As we approach the end of the financial year, it’s that time again when organisations turn their attention to annual security assurance services, such as penetration testing, to help inform their budget. During this period, a common trend emerges where organisations dust off last year’s scope and request for it to be tested again, without considering whether there have been significant changes in their environment.
While some organisations adopt this approach to comply with their obligations (such as ISO 27001 or PCI), others may not have thought about alternative ways to achieve assurance with greater value. At Sentaris, we recommend two complementary strategies to refine your security assurance: avoiding “over assurance” while scoping your annual penetration testing; and shifting more security assurance responsibilities into your project lifecycle.
Traditional annual Penetration Testing often involves testing the same scope every year, assuming no significant changes in the risk landscape or compliance requirements. This approach can be inefficient and costly, consuming valuable resources without delivering tangible benefits. We suggest working with your Penetration Testing provider to:
Embedding security and privacy measures at the earliest stages of a project ensures that all stakeholders understand their roles in maintaining a secure environment. It also ensures that the appropriate security assurance is budgeted for. Ensuring security assurance is considered in projects can help alleviate pressure on Business as Usual (BAU) budgets, which can then be used to test legacy or other “at-risk” systems.
We recommend:
By implementing robust project governance, organisations can ensure that all security requirements are captured early in the project lifecycle. If you would like more information on how to implement Security Assurance effectively into your Project Management lifecycle, feel free to Contact Us
Adopting these strategies doesn’t mean compromising on security; instead, it allows organisations to optimise their resources while maintaining a level of protection within their risk appetite. By moving away from only performing security assurance practices annually and towards a “secure by design” strategy, the annual funding provided to Security teams can be appropriately applied to areas of the business that have not been assessed.
As the financial year approaches, now is the perfect time to initiate meaningful changes in your approach to your Security Assurance. Whether it’s creating a three-year roadmap or implementing project triage tools, these strategies can help uplift your overall security posture while keeping pressure away from annual security assurance budgets.
Sentaris is proud of its pragmatic approach to security assurance, which has helped many organisations better understand their risks without needing a significant increase in their budget. If you would like to learn more, please don’t hesitate to reach out to us.