المعيار الأساسي: سنوياً على الأقلThe baseline: at least annually

الممارسة المعيارية في القطاعات المنظّمة هي اختبار اختراق شامل مرة سنوياً على الأقل للأصول الحرجة. هذا ليس رقماً اعتباطياً — بل يوازن بين تكلفة الاختبار ومعدل ظهور الثغرات الجديدة والتغييرات المعمارية التي تطرأ خلال العام.The standard practice in regulated sectors is a comprehensive penetration test at least once a year on critical assets. This is not arbitrary — it balances testing cost against the rate of new vulnerabilities and the architectural changes that occur during a year.

الأحداث التي تستوجب اختباراً فورياًEvents that demand immediate testing

لا تنتظر الدورة السنوية إذا حدث أحد التالي: إضافة تطبيق أو خدمة معرّضة للإنترنت، تغيير جوهري في البنية أو الهوية البصرية للنظام، اندماج أو استحواذ، حادث أمني سابق، ترقية كبرى لنظام ERP، أو إطلاق خدمة لعملاء جدد. التغيير الجوهري = اختبار جديد.Do not wait for the annual cycle if any of these occur: a new internet-facing application or service, a material change in architecture or system identity, a merger or acquisition, a prior security incident, a major ERP upgrade, or launching a service to new customers. Material change equals a new test.

المتطلبات التنظيمية في السعوديةRegulatory requirements in Saudi Arabia

ضوابط NCA ECC تشترط اختبارات اختراق دورية موثّقة، والقطاع المالي تحت إشراف البنك المركزي له متطلبات أكثر تحديداً وتكراراً. الجهات الحكومية والبنية التحتية الحرية غالباً ملزمة بوتيرة أعلى. تحقق من متطلبات منظّمك تحديداً — فهي الحد الأدنى لا الاختيار.The NCA ECC requires documented periodic penetration testing, and the financial sector under Central Bank supervision has more specific and frequent requirements. Government entities and critical infrastructure are often bound to a higher frequency. Verify your specific regulator's requirements — they are a floor, not an option.

الفرق حسب حجم المنشأةDifference by company size

منشأة صغيرة بأصول محدودة: اختبار سنوي مركّز على الأصول الحرجة كافٍ غالباً. منشأة متوسطة: اختبار سنوي شامل مع اختبارات موجّهة عند كل إصدار كبير. منشأة كبيرة أو حكومية: برنامج اختبار مستمر بموجات ربع سنوية تغطي نطاقات متغيرة من الأصول.A small organization with limited assets: a focused annual test on critical assets is often sufficient. A mid-sized organization: an annual comprehensive test plus targeted tests at each major release. A large or government entity: a continuous testing programme with quarterly waves covering rotating asset sets.

الاختبار المستمر — الاتجاه الحديثContinuous testing — the modern direction

الاختبار المستمر (Continuous Pentesting) يوزّع الاختبار على مدار العام بدل جرعة واحدة سنوية: اختبار أسبوعي أو شهري لنطاقات محددة بالتناوب. الميزة أن الثغرات تُكتشف وتُعالج خلال أيام لا أشهر — والنتيجة أن «النافذة المفتوحة» للمهاجمين تنكمش بشكل كبير.Continuous pentesting spreads testing across the year instead of one annual dose: weekly or monthly testing of defined scopes on rotation. The advantage is that flaws are found and fixed in days rather than months — dramatically shrinking the window open to attackers.

كيف تبرّر الميزانية للإدارة؟How to justify the budget to management?

لا تُبرّر بالامتثال وحده — بل بالأثر المالي: متوسط تكلفة الاختراق يشمل توقف الأعمال، الاستجابة للحادث، الغرامات التنظيمية، وفقدان الثقة. اختبار واحد بجزء بسيط من هذه التكلفة يقلّل احتمال وقوعها بشكل ملموس. هذه هي اللغة التي تفهمها الإدارة.Do not justify it on compliance alone — justify it on financial impact: the average cost of a breach includes business interruption, incident response, regulatory fines and lost trust. A single test at a fraction of that cost materially reduces the probability of it occurring. That is the language management understands.