We operate a 30-person logistics company. An enterprise client of ours requested an independent pentest report as part of their vendor audit. We received quotes from two different cybersecurity firms: one quoted 35,000 TL, the other 85,000 TL. Both quotes broadly state that pentesting techniques will be applied, but the scopes are night and day.
The cheaper quote covers only external network and web application testing. The pricier one adds internal network, social engineering, and wireless testing. We don't know the technical details, so we can't tell how much of that 50,000 TL gap is a genuine requirement versus pure bloat.
For a business like ours with 30 PCs and just one customer tracking portal, which core techniques are absolute must-haves in the proposal? Which ones can we safely leave out without failing the audit?