forumNew topic

We were asked to get a pentest for our site, what does that mean and is it really necessary?

TTaner A***Veteran
Job title
Intern
Sector
Advertising and promotion
Organization type
two-branch business
Joined
Mar 2025
Message
406
#1

We're a boutique brand making and selling natural cosmetics online. We get around 15,000 unique visitors a month. For checkout, we use a third-party virtual POS infrastructure, so credit card details aren't stored on our servers. Last week, as part of a B2B supply contract we're negotiating with a corporate partner, they asked us for an up-to-date "pentest report" of our systems.

While looking into it, we got a quote from a cybersecurity firm; they quoted us 45,000 TL for a web app and server penetration test. Since our budget is limited, this felt pretty steep to us.

What exactly does a pentest mean, and what do cybersecurity folks actually do here? Is this test truly vital for a small e-commerce site that doesn't store card data, or is it just a formality audit that only huge holding companies need to deal with?

KKemal Ö***Member
Job title
Co-founder
Sector
Cleaning services
Organization type
300-person organization
Joined
Oct 2023
Message
28
Most Helpful#2

Short answer: A pentest, or penetration test, is a legal, controlled attack simulation carried out by authorized cybersecurity professionals to detect vulnerabilities in your IT systems before malicious hackers do. The goal is to find and patch weaknesses before any potential data leak or downtime occurs.

A lot of business owners think their sites won't be targeted just because they don't store credit card details. But card details aren't a hacker's only target. Pentest pros test your system on these fronts: 1) Checking if personal data like customer names, addresses, and phone numbers can be pulled from the database, 2) Seeing if unauthorized access can be gained to the admin panel, and 3) Testing whether site prices can be manipulated during checkout.

The process generally consists of reconnaissance, vulnerability scanning, exploitation, and reporting phases. Once the test is done, the security team ranks the risks by severity and provides clear remediation advice so your developer knows how to patch those holes.

In your case, your corporate partner is asking for this report to secure their supply chain. Since you also have an obligation to protect customer data under KVKK, a pentest isn't a luxury even for small sites—it's concrete assurance for corporate reputation and legal compliance.

PPolat K***MemberCommunity member
Joined
May 2025
Message
27
#3

Pentests are usually done using three methods: Black Box, where zero info about the system is provided; White Box, where source code and server access are granted; and Gray Box, done using standard user privileges. For an e-commerce site, the most efficient one is a Gray Box test, which mimics both an external attacker and a customer with escalated privileges.

BBurcu E***Member
Job title
Data Analyst
Sector
Jewelry
Organization type
300-person organization
Joined
Jul 2023
Message
246
#4

We had a 3-day test done for our similarly sized site two months ago and paid 38,000 TL. We weren't storing cards either, but an authentication vulnerability was found on the API. Turns out any user could view the order history and home addresses of all other customers. Patching just that one vulnerability was well worth the money.

CCeren A***Expert
Job title
Brand Manager
Organization type
chain store
Joined
Aug 2023
Message
154
#5

Definitely ask the firm quoting 45,000 TL about their scope. There are plenty of shops out there that just run automated software and hand over the tool's raw output two hours later calling it a report. Will they do manual testing, how many man-days will they put in does the tester have valid certs? Get all of that in writing.

JJale Ç***MemberCommunity member
Joined
Nov 2024
Message
199
#6

If your partner wants the report, you can't dodge it. To bring the quote down, narrow the scope: 1) Include only the web app and exclude the internal office network, 2) Cap the testing duration at 2 business days, 3) Put a free verification test (re-test) in the contract for after the vulnerabilities get patched.

SSelim C***MemberCommunity member
Joined
Nov 2025
Message
53
#7

Last year when we were running a small jewelry site, we used to say "who would bother targeting us." Then one day they breached our database through the customer portal, wiped all delivery addresses, and demanded ransom. We couldn't make sales for two weeks, and restoring backups plus recovering from data loss cost us way more than any test fee ever would.

BBurak A***Member
Job title
IT manager
Sector
E-commerce
Organization type
early-stage startup
Joined
May 2023
Message
126
#8

using a third-party virtual pos only covers card security. anyway if the address and contact details of thousands of people stored in your site's database get stolen, the penalties under kvkk will be way higher than 45k lira.

NNeslihan S***Member
Job title
Board member
Sector
Cosmetics
Organization type
medium-sized business
Joined
Sep 2025
Message
325

Doki · Server maintenance contract · 2023

#9

Does your partner want a standard independent audit report, or are they requiring a TSE-approved Level A or B certified penetration test? If their spec sheet mentions a specific accreditation requirement, don't waste money on shady fly-by-night firms—the report won't be accepted.

ZZerrin K***ExpertCommunity member
Joined
Sep 2024
Message
139
#10

Don't let the process freak you out just because it's your first time. Your site won't crash while the security firm is testing; they usually run tests on a staging clone or during low-traffic overnight hours in a controlled way.

KKübra M***Member
Job title
Accounting Manager
Sector
Consulting
Organization type
early-stage startup
Joined
Oct 2023
Message
140
#11

The opposite happened to me that's why I'm writing. Don't rely on a single measure; go layer by layer.

This is my opinion I'm not claiming it's absolute truth.

EElif B***Member
Job title
Courier coordinator
Sector
Healthcare services
Organization type
a company within a holding
Joined
Dec 2023
Message
228
#12

You're right.

IIrmak P***ExpertCommunity member
Joined
Dec 2023
Message
153
#13

let me share what happened to me; it might be useful but your time to detect an issue directly determines its cost.

of course it varies if your situation is different.

AAhmet Z***MemberCommunity member
Joined
Feb 2024
Message
25
#14

I'm curious too. Don't hesitate to ask; those who don't ask always pay more.

An automated scan report is not the same as a penetration test. Proven by experience.

YYasemin I***MemberCommunity member
Joined
Jun 2022
Message
11
#15

Thanks, that was the answer I was looking for.

AAycan O***Member
Job title
Front office accounting
Sector
Paper
Organization type
8-person team
Joined
May 2022
Message
6
#16

Same here.

SSultan M***MemberCommunity member
Joined
Jul 2023
Message
12
#17

Generally correct, but one part is missing. Just because everyone does it doesn't mean it's right.

If I were you, I'd go this route.

İİbrahim Y***MemberCommunity member
Joined
Feb 2026
Message
3
#18

id say dont rush. taking notes for two weeks yields better results than a six-month estimate.

this is my opinion, I'm not claiming it's absolute truth.

NNuri K***Member
Job title
Purchasing manager
Sector
Plastic
Organization type
boutique agency
Joined
Sep 2024
Message
335
#19

The opposite happened to me, that's why I'm writing. Solutions that work at a small scale collapse when you grow; I learned this late.

Proven by experience.

ÖÖzgür Y***MemberCommunity member
Joined
Mar 2022
Message
385
#20

I didn't know that.

Reply