A year of planned security testing.
Some teams want testing tied to release cycles or quarterly reviews rather than booked ad-hoc. The annual programme is a way to run that work on a predictable cadence with the same people each time.
- Scope
- Testing aligned to changes
- Deliverables
- Per-cycle findings and summaries
- Approach
- Retesting in the programme
// What's typical
- 01
Plan
Agree systems, changes and dates for the next cycle.
- 02
Test
Carry out the scoped assessment and document findings.
- 03
Review
Work through evidence and prioritised fixes with your team.
- 04
Retest
Verify remediated findings and feed results into the next cycle.
- CadenceAgreed up front — usually a deep dive each quarter, with lighter checks aligned to releases or change windows.
- CoverageMix of application, infrastructure, identity, and detection testing. Adversary simulation when it makes sense.
- ReportingPer-cycle findings plus a quarterly summary. Annual review of trend, posture, and what to focus on next.
- Follow-upRe-testing of remediated findings is scheduled into the programme cadence.
- ComplianceMapping to PCI DSS, CPS 234, ISO 27001, Essential Eight when you need to evidence testing for an audit.
// Next step
Send the systems and assurance dates.
Include the systems that change most often, audit or release deadlines, and how frequently you need testing evidence.