Most Australian SMBs should get a human-led penetration test at least once every 12 months, and again after any significant change to their systems, such as a new web app, a cloud migration, a new office network or a major release. Between those tests, cheaper automated vulnerability scanning and assessments should run far more often, so you are not flying blind for eleven months of the year.
That is the short answer to how often you should get a penetration test. The honest answer is that frequency depends on four things: how fast your environment changes, what your insurer, clients or regulators expect, how sensitive the data you hold is, and what your last test found. This guide covers each one, gives you a practical testing calendar, and explains where automated assessments fit (and where they don't).
How often should you get a penetration test?
For most SMBs, the baseline is one human-led penetration test per year, plus a retest after fixes and an extra test whenever something significant changes. Annual is a floor, not a ceiling.
Annual testing is common for a practical reason: it lines up with insurance renewals, audit cycles and board reporting. The problem is that a pentest is a point-in-time assessment. It tells you what an attacker could do on the days testers were on your systems. A month later you might have deployed new code, opened a firewall rule for a vendor, or spun up a cloud storage bucket that nobody reviewed.
That is why a sensible testing rhythm has three layers:
- ▸Continuous or frequent scanning to catch missing patches and obvious exposures quickly.
- ▸An annual human-led penetration test to find the issues scanners miss, such as chained vulnerabilities, broken access controls and business-logic flaws.
- ▸Event-driven testing after significant change, so new risk doesn't wait until next year's test.
What counts as a "significant change" that should trigger a new test?
A significant change is anything that meaningfully alters your attack surface or how sensitive data is accessed. If you would need to redraw your network diagram or update your data-flow documentation, you probably need to test it.
Common triggers we see with Australian SMBs include:
- ▸Launching a new customer-facing web application, portal or API
- ▸A major release that changes authentication, payments, user roles or file uploads
- ▸Migrating workloads to AWS, Azure or Google Cloud, or restructuring cloud accounts
- ▸Opening a new office, merging networks after an acquisition, or changing remote-access arrangements
- ▸Replacing a firewall, VPN or identity provider
- ▸Onboarding a new MSP or bringing IT in-house
- ▸A security incident or near miss, once it has been contained and remediated
The PCI DSS standard, which applies to organisations that store, process or transmit cardholder data, formalises this idea: v4.0 requires internal and external penetration testing at least once every 12 months and after any significant infrastructure or application upgrade or change. Even if you are not in scope for PCI DSS, it is a useful benchmark for what "reasonable" looks like.
Does Australian law or regulation say how often you must pentest?
For most private-sector SMBs, no Australian law sets a fixed pentest frequency. What exists instead are obligations to take reasonable steps to protect information, plus contractual and industry requirements that often expect regular testing.
The main frameworks worth knowing:
- ▸Privacy Act 1988 (Australian Privacy Principle 11): organisations covered by the Act must take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access. It doesn't prescribe pentests, but regular independent testing is one way to show your steps were reasonable.
- ▸Notifiable Data Breaches (NDB) scheme: if an eligible data breach is likely to result in serious harm, you must notify affected individuals and the OAIC. Testing is how you find the weaknesses before they become a notifiable breach.
- ▸APRA CPS 234: APRA-regulated entities must test the effectiveness of their information security controls through a systematic testing program, with frequency commensurate with the rate at which vulnerabilities and threats change. If you are a supplier to a bank, insurer or super fund, expect this to flow down into your contracts.
- ▸Essential Eight: the ASD maturity model does not require penetration testing, but it does require frequent vulnerability scanning. At Maturity Level One, a vulnerability scanner must be used at least daily to identify missing patches or updates in online services, supported by automated asset discovery at least fortnightly.
In practice, the frequency pressure usually comes from commercial sources: cyber insurance questionnaires, tender and supplier security questionnaires, enterprise customers asking "when was your last pentest?", and boards wanting assurance. If a client contract says annual, annual is your minimum.
How often should different types of systems be tested?
Test your most exposed and most frequently changed systems most often. Not everything needs the same cadence, and splitting scope is often how SMBs keep testing affordable.
Internet-facing infrastructure (external network)
Your firewall, VPN, email gateway and public IP ranges are what attackers see first. Scan them continuously or at least weekly, and include them in an annual human-led external pentest. Retest after any change to perimeter devices or remote-access configuration.
Web applications and APIs
If you release often, your app changes faster than anything else you own. A good pattern is automated assessment on a regular cadence (for example, monthly or before major releases) plus a human-led web application pentest at least annually and before launching significant new features. Authentication, authorisation and payment changes deserve a test before go-live, not after.
Internal network and Active Directory
Internal testing shows what an attacker could do after phishing a staff member or compromising a laptop. For most SMBs, annual internal testing is appropriate, with an extra test after network restructures, identity-provider changes or a new MSP taking over administration.
Cloud environments
Cloud misconfigurations appear quickly because anyone with the right permissions can create resources. Pair configuration reviews with an annual human-led cloud assessment, and test again after migrations or major account restructures.
Is an annual penetration test enough?
An annual pentest is enough for some low-change SMBs, but not on its own. It needs to sit alongside frequent vulnerability scanning, prompt patching and retesting of critical fixes.
A pattern we see repeatedly: a business gets a solid annual pentest, fixes the criticals, then changes little about how it manages security for the next year. By the time the next test arrives, new issues have crept in through routine change: an unpatched VPN appliance, a forgotten test subdomain, or an admin account that was never removed when a contractor left.
