Cover the estate deliberately
Infrastructure, applications, cloud, identity and APIs are scheduled across the year, so coverage follows a plan rather than whichever request happened to be raised
Services
A twelve-month security testing program, built around your estate, your priorities and your budget. The example below rotates penetration testing across the year, with adversary simulation and purple team as a second stream.
Discuss an engagementEvery program is different. What follows is an example of how one can be structured, not a package to buy. The activities, the rotation, the depth of each assessment and the balance between the two streams are all agreed with you, against your environment, your priorities and your budget.
An annual program replaces a series of disconnected engagements with a single twelve-month plan. Testing rotates across infrastructure, applications, cloud and identity through the year, so coverage is deliberate rather than incidental, and each quarter builds on what the last one found.
The program is structured as two streams. The testing stream is a complete program in its own right and produces the evidence base for remediation, audit and board reporting. The adversary stream is optional, and tests whether the weaknesses found in the testing stream can actually be exploited, and whether your security operations would see it happen.
The program year runs from whenever it starts, not from a fixed calendar date. Four quarters, one planning session each, and a year-end view that shows what changed rather than four independent snapshots.
One year establishes a baseline. Security maturity is built over several. We recommend running the program across multiple years, because the work compounds: scoping gets sharper, the same consultants keep the knowledge of your environment, and the results become a trend you can act on rather than a result you file.
To sketch a year of testing before the first conversation, use the continuous testing program planner.
Infrastructure, applications, cloud, identity and APIs are scheduled across the year, so coverage follows a plan rather than whichever request happened to be raised
One planning session a quarter replaces individual scoping requests, approvals and procurement workflows for every engagement
Retesting is built into each quarter, so a remediated finding becomes evidence that the security program is working rather than a line in an old report
Four quarters of results in one place give trend data for board reporting, audit evidence and year-on-year comparison within the tested scope
An annual program suits organisations with a broad enough estate, or a fast enough rate of change, that a single yearly engagement cannot cover it meaningfully. Where the need is a defined application or a one-off technical question, a targeted assessment is the better answer and remains available on its own.
An annual program fits when
An example of what each stream can cover. The testing stream stands on its own; the adversary stream builds on what it finds, and can be added at any quarterly planning session. Which of these activities apply, and how deep each one goes, is agreed during scoping.
An example year, not a fixed schedule. The sequencing below is not arbitrary: testing stream findings inform the adversary campaigns that follow, and those campaigns validate whether the remediation held. Purple team sessions close the loop by building detection for the techniques both streams surfaced. A program with different priorities rotates differently and may not need every activity shown here, and the exact schedule for each quarter is confirmed at its planning session.
The mechanics that keep a twelve-month engagement moving without a scoping conversation every time something changes.
Every quarter produces a plan, reports and verified retests, with the Client Portal holding the record across the whole year:
Agreed scope, allocation and testing windows for the quarter ahead
Per activity, for technical and executive audiences
Evidence that findings were remediated, each quarter
Posture across all activity, remediation progress and every report in one place
Real-time collaboration between operators and your security team during purple team
Every technique tested, its detection result and remediation status
Technical and executive, following each adversary campaign
Four quarters of results as trend data for board and audit use
A single year tells you where you stand. It cannot tell you whether you are improving, and improvement is the thing a board, an auditor or a regulator actually asks about. We recommend committing to more than one year, and we structure the program so that each one is worth more than the last.
Further still
Once the program has years of data behind it, the quarterly campaigns become the limit. CAOS replaces the quarterly campaigns with persistent operations by a dedicated team, while the testing and purple team streams continue as they are.
Explore CAOSA program is supported by a named customer success contact responsible for scheduling, communication and escalation, so testing windows are met without the coordination falling to your security team. Consultants are allocated per activity by specialisation, and high retention means the people who learned your environment in the first quarter are still the ones testing it in the fourth, and the year after.
SilentGrid holds CREST ANZ accreditation and tests to OWASP for web and API, PTES for infrastructure, CIS Benchmarks for cloud configuration and MITRE ATT&CK for technique mapping. Automated tooling is used for reconnaissance and coverage validation only. Exploitation, business logic testing and adversary simulation are manual, operator-led work.
CREST ANZApproved company Individual credentials across our team include
No. The streams and the rotation on this page are an example of how a program can be structured, drawn from a real one. Every program is built around the organisation it is for: which activities are included, how deep each one goes, how the year is sequenced and how much of it runs are all agreed during scoping, against your environment, your priorities and your budget. A smaller estate or a tighter budget produces a smaller program, not a worse one.
We recommend it. A single year establishes a baseline; it cannot show whether security is improving, which is what a board or a regulator asks about. From year two the scoping is far more precise because the environment is known, effort shifts from discovery to depth, regression testing confirms that earlier detections still fire, and the results read as a trend. Programs are agreed a year at a time, so the commitment is renewed on evidence rather than locked in up front.
Yes. The testing stream is designed as a complete, standalone program and delivers a full year of structured penetration testing without the adversary stream. The adversary stream can be added at program start or at any quarterly planning session, and its rotation adjusts to begin from whichever quarter it joins.
Scope assumptions are reviewed and confirmed before the program is signed, then validated in detail during the first quarter. If the environment materially exceeds the assumptions, adjusted options are presented within the agreed allocation before work proceeds, and a scope amendment is proposed where the variance is significant.
Reserved capacity exists for exactly that: an unplanned release that needs validating, a newly published critical vulnerability affecting your infrastructure, or a deeper dive into something testing surfaced. Requests go through your customer success contact rather than a new procurement cycle.
No. The program runs for twelve months from whenever it starts, divided into four quarters of its own. If the start date happens to align with your financial year, reporting maps naturally to your budgeting and board cycles. If it does not, year-end reporting can be adjusted to coincide with the financial year close.
Either two longer sessions a year or four shorter ones. Fewer, longer sessions suit teams that need time between them to implement findings. A quarterly cadence suits teams with dedicated detection engineering capability who can action gaps quickly. The cadence can be changed at any quarterly review, and the total annual allocation stays the same either way.
The exercise still runs and the findings are still delivered, but detection validation is limited to what can be assessed without active participation. Purple team is collaborative by design, and the value comes from your team observing technique execution as it happens.
Individual assessments each carry their own scoping, approval and scheduling overhead, and produce results that are hard to compare. A program plans coverage across the year, builds retesting in, and produces four quarters of comparable data. It also means the same consultants keep learning your environment rather than starting from scratch each time.
CAOS replaces the quarterly adversary campaigns with persistent, continuous operations by a dedicated team. It can complement a program by taking over the adversary stream while the testing and purple team streams continue, or run as a standalone service. A year of program data is a natural foundation for it.
Planning next year's testing?
Tell us what the estate looks like, what the year has to evidence and what the budget allows, and we will shape a program around it.
Nothing on this page is fixed. Scoping starts from your environment and the priorities behind the year, and the program is built from there: which activities run, how often, and in what order. The first quarter then validates that scope in detail, and each year is agreed on the evidence the last one produced.