Insights

How Often Should You Conduct an External Penetration Test?

How often should you conduct an external penetration test? Annual testing is a sensible baseline, with additional tests after significant changes or cyber incidents.

Plainsight Security penetration tester discusses annual external penetration testing with a business owner following changes to cloud, VPN and customer portal services.

For many organisations, conducting an external penetration test once a year is a sensible starting point. However, annual testing should be treated as a baseline rather than a rule that suits every business.

Organisations with rapidly changing infrastructure, numerous internet-facing services or demanding customer requirements may need to test more frequently. Testing should also be considered whenever a meaningful change occurs, rather than relying entirely on the calendar.

Why is annual penetration testing so common?

An annual penetration test provides organisations with regular, independent assurance that their internet-facing systems have been examined for exploitable weaknesses.

Twelve months is a long time in cyber security. During that period:

  • New vulnerabilities will be discovered
  • Software and infrastructure may be changed
  • New systems could be exposed to the internet
  • Firewall or cloud configuration changes may introduce weaknesses
  • Suppliers and administrative responsibilities may change
  • Previous remediation may no longer be effective

A penetration test is a snapshot of your external security at the time the testing takes place. Passing a test today does not guarantee that the same environment will remain secure for the following 12 months.

Annual testing is therefore a useful minimum for many organisations, but it should form part of an ongoing security programme rather than being viewed as a once-a-year exercise.

When should you test more frequently?

Testing every six months, or even quarterly, may be appropriate where an organisation:

  • Operates numerous internet-facing systems
  • Regularly changes its external infrastructure
  • Provides online or cloud-based services to customers
  • Handles sensitive, regulated or commercially valuable information
  • Is considered an attractive target
  • Has previously experienced attacks or security incidents
  • Has contractual requirements for more frequent assurance
  • Frequently acquires or integrates other businesses

The scope does not necessarily need to be identical each time. For example, an organisation might conduct a comprehensive annual penetration test while arranging smaller, targeted tests following particular projects or infrastructure changes.

Test after significant infrastructure changes

You should consider an external penetration test whenever a significant change could affect your internet-facing attack surface.

Examples include:

  • Installing or replacing a firewall
  • Introducing a new VPN or remote-access service
  • Migrating systems to a cloud provider
  • Changing hosting providers
  • Deploying new externally accessible servers
  • Introducing a new domain or customer portal
  • Making substantial network architecture changes
  • Moving services between suppliers
  • Completing a merger or acquisition

Even a well-planned change can produce unexpected results. A service may be exposed on the wrong network interface, a management portal could become publicly accessible or a device may retain insecure default settings.

Testing after implementation provides an opportunity to identify these problems before an attacker does.

Test new internet-facing services

New services should ideally be tested before they go live. Where that is not practical, testing should take place as soon as possible afterwards.

This may apply to:

  • VPN gateways
  • Remote desktop gateways
  • File-transfer services
  • Email gateways
  • Customer portals
  • Cloud-hosted management platforms
  • Web servers
  • APIs and mobile application back ends

It is important to choose the right type of test. An external infrastructure penetration test assesses services such as firewalls, VPNs and externally accessible servers. A bespoke customer portal or API may require a dedicated web application penetration test.

Simply including the application’s IP address in a general infrastructure test will not provide the same depth of coverage.

Test following a cyber incident

A cyber incident may reveal weaknesses in technology, processes or previous security assumptions.

An external penetration test may be useful following:

  • Unauthorised access to an internet-facing system
  • Compromise of a VPN or remote-access account
  • Discovery of an exposed management interface
  • Exploitation of a public-facing vulnerability
  • Suspicious activity involving an external service
  • Completion of incident remediation

Penetration testing is not a replacement for incident response or forensic investigation. Its role comes later, helping to verify that the identified weaknesses have been corrected and that similar attack paths are no longer available.

