Services
Services
SOC & Attestations
SOC & Attestations
Payment Card Assessments
Payment Card Assessments
ISO Certifications
ISO Certifications
Privacy Assessments
Privacy Assessments
Federal Assessments
Federal Assessments
Healthcare Assessments
Healthcare Assessments
Penetration Testing
Penetration Testing
Cybersecurity Assessments
Cybersecurity Assessments
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
ESG & Sustainability
ESG & Sustainability
AI Services
AI Services
Industry Solutions
Industry Solutions
Cloud Computing & Data Centers
Cloud Computing & Data Centers
Financial Services & Fintech
Financial Services & Fintech
Healthcare
Healthcare
Payment Card Processing
Payment Card Processing
US Government
US Government
Higher Education & Research Laboratories
Higher Education & Research Laboratories
About Us
About Us
Leadership Team
Leadership Team
Careers
Careers
Corporate Social Responsibility
Corporate Social Responsibility
Strategic Partnerships
Strategic Partnerships

How Often Should You Have a Penetration Test Performed?

Penetration Testing

So you're interested in having a penetration test performed and you're wondering, is one enough for five years? Do I have to do it weekly or monthly? In this video, we'll talk about how frequently you should have a test performed.

Hi, I'm Josh Tomkiel, I'm a senior manager here at Schellman on the pen test team. I've been in the industry for over 10 years, started out as a penetration tester, and now I'm a manager so I've seen things from both sides. And all the time we get asked: "how frequently should we have a penetration test performed?"

Well, as with most things, it does depend (at least annually). If there are any major changes to your environment or web application, that's a good time to have a pen test. If there's a compliance initiative that says you must do it by X date or you must have certain things tested, well, there's your answer on that front.

But in general, we have all sorts of clients having pen tests performed quarterly or after major releases, or annually. It's really up to you.

The threat landscape is always evolving and changing. Just because you're not vulnerable today doesn't mean you won't be vulnerable to something tomorrow.

There are new patches, and security updates coming out all the time. And a pen test is only good for a moment in time. That point in time, that report, that deliverable will say you had certain issues or you didn't have certain issues identified at this point in time. Now, tomorrow is a different story.

So I hope you understand now why maybe just having a pen test performed annually is not good enough in all cases. If you're interested in learning more about penetration testing or have any other questions, head over to our website, fill out our form and I or another pen test specialist will be in touch shortly. 

About JOSH TOMKIEL

Josh Tomkiel is a Managing Director and Penetration Tester based in Philadelphia, PA with over 10 years of experience within the Information Technology field. Josh has a deep background in all facets of penetration testing and works closely with Schellman's other service lines to ensure penetration testing requirements are met. Additionally, Josh leads the Schellman's Red Team service offering, which provides an in-depth security assessment focusing on different tactics, techniques, and procedures (TTPs) for clients with mature security programs.