forumNew topic

They keep talking about penetration testing techniques — which ones should actually be in our proposal?

FFeyza S***MemberCommunity member
Joined
Aug 2023
Message
251
#1

We operate a 30-person logistics company. An enterprise client of ours requested an independent pentest report as part of their vendor audit. We received quotes from two different cybersecurity firms: one quoted 35,000 TL, the other 85,000 TL. Both quotes broadly state that pentesting techniques will be applied, but the scopes are night and day.

The cheaper quote covers only external network and web application testing. The pricier one adds internal network, social engineering, and wireless testing. We don't know the technical details, so we can't tell how much of that 50,000 TL gap is a genuine requirement versus pure bloat.

For a business like ours with 30 PCs and just one customer tracking portal, which core techniques are absolute must-haves in the proposal? Which ones can we safely leave out without failing the audit?

LLeyla Y***MemberCommunity member
Joined
Mar 2026
Message
61
Most Helpful#2

Short answer: The non-negotiable core techniques in the quote are web application penetration testing and external network penetration testing. Social engineering, internal network, and wireless assessments are supplementary layers depending on your physical setup and your client's specific audit specs.

To scope this properly, break it down into three key criteria. First is external network testing. This technique scans your internet-facing servers, routers, and firewalls from outside to identify open ports or configuration flaws. Second, web application testing is mandatory; it probes the client tracking portal for privilege escalation, SQL injection, and session management vulnerabilities. Since the auditing client accesses your systems over the web, this is the very first area they will look at.

The internal network and social engineering items in the pricier quote measure how far an attacker could spread once they're already inside your perimeter. That involves physically coming to your office to plug into network ports or sending phishing emails to staff to harvest credentials. Unless your client explicitly demanded staff awareness or internal network testing in the audit specs, you can safely descope those for now. That allows you to clear the audit cleanly with a baseline test in the 35,000 TL to 45,000 TL range.

ZZeynep K***Expert
Job title
Marketing manager
Sector
Textile
Organization type
two-branch business
Joined
Nov 2023
Message
330
#3

Ask your client for their written audit requirements or checklist. Most corporate clients only care about a report covering external-facing assets. Unless social engineering is explicitly stated in the specs, just scope external network and web portal testing and approve the quote that way.

DDoruk S***New memberCommunity member
Joined
Aug 2026
Message
278
#4

Went through the exact same thing last year for our 40-person manufacturing business. We stripped out social engineering and had the initial 75,000 TL quote revised down to 40,000 TL for just external network and portal testing. The auditor accepted the report with zero issues.

İİbrahim K***MemberCommunity member
Joined
Apr 2023
Message
204
#5

Ask the firm whether their web application testing includes manual verification based on OWASP standards. If they're just going to run an automated scanner and dump screenshots into a PDF, that report has zero technical value, and the auditor might reject it for lack of detail.

SSerkan Ç***VeteranCommunity member
Joined
May 2023
Message
294
#6

Is your customer tracking portal hosted on a physical server in your office or on an external cloud provider? Does the portal store personal data or commercial invoices? Those details directly dictate the depth of the external test and the techniques needed.

MMeryem S***Member
Job title
Human Resources Specialist
Sector
E-commerce
Organization type
two-branch business
Joined
Dec 2024
Message
303
#7

The social engineering line item is usually tacked on just to inflate the budget. No need to pay extra just to have them phish three employees and write a report saying "staff clicked the link"—that's staff training, not pentesting.

VVeli Y***MemberCommunity member
Joined
Feb 2024
Message
8
#8

Tell the pricey vendor to give you an itemized quote just for the external network and web app testing. Once you get a line-by-line breakdown you'll clearly see the unnecessary costs and can trim things down according to your budget.

MMurat K***Member
Job title
Human Resources Manager
Sector
Freight
Organization type
early-stage startup
Joined
Aug 2025
Message
333

Doki · Brand identity · 2023

#9

we also went for the whole package at first but then we ended up having to host security experts in our office for two days for the internal network test then unless it's mandatory, don't bother going that deep and disrupting your workflow; just proving your front door is locked is enough.

TTuğçe V***Member
Job title
Software developer
Sector
Healthcare services
Organization type
boutique agency
Joined
Mar 2022
Message
289
#10

The takeaway from this discussion is clear: unless the client specifically asked for internal network or staff testing, having just web portal and external network techniques in your proposal is plenty. Confirm the specs before setting aside budget for extra techniques.

EElif D***MemberCommunity member
Joined
Oct 2024
Message
98
#11

I agree, and I'd like to emphasize that. Your time to detect an issue directly determines its cost.

Proven by experience.

OOsman K***Member
Job title
Logistics planning
Sector
Energy
Organization type
a company within a holding
Joined
Sep 2025
Message
125
#12

Let me summarize what's been said so far. Having backups accessible on the same network and with the same identity makes them part of the target.

SSinan B***MemberCommunity member
Joined
Apr 2024
Message
140
#13

saved.

EEmine Y***ExpertCommunity member
Joined
Apr 2024
Message
7
#14

I felt relieved reading this answer, so it's not just me. An automated scan report is not the same as a penetration test.

If I were you, I'd go this route.

FFatih K***Member
Job title
Human Resources Manager
Sector
Accounting & advisory
Organization type
20-person company
Joined
Jan 2023
Message
37

Doki · Vulnerability scanning · 2024

#15

My questions are cleared up, thanks. Don't hesitate to ask; those who don't ask always pay more.

YYiğit Y***New member
Job title
Sales Manager
Sector
Machinery manufacturing
Organization type
a company within a holding
Joined
Aug 2026
Message
4
#16

Following.

CCaner E***MemberCommunity member
Joined
Sep 2024
Message
11
#17

Thanks, that was the answer I was looking for. Don't hesitate to ask; those who don't ask always pay more.

Don't hesitate to ask; those who don't ask always pay more. Hope this helps.

OOnur Y***Member
Job title
Social media manager
Sector
Leather
Organization type
regional distributor
Joined
Aug 2025
Message
120
#18

You're right. Most incidents start with a leaked password, not a vulnerability.

Everything goes well for the first three months; problems arise in the fourth.

TTülay Y***MemberCommunity member
Joined
Jan 2025
Message
412
#19

I agree, and I'd like to emphasize that. Security isn't absolute; it's about making attacks not worth the effort.

MMert Y***Expert
Job title
Board member
Sector
Logistics
Organization type
medium-sized business
Joined
Oct 2023
Message
306
#20

I'll try it.

Reply