Penetration test & external assurance
Independent human validation on top of the automated security gates — because automation and self-assessment have blind spots that an external tester doesn't.
The cadence
- Before first production release of any client-facing product — an external pen test.
- Annual retest thereafter.
- After major architectural change — targeted testing of the changed surface.
Why external, on top of the gates
The security gates catch known classes continuously; a skilled external tester finds the novel and the chained. For insurance clients, an independent assurance report is also a commercial asset — it's what a vendor-risk team wants to see, and it slots into the release evidence pack.
Deliberately P2 in the backlog — it doesn't slow the first builds — but scheduled, so assurance is proven, not assumed.
Standards referenced: CREST, OWASP WSTG.