How often should you conduct penetration testing?
In a rapidly shifting attack landscape against the backdrop of a hackers' black market worth billions, if you wait to pentest -- you lose.
Still, unless required by law, too many companies and organizations only do a penetration test when they have to.
Often, it's because they need to comply with regulations or they've been told they need to prove they're secure, in which case it's a checklist security audit by the numbers. Most unfortunately, too many only do a penetration test after they've been scorched: When hackers have successfully gotten in, executed a payload, and made off with valuable IP, records, customer PII, and cost the company more than it probably knows or can calculate.