How risk-based testing is transforming security in regulated organisations
For many organisations, cyber assurance penetration testing still follows a familiar pattern. A system is due its annual test, so someone raises a request. The scope is drafted, reviewed and approved, a purchase order is raised, and the test is scheduled, delivered and reported, with any findings retested. A year later, the cycle begins again, for the majority of systems.
Each step makes sense on its own. Taken together, they create a process that is slow, resource-intensive and, most importantly, disconnected from risk. Testing happens when procurement allows, not when assurance would add most value, and the depth of testing a system receives often bears little relation to how critical that system is to the organisation.
At Resillion, we have been working with a public sector organisation to change that. We have a proven track record of combining expertise from across our business, and a long heritage of innovation and continuous improvement, and this work drew on both. The results show what is possible when assurance is designed around risk rather than around the procurement calendar.
Assurance that is hard to defend
One of our customers operates in one of the UK’s most tightly regulated environments. Its cyber security arrangements are assessed by the industry regulator against its Security Assessment Principles, which expect organisations to show that their assurance activity is effective and proportionate to risk.
The existing testing model made that harder than it should have been. Most systems required annual testing, and each test moved through eight separate review and approval steps. The customer’s staff spent significant time managing engagements rather than managing risk. There was also no documented link between a system’s criticality and the depth of testing it received, so proportionality relied on explanation rather than evidence.
This is not an organisation-specific problem. Central government departments working under GovAssure, critical national infrastructure operators under the NIS Regulations, and organisations preparing for the UK Cyber Security and Resilience Bill all face the same question: can you show that your assurance effort matches your risk?
Let risk drive the scope
Together with our customer, we designed a risk-based, continuous assurance model. At its centre is a scoping tool that assesses each system’s criticality and risk, and uses that assessment to determine the scope, depth and frequency of testing.
What made this possible was combining three areas of Resillion expertise that are rarely brought together. Our Cyber Assurance Testing team brought deep knowledge of how attackers target critical systems and how testing should be scoped and delivered. Our Quality Engineering team brought its experience of continuous testing in software delivery, where testing is built into every change rather than scheduled at the end. And our Governance, Risk and Compliance (GRC) specialists brought the risk assessment and regulatory insight needed to make every decision defensible to auditors and regulators.
We built the assessment criteria in joint workshops, bringing together the customer’s stakeholders with all three teams. The criteria were aligned with regulatory principles and the customer’s own risk appetite, so that every scoping decision traces back to an agreed, transparent basis. Before relying on the tool, we ran tests against a range of previously tested systems to confirm that its outputs were accurate and accepted by the customer.
We then delivered the change as a structured programme of nine workstreams across four stages. We began by understanding the current state: rationalising the asset inventory and analysing years of historic findings against asset criticality to reveal where risk was really concentrated. Next, we designed a library of pre-approved scopes, so that tests could be mobilised quickly without repeating the same approvals each time. We then embedded the model in day-to-day operations, integrating testing with the DevSecOps lifecycle so that significant change triggers assurance automatically, and supporting remediation through to verified closure. Finally, we put metrics and governance in place to sustain the change, with change management running throughout, so that the new model became how the organisation works.
Efficiency without compromising independence
A common concern with streamlining assurance is that efficiency might come at the expense of objectivity. We designed the model to strengthen independence, not weaken it. Scope is set by the agreed risk criteria rather than by the testers, so no one has a stake in the outcome. Findings are reported unfiltered against a standard severity methodology. Where we support remediation, verification retests are carried out by a different consultant, so we never sign off our own advice.
The results
The outcomes have been significant. Our customer now spends more than 60% less staff time on testing engagements. Review and approval steps have been cut from eight to two per engagement, with governance fully intact, and the average time from request to the start of a test reduced from six weeks to two.
Just as importantly, testing is now prioritised by criticality and timed to when it adds most value, including after significant change rather than only on an annual cycle. And there is a traceable chain from risk assessment to scope, findings and verified remediation, giving the customer clear evidence of effective assurance processes for the regulator.
Reduction in testing time
Approval steps cut from 8 to 2 per engagement
av. time from request to start of a test reduced to 2 weeks
Why this matters for the public sector
For public sector and regulated organisations, the benefits go beyond efficiency.
The first is that audit and assurance become far easier to evidence. When every test can be traced back to a documented risk assessment, demonstrating proportionality to auditors and regulators becomes a matter of showing the record, not reconstructing the reasoning.
The second is that critical systems get the attention they deserve. Risk-based scoping directs testing effort to the systems that matter most, rather than spreading it evenly across the estate.
The third is that scarce internal resources are freed up. Security and procurement teams in the public sector are often stretched, and reducing the engagement process from eight approval steps to two returns time to the people who need it most, without removing the controls that matter.
Finally, assurance keeps pace with change. Linking testing to the development lifecycle means that new risks are assessed when they are introduced, not months later at the next scheduled test.
Getting started
Organisations considering a similar journey can begin by asking themselves a few simple questions. Do they have an agreed, documented way of assessing the criticality of each system, and can they trace each test’s scope back to that assessment? How many approval steps does a routine test go through, and which of those steps genuinely manage risk? And when significant change happens, does it trigger assurance, or does it wait for the next annual cycle? If the answers are uncertain, there is value, and time, to be recovered.
We have since applied this approach with other Resillion customers, with similar efficiency gains. Effective assurance depends as much on agreed criteria, governance and evidence trails as on technical testing. When those are in place, organisations can test smarter, spend less time managing engagements, and give their boards and regulators the confidence they need.
To find out how a risk-based, continuous assurance model could work for your organisation, contact the Resillion Cyber Assurance team.