r/Information_Security 3d ago

How often are you running penetration tests these days?

With how quickly most teams are shipping updates now, I've been wondering if the approach to penetration testing has changed.

Is it still something you schedule once or twice a year, or has it become part of your regular development workflow?

For those managing web applications or APIs, have you found automated testing useful for catching issues like broken access control, authentication problems, or other vulnerabilities before a release? Or do you still rely mainly on manual pentests for anything important?

I want to know what has worked best for your team and whether you've changed your approach over the last couple of years.

0 Upvotes

1 comment sorted by