Organizations should conduct assessments regularly and whenever significant changes occur. Examples include opening a new location, adopting new cloud platforms, completing an acquisition, changing IT providers, introducing remote work or becoming subject to new compliance requirements. The appropriate frequency depends on the organization’s size, industry, risk profile and regulatory obligations.