How often should security testing (penetration tests / audits) be performed?

SituationRecommended action
Significant change in IT/OT infrastructureImmediately after the change
New system / application / service rolloutBefore going live + 30 days after
No changes in the environmentAt least once per year
Regulated entities (NIS2, KSC, critical operators)Minimum once per year + after changes
High-risk environments (finance, industry, OT)2–4 times per year or continuous

Why regular testing is crucial

Best practice (used by my retainer clients)

Continuous / automated security testing (vulnerability scanning + quarterly red-team or pen-test) combined with an annual comprehensive audit — this is currently the gold standard for production plants, law firms, and critical infrastructure operators in Poland.