is limited, this felt pretty steep to us.
What exactly does a pentest mean, and what do cybersecurity folks actually do here? Is this test truly vital for a small e-commerce site that doesn't store card data, or is it just a formality audit that only huge holding companies need to deal with?