How frequently do you perform penetration testing of your web applications? Is there a way to automate pen tests as part of the CI/CD process?

IT Analyst in IT Services, 2 - 10 employees
It is recommended to perform penetration testing on web applications at least once a year or after significant changes are made to the application. However, more frequent testing, such as quarterly or monthly, may be necessary for highly critical applications.

As for automating pen tests as part of the CI/CD process, yes, it is possible. This is commonly known as "Continuous Penetration Testing." It involves integrating automated penetration testing tools into the CI/CD pipeline to identify and report vulnerabilities in real-time. This helps to ensure that any new vulnerabilities introduced by code changes are detected and remediated early in the development process. There are many commercial and open-source tools available that can be used to automate pen tests as part of the CI/CD process.
Senior Engineering Manager in Finance (non-banking), 5,001 - 10,000 employees

Thanks for update. Will checkout tools for same.

IT Cyber Security and Compliance in Healthcare and Biotech, 1,001 - 5,000 employees
remediations are manually performed annually

