A yearly pentest is a photograph, not a guard
Most SMEs buy one Vulnerability Assessment and Penetration Testing exercise a year because that's what the audit checklist asks for. The other 364 days, new systems ship, configurations drift, and the report ages in a drawer. Point-in-time testing was never a security programme.