There is no universal right frequency. Annual testing is the usual baseline because certifications, insurers and customer contracts tend to expect it, but the right answer depends on how quickly your environment changes and what it protects.
Why it matters
A test is a snapshot in time. Every release, migration and new integration after it chips away at what the report can tell you. Tying cadence to your rate of change keeps the assurance meaningful rather than ceremonial.
A sensible cadence
- Annually as the floor, which is what most frameworks, insurers and tenders look for
- After major change: a new internet-facing application, a cloud migration, a significant upgrade
- Before go-live for anything that will hold sensitive data or face the internet
- After an incident, to confirm the route that was used is genuinely shut
- More frequently in fast-moving environments, where rotating focused tests beats one big annual exercise
Getting more from the gap between tests
Continuous vulnerability scanning between tests catches newly disclosed flaws in systems you have already had tested. Retesting remediated findings closes the loop on the previous report. Together they mean each annual test starts from a known position instead of rediscovering the same issues.
Intelligence Group tests networks, applications, wireless and people across New Zealand and Australia, evidences every finding and retests once you have fixed it. See what we test or request a quote.

