Recommended frequency
| Situation | Recommended action |
|---|---|
| Significant change in IT/OT infrastructure | Immediately after the change |
| New system / application / service rollout | Before going live + 30 days after |
| No changes in the environment | At least once per year |
| Regulated entities (NIS2, KSC, critical operators) | Minimum once per year + after changes |
| High-risk environments (finance, industry, OT) | 2–4 times per year or continuous |
Why regular testing is crucial
- Most breaches exploit vulnerabilities that were known for months
- NIS2, ISO/IEC 27001, TISAX®, and Polish UKE/KSC regulations explicitly require regular testing
- One-time tests give only a snapshot — threats evolve daily
Best practice (used by my retainer clients)
Continuous / automated security testing (vulnerability scanning + quarterly red-team or pen-test) combined with an annual comprehensive audit — this is currently the gold standard for production plants, law firms, and critical infrastructure operators in Poland.