What Events Should Trigger a Penetration Test A Three-Part Practical Guide for CIOs
Posted in Penetration Testing
What Events Should Trigger a Penetration Test?
An annual penetration test should be supplemented when significant changes introduce new attack surfaces. Many people ask “What Events Should Trigger a Penetration Test?”
This part will help to answer that question.
A Major Cloud Migration
Moving critical information into AWS, Microsoft Azure, or another cloud environment can significantly change your security controls.
New identity permissions, storage configurations, security groups, APIs, virtual networks, and cloud services may all create opportunities for misconfiguration.
Don’t assume your cloud environment is secure just because it’s hosted by a big provider.
The provider protects the core cloud infrastructure, but your company is still responsible for identity, settings, workloads, apps, and data.
Doing a focused cloud penetration test or security assessment after the migration can help you find weaknesses before they cause problems.
A New or Significantly Updated Web Application
Web applications are always changing.
A new feature can introduce a new authorization weakness. A new API can expose data in an unexpected way. A change in business logic can create an attack path that wasn’t previously possible.
Tanner Security recommends that web applications be tested at least annually, with additional testing after major updates, new feature releases, infrastructure changes, or significant third-party integrations.
If your company develops software quickly, CIOs should consider targeted testing before major releases rather than only running one test a year.
A Merger or Acquisition
When you acquire another company, you get more than just new employees and customers.
They can introduce:
- Unmanaged systems
- Legacy infrastructure
- Unknown administrative accounts
- Different cloud environments
- Unsupported applications
- Inconsistent security controls
- Third-party access relationships
A penetration test can show you how attackers might move between the new company’s systems and your own.
This is especially important when you’re combining networks, user accounts, apps, or cloud services.
A Significant Security Incident
If your company experiences a cybersecurity incident, penetration testing can help you determine whether attackers could still access your systems.
The goal isn’t to redo the incident investigation.
Instead, testing can evaluate whether the same weaknesses could be exploited via a different gap in controls and whether the company’s broader security controls can detect and prevent similar activity.
Major Changes to Identity or Remote Access
Identity has become one of the most important security boundaries for modern companies.
Changes involving Microsoft 365, Microsoft Entra ID, VPNs, remote access platforms, multi-factor authentication, privileged access, or single sign-on can have far-reaching security consequences.
If an attacker gets access to someone’s identity, they could reach email, cloud apps, internal systems, sensitive files, and other key resources.
After major changes to how you manage identities, targeted testing can help ensure your access controls are working properly.
A Practical Penetration Testing Schedule for CIOs
There’s no one-size-fits-all schedule, but this model is a good place to start.
Lower-Risk, Stable Companies
If your company’s technology doesn’t change much and you have limited exposure, start with a full penetration test every 12 months.
You should also consider extra tests after big infrastructure changes, major security incidents, or when you add important new applications.
Mid-Market Companies With Ongoing Change
Companies that use cloud services and web applications and make infrastructure changes should perform an annual penetration test and plan for targeted testing throughout the year.
For example, a company might perform annual external and internal penetration tests and conduct targeted web application testing before major releases.
High-Risk or Highly Regulated Companies
Companies that handle sensitive data, provide critical services, or operate under strict rules may need to test more often.
This might mean doing targeted tests every few months, along with a full penetration test once a year.
How often you test should depend on your systems, the threats you face, how quickly things change, and what could happen if something goes wrong.
Penetration Testing Frequency Related Services
- External Network Penetration Testing: Evaluate your company’s internet-facing systems from the perspective of an external attacker. Testing may include public infrastructure, VPNs, remote access systems, cloud services, and other externally accessible assets. Tanner Security recommends annual testing and additional testing after significant changes.
- Internal Network Penetration Testing: Determine what an attacker could accomplish after gaining an initial foothold inside your network.
- Web Application Penetration Testing: Evaluate business-critical web applications for vulnerabilities involving authentication, authorization, session management, input validation, APIs, and business logic.
- Custom Application Penetration Testing: Assess proprietary applications with complex workflows, integrations, user roles, and functionality that may require deeper manual testing.
- Cloud Penetration Testing: Test AWS, Azure, and other cloud environments for exploitable weaknesses and misconfigurations.
- Vulnerability Assessments: Identify known vulnerabilities more frequently and use the results to support ongoing remediation between penetration testing engagements.
- Cybersecurity Risk Assessments: Evaluate the broader cybersecurity program and identify which systems, threats, and weaknesses should receive the highest priority.
FAQ’s – Events That Should Trigger a Penetration Test
What events should trigger a penetration test?
A penetration test should be considered after major technology or business changes that introduce new attack surfaces. Common triggers include cloud migrations, significant web application updates, mergers and acquisitions, cybersecurity incidents, major identity or remote-access changes, and the deployment of new internet-facing systems.
Do I need a penetration test after moving to the cloud?
A major migration to AWS, Microsoft Azure, or another cloud platform can justify additional penetration testing. Cloud migrations can change identity permissions, network configurations, APIs, storage, workloads, and security controls. Testing after a significant migration can help identify vulnerabilities or misconfigurations that may not have existed in the previous environment.
Should a company perform a penetration test after a major software update?
Yes, particularly when an update changes authentication, authorization, business logic, APIs, payment functionality, sensitive data access, or other security-sensitive features. Significant application changes can introduce vulnerabilities that were not present during previous testing.
Should a company perform a penetration test after a merger or acquisition?
A merger or acquisition can introduce unfamiliar networks, applications, user accounts, cloud environments, administrative privileges, and third-party connections. Penetration testing can help identify weaknesses that could allow an attacker to move between the acquired company’s environment and your existing systems.
Should you perform a penetration test after a cybersecurity incident?
Potentially, yes. After an incident, targeted penetration testing can help determine whether vulnerabilities related to the incident, or other weaknesses that could provide an alternative attack path, remain exploitable. Penetration testing should complement, rather than replace, incident response, forensics, and root-cause analysis.
Do changes to Microsoft 365 or Entra ID require penetration testing?
Significant changes to Microsoft 365, Microsoft Entra ID, VPNs, single sign-on, privileged access, or other identity and remote-access systems may warrant targeted security testing. Because compromised credentials can provide access to multiple systems and applications, changes to identity architecture can materially affect a company’s attack surface.
Should penetration testing be performed before or after a major technology change?
In many cases, both approaches can provide value. Testing before a major change can identify weaknesses in the existing environment and help establish a baseline, while testing after implementation can determine whether the new environment was configured securely. For major application releases, targeted testing before deployment can also help identify vulnerabilities before they reach production.
What is the difference between annual penetration testing and event-driven testing?
An annual penetration test provides a scheduled assessment of the company’s security controls and attack surface. Event-driven testing is performed because something has changed, such as cloud migration, application release, acquisition, or security incident. Using both approaches helps companies avoid relying on a security assessment that may no longer reflect their current environment.
Can a vulnerability assessment replace a penetration test after a major change?
Not always. A vulnerability assessment primarily identifies known vulnerabilities and security weaknesses, while penetration testing attempts to determine whether vulnerabilities and weaknesses can be combined or exploited in a realistic attack. Depending on the nature of the change, a vulnerability assessment, penetration test, or combination of both may be appropriate.
What should a CIO do if the company’s technology environment changes constantly?
Companies with rapidly changing environments should consider treating security testing as an ongoing process rather than a once-a-year event. An annual comprehensive penetration test can be supplemented with targeted testing of new applications, cloud environments, identity systems, APIs, and significant infrastructure changes.
Schedule a Call