You are probably under-testing if any of these are true:
- ▸You release code to production weekly or more often, but test once a year
- ▸Your last pentest is older than your current network or cloud architecture
- ▸You have never retested to confirm critical findings were actually fixed
- ▸Your insurer or a major client asks for evidence and your most recent report is more than 12 months old
- ▸You hold health, financial or large volumes of personal information
How do automated assessments and pentests fit together?
Automated assessments give you frequency; human-led penetration tests give you depth. You need both, and you should never treat one as the other.
An automated security assessment runs scanners against your targets to find known vulnerabilities, missing patches and misconfigurations. At Aussie Pentest, every automated report is reviewed by an analyst before it reaches you, but it is still a scan-based assessment, not a penetration test. A human-led pentest goes further: a tester chains findings, bypasses controls and proves impact with evidence.
A practical split for many SMBs:
- ▸Monthly or quarterly: automated security assessment of internet-facing targets (Aussie Pentest options range from $80 to $2,000 AUD depending on targets and depth)
- ▸Annually and after significant change: human-led penetration test (from $5,000 for an external test, with broader scopes from $12,000 to $20,000 AUD)
- ▸After remediation: targeted retest of critical and high findings
If you are unsure which you need right now, our guide to vulnerability assessment vs penetration testing breaks down the differences in more detail.
How often should you test for Essential Eight, insurance and tenders?
Match your testing cycle to the evidence cycle you are judged on. Insurers and clients typically ask at renewal or contract time, so plan testing so your report is recent when the question lands.
- ▸Cyber insurance: book testing a couple of months before renewal so you have time to remediate and, ideally, retest before you answer the questionnaire. Never overstate your controls on the insurance application. See our guide on cyber insurance and penetration testing for what insurers commonly ask.
- ▸Tenders and supplier questionnaires: many ask for a pentest within the last 12 months. Keep an executive summary ready to share under NDA.
- ▸Essential Eight: a maturity assessment is a different activity from a pentest. Many SMBs reassess annually to track progress against their target maturity level, while running the frequent vulnerability scanning the model requires. Aussie Pentest's Essential Eight assessment is $4,950 + GST for environments up to 50 seats.
If keeping all of this on schedule feels like a recurring scramble, that is exactly what a vCISO retainer is for: planning the testing calendar, tracking findings in a risk register and reporting to the board. Aussie Pentest vCISO retainers run from $2,500 to $6,500 per month and are advisory and oversight, not implementation, and not incident response.
What does a practical penetration testing schedule look like for an SMB?
A workable schedule combines continuous scanning, quarterly reviews, an annual human-led test and event-driven retests. Here is a simple calendar you can adapt:
- Every day to every week: vulnerability scanning of internet-facing services, prioritised patching of anything exploitable.
- Every quarter: automated security assessment of external targets and key web apps; review open findings with your MSP or IT team.
- Two to three months before insurance renewal or major tenders: human-led penetration test of your highest-risk scope.
- Within weeks of the pentest: remediate critical and high findings, then retest to confirm the fixes hold.
- Whenever significant change happens: scope a targeted test of the new or changed system before or shortly after go-live.
- Every year: review scope. Add anything new, retire what's gone, and rotate deeper testing through internal, cloud and application areas if budget is tight.
If you are budgeting for the year, our guide to how much a penetration test costs for Australian SMBs explains what drives the price, and our checklist on how to prepare for a penetration test helps you get the most out of each engagement.
Want help turning this into a calendar that fits your budget and renewal dates? Book a 1-on-1 scoping call with Aussie Pentest and we'll map out what to test, when, and at what depth.
Frequently asked questions
How often should a small business get a penetration test?
At least once every 12 months, plus after significant changes such as a new application, cloud migration or network restructure. Low-change businesses with limited sensitive data can often stay annual, provided they run frequent vulnerability scanning in between.
Is a penetration test required every year in Australia?
Not by general law for most private businesses. Annual testing is usually driven by PCI DSS (if you handle card data), APRA CPS 234 flow-down requirements, insurer questionnaires, and client or tender contracts. The Privacy Act requires reasonable steps to protect personal information, and regular testing helps you demonstrate that.
How long is a penetration test report valid for?
A report has no formal expiry date, but most insurers, clients and auditors treat anything older than 12 months as stale. It also becomes outdated as soon as your environment changes significantly, regardless of its age.
Can I replace annual pentests with automated scanning?
No. Automated scanning is valuable for frequency and catching known issues quickly, but it cannot reliably find chained attacks, access-control flaws or business-logic issues. Use automated assessments between human-led pentests, not instead of them.
Should I retest after fixing pentest findings?
Yes, especially for critical and high findings. A retest confirms the fix actually works and gives you cleaner evidence for insurers and clients than a report full of open issues.
The bottom line
Plan for one human-led penetration test a year, test again after significant change, retest your critical fixes, and scan frequently in between. That rhythm keeps your evidence current for insurers and clients, and, more importantly, catches new weaknesses before an attacker does.
This article is general guidance, not a substitute for a scoped assessment of your environment. If you'd like a testing cadence built around your systems, renewal dates and budget, book a 1-on-1 call with Aussie Pentest or explore our penetration testing services.
Sources
- ▸ASD's ACSC: Essential Eight maturity model (cyber.gov.au)
- ▸OAIC: Notifiable Data Breaches scheme and Australian Privacy Principle 11
- ▸APRA: Prudential Standard CPS 234 Information Security
- ▸PCI Security Standards Council: PCI DSS v4.0 document library
- ▸NIST SP 800-115: Technical Guide to Information Security Testing and Assessment
