Spreading Testing Cost Across a Financial Year

2 min read

Spreading Testing Cost Across a Financial Year

A single annual test arrives as one invoice in one quarter, which is why security testing is often the first line cut when budgets tighten. Spreading the same spend across the year gives you better coverage, easier approval and a report that is never twelve months old. The government’s Cyber Security Breaches Survey has consistently found that smaller organisations spend little on security, and predictable phasing is one of the few things that changes that.

Deciding what goes first

Sequence by exposure. External infrastructure comes first because it is reachable by anyone and usually the cheapest engagement to run. The application holding customer data comes next, since that is where a breach becomes a notification. Internal testing follows, because it answers what a phishing click leads to. Cloud configuration review fits alongside whichever of these your estate depends on most. That order works for most organisations and it changes if a contract or an auditor has already told you what they want to see.

See also: Practical Financial Wellness Tips for Everyday Life

Phasing across quarters

A workable pattern for a mid-sized firm is external testing in the first quarter, the main application in the second, internal and cloud in the third, and retesting plus any new systems in the fourth. Each engagement is a few days rather than a fortnight, which is easier to approve and easier to absorb operationally. It also produces a report every quarter, so evidence for customers and insurers is always current rather than being renewed once a year and then aging visibly.

“Buying days in advance is the practical way to make this work. Agree a block of consultant days for the year at an agreed rate and draw against them as you need them. It removes the procurement cycle from every individual engagement, which is usually a bigger obstacle than the money.”

William Fieldhouse, Director, Aardwolf Security Ltd

Building a three-year view

A single year of testing looks like a cost, and a three-year plan looks like a programme. Set out which systems are tested in which year, where retesting fits, and how the scope grows as the business grows. Include the certification cycle in the same plan, since the evidence overlaps. Boards approve programmes more readily than they approve individual invoices, particularly when the plan shows findings reducing over time, which is the number worth reporting rather than the count of tests performed each year.

Getting the commercial arrangement right

Discuss the shape as well as the price. Ask whether the supplier offers a pre-purchased day arrangement, whether unused days roll forward, and whether retesting is drawn from the same pool. Confirm how long quoted rates hold, since a programme spanning a financial year needs price certainty. When you get a quote for your testing programme, ask for it as an annual plan rather than a series of separate proposals, and check that the right testing partner can commit the same consultants across the year, because continuity is where the value compounds.

Frequently asked questions about testing budgets

These questions come up when a security budget is prepared for the first time.

How much should a mid-sized firm budget?

Enough for external testing, one significant application and a retest is a sensible floor, which for most organisations means ten to fifteen consultant days a year. Scale from there based on how many systems hold data you would have to report on.

Is a retainer better than buying per engagement?

It helps when you test several times a year, because it removes repeated procurement and secures resource. For a single annual test it adds little, so compare the total rather than the arrangement.

How To Build…

John A
4 min read

What Should a…

John A
4 min read

Visualizing Business Insights…

John A
4 min read

Leave a Reply

Your email address will not be published. Required fields are marked *