Customer, tender and contractual requirements

The right testing frequency is not always determined by technical risk alone. Customers, insurers and procurement teams may expect evidence of regular independent testing.

They might request:

  • A recent penetration testing report
  • An executive summary
  • Confirmation that serious findings were remediated
  • Evidence of independent testing within the previous 12 months
  • Testing following significant changes
  • Annual assurance as part of supplier onboarding

Having a recent report available can make security questionnaires, tender submissions and supplier due-diligence exercises much easier. It can also prevent delays when a potential customer requests evidence at short notice.

There is no single regulatory testing frequency that applies to every organisation. Requirements may instead be influenced by regulations, industry standards, customer contracts, cyber insurance conditions or internal risk-management policies.

Businesses should establish exactly what evidence, scope and frequency their particular obligations require.

Is Cyber Essentials Plus a substitute?

Cyber Essentials Plus and external penetration testing provide different forms of assurance.

Cyber Essentials Plus uses a defined assessment process to verify that the Cyber Essentials technical controls have been implemented effectively. An external penetration test examines internet-facing systems to identify weaknesses that could be exploited by an attacker.

One should not automatically be treated as a substitute for the other. An organisation may benefit from both, particularly where customers expect evidence of certification alongside more detailed security testing.

Can vulnerability scanning be used between tests?

Automated external vulnerability scanning can provide more frequent visibility between penetration tests.

A practical assurance programme might include:

  • Regular external vulnerability scanning
  • Prompt investigation of serious findings
  • Annual independent penetration testing
  • Additional testing following significant changes
  • Retesting after important vulnerabilities are corrected

Scanning is valuable for identifying known vulnerabilities and unexpected exposed services. However, it does not provide the same manual investigation, validation or depth as a penetration test.

The two approaches work best when they complement each other.

What about smaller businesses?

A small business with a limited and stable external presence may not need quarterly penetration testing. An annual test, supported by vulnerability scanning and additional testing after significant changes, may provide proportionate assurance.

However, company size alone does not determine risk. A small organisation operating a customer portal, processing sensitive information or exposing remote-access services may need more frequent testing than a much larger organisation with a very limited internet presence.

A simple decision guide

SituationSuggested approach
Small, relatively stable external environmentConsider annual testing
Regular infrastructure or cloud changesTest annually and after significant changes
High-risk or heavily internet-facing environmentConsider six-monthly or more frequent testing
New VPN, firewall or remote-access serviceTest after implementation
New customer portal or bespoke applicationArrange dedicated application testing
Recent cyber incidentTest after remediation, alongside appropriate incident-response work
Customer or contractual requirementFollow the specified frequency and scope

These are practical guidelines rather than rigid rules. Your schedule should reflect the systems you expose, how frequently they change and the consequences if they are compromised.

Test according to risk and change

Annual external penetration testing is a sensible baseline for many organisations, but it should not become a box-ticking exercise.

The most effective approach combines scheduled testing with event-driven reviews whenever the external attack surface changes materially. This provides assurance when it is most valuable, rather than waiting for the next anniversary while an unknown weakness remains exposed.

If you are unsure whether your existing test is still current, Plainsight Security can review your external scope and recommend a proportionate testing schedule based on your systems, risk and customer requirements.

Portrait of Plainsight Security's lead tester

Written by

Mark Tomlinson

Our lead penetration tester, Mark Tomlinson, holds The Cyber Scheme Team Leader qualification in infrastructure penetration testing, an advanced certification recognised by the National Cyber Security Centre (NCSC) and used by professionals testing government systems and UK critical national infrastructure. Mark is also registered with the UK Cyber Security Council as a Principal Cyber Security Professional (PriCSP) specialising in Security Testing and holds an MSc in Computer Science with Cyber Security.

More about how we work
Talk to a tester

Put this into practice.

Cyber Essentials, Cyber Essentials Plus, and penetration testing — fixed-price, plain English, and built to stay out of your way.

← All insights