I manage a large college network with enterprise level infrastructure. As we all know, the GDPR is sufficiently vague in terms of the guidance on the technical requirements regarding security.With this in mind my question concerns whether it is a requirement to conduct external penetration testing of the network.Below is the guidance taken from the ICO website.The GDPR specifically requires you to have a process for regularly testing, assessing and evaluating the effectiveness of any measures you put in place. What these tests look like, and how regularly you do them, will depend on your own circumstances.Technically, you can undertake this through a number of techniques, such as vulnerability scanning and penetration testing. These are essentially ‘stress tests’ of your network and information systems, which are designed to reveal areas of potential risk and things that you can improve.In some industries, you are required to undertake tests of security measures on a regular basis. The GDPR now makes this an obligation for all organisations.Personally I feel that we should undertake this as belt & braces precaution to err on the side of caution & prove we are taking active measures towards compliance in this area. However, having run this by management along with the costs they have questioned the need for this. I would be really interested in other peoples thoughts on this please?Thanks