PTaaS and TG Pen Test

Penetration testing as a service, planned for the whole year

Our PTaaS and continuous penetration testing program replaces the once-a-year test with a schedule you plan with us. Certified ethical hackers test throughout the year, so you see trends, fix issues in smaller batches and always have current results.

  • Continues the TG Pen Test subscription program
  • Menu-based tests on a schedule you control
  • Remediation validation between test windows
Engineer working at a laptop in a workshop

Year-round schedule

Test windows planned in pre-engagement sessions

Human-led testing

Certified ethical hackers, not just automated scans

Reporting your way

Executive summaries, trends and prioritized fixes

Two security specialists in a server room

Formerly TG Pen Test

TG Pen Test is now PTaaS and continuous pen testing

TG Pen Test was Triden’s subscription-based recurring assessment service. Clients chose the assessments they needed and the schedule they wanted, and our testers delivered them across the year. That program continues today as PTaaS and continuous penetration testing, with the same planning model and the same testers.

The idea is simple. An annual penetration test gives you a point-in-time view, usually timed for an audit or a cyber insurance renewal. Your environment keeps changing after the report is delivered. Continuous security testing spreads the work across the year, so new systems get tested soon after they launch and fixes are verified before the next window.

What you can include

Choose tests from the full menu

Build the year from any mix of these assessments. You can swap one assessment for another of similar effort in a given window as priorities change.

How it works

How continuous penetration testing runs

1

Plan the year

In pre-engagement sessions we map out the assessment schedule, collect scope, set priorities, authorize rules of engagement and verify the access testers need.

2

Revalidate before each window

Before every scheduled test we confirm scope, access and contacts are still current, and adjust if your environment has changed.

3

Test and report

Our testers carry out the selected assessments and deliver an executive summary, strategic recommendations and prioritized findings.

4

Validate and adjust

We retest fixed issues against earlier results and reshape upcoming windows around new systems, projects or risks.

PTaaS vs traditional pen testing

How a testing program compares to an annual test

A traditional engagement is one large test, one large report and one large remediation effort, often squeezed into the weeks before an audit. PTaaS breaks that into regular windows. Your team handles a manageable set of findings at a time, and leadership sees whether exposure is going down across the year.

An annual test still makes sense for a stable environment with a single compliance deadline. If you release software often, add locations, move workloads to the cloud or answer frequent customer security questionnaires, a recurring program usually fits better.

With a testing program

What changes for your team

Testing becomes part of how you run security instead of a yearly event.

  • Smaller, steadier remediation workload
  • New systems tested soon after launch
  • Trend data for leadership and auditors
  • Year-round access to our testers for questions

What you get

Deliverables in every PTaaS program

  • Annual testing schedule built with your team
  • Executive summary for each engagement window
  • Strategic recommendations tied to your objectives
  • Prioritized remediation in business context
  • Remediation validation against earlier results
  • Monthly or quarterly reporting on trends
  • Testing aligned to NIST SP 800-115, PTES, OWASP and OSSTMM
  • Year-round access to testers for strategy questions

What clients say

Recurring testing, reported the way you need it

“With Triden Group’s recurring penetration testing, we are able to customize reporting to fit our needs. Triden Group provides the expertise, and we know the expertise will always be there.”

Senior Program Manager, Information Security, global golf manufacturer

FAQ

PTaaS questions

Penetration testing as a service, or PTaaS, is a subscription model for pen testing. Instead of one annual test, you get a planned schedule of assessments across the year, with regular reporting and retesting. Triden’s PTaaS is delivered by certified ethical hackers and continues the TG Pen Test program.

Continuous penetration testing, sometimes called CPT, means testing on a recurring cycle rather than once a year. Windows are scheduled so that changes in your environment are tested soon after they happen, and fixes are verified before the next round.

TG Pen Test continues as our PTaaS and continuous pen testing service. Existing subscribers keep the same planning model and testers. If you have questions about a current schedule, use the client portal or contact your account team.

Price depends on which assessments you include, how often they run and the size of each scope. Because the work is spread across the year, billing is spread out too. We build a proposed schedule with you and price it as a recurring program.

No. Our program is human-led testing by certified ethical hackers. Automated scanning can be part of the menu through vulnerability assessments, but penetration tests are carried out by people who exploit and chain weaknesses the way an attacker would.

Yes. You can swap an assessment for another of similar effort in a given window, and we adjust timing when projects or staffing get in the way. We revalidate scope before every window.

Plan your testing year

Build a year-round penetration testing schedule

Tell us what you need tested and when your audits and renewals fall. We’ll draft a schedule and a recurring price.

  • Pre-engagement planning with our testers
  • Schedule built around your deadlines

Prefer email? Write to [email protected] or call (858) 712-0040.

Send us a message