Annual programme

For when one-off testing doesn't match how you actually ship and operate.

Recurring penetration testing on a calendar.

Some teams want testing tied to release cycles or quarterly reviews rather than booked ad-hoc. The annual programme is a way to run that work on a predictable cadence with the same people each time.

  • CadenceAgreed up front — usually a deep dive each quarter, with lighter checks aligned to releases or change windows.
  • CoverageMix of application, infrastructure, identity, and detection testing. Adversary simulation when it makes sense.
  • ReportingPer-cycle findings plus a quarterly summary. Annual review of trend, posture, and what to focus on next.
  • Follow-upRe-testing of remediated findings is scheduled into the programme cadence.
  • ComplianceMapping to PCI DSS, CPS 234, ISO 27001, Essential Eight when you need to evidence testing for an audit.

// What it isn't: a SOC, a scanner subscription, or a compliance tick-box without testing.

Scope first

A short note is enough. We reply within one Australian business day.

Send the systems and assurance dates.

Include the systems that change most often, audit or release deadlines, and how frequently you need testing evidence.