TL;DR: Traditional pentesting struggles to keep pace with asset churn, configuration changes, and the need to prioritise high-impact findings, positioning agentic testing as a way to monitor assets, understand context, and reduce false positives, according to Hadrian. The shift matters because security teams need continuous exposure insight, not occasional point-in-time validation.
At a glance
What this is: This is a short analysis of why traditional pentesting reaches operational limits as environments change faster than manual testing cycles can follow.
Why it matters: It matters because IAM, PAM, and broader security teams must decide where human testing ends and continuous, machine-assisted validation begins across identities, exposure, and remediation workflows.
👉 Read Hadrian's analysis of the operational limits of traditional pentesting
Context
Traditional penetration testing is still useful, but it is fundamentally a point-in-time control in a continuously changing environment. As assets, configurations, and exposed services change, the value of one-off validation falls unless it is paired with ongoing exposure monitoring and faster remediation workflows. For identity and access teams, the same problem appears wherever credentials, permissions, and external attack surfaces change faster than review cycles.
The operational question is not whether testing should exist, but whether it can keep up with modern cloud and identity-driven attack paths. That includes service accounts, API tokens, and external exposure points that can create a path into critical systems before a manual assessment is complete. Hadrian’s article frames that gap from an offensive security angle, but the governance issue is broader: validation now has to be continuous enough to reflect real risk.
Where agentic testing intersects with identity security, the core issue is coverage of access paths, not just vulnerability counts. That makes the topic relevant to IAM and PAM teams that rely on periodic assurance to confirm privilege boundaries, especially in environments with frequent change. The starting point here is typical for mature security programmes, but the pressure to move beyond manual testing is intensifying.
Key questions
Q: How should security teams use agentic testing without over-relying on automation?
A: Security teams should use agentic testing to expand coverage, speed up discovery, and reduce repetitive triage, but keep humans responsible for interpreting business impact and validating the most sensitive paths. The right model is machine-assisted assurance, where automation improves cadence and consistency while expert judgement handles chaining, edge cases, and remediation decisions.
Q: Why do point-in-time pentests miss important risks in fast-changing environments?
A: Because the environment often changes faster than the test cycle. New assets, configuration drift, and exposure changes can appear after the test window closes, which means the result no longer reflects current risk. Continuous validation closes that gap by checking whether the attack surface still matches the last assessed state.
Q: What do teams get wrong about pentest output and vulnerability counts?
A: They often treat the number of findings as the measure of security value. In practice, a smaller number of well-contextualised findings is more useful than a long list of issues with no asset ownership, exposure context, or privilege path analysis. Risk is determined by reachability and impact, not by volume alone.
Q: When should organisations prioritise continuous compliance over manual review cycles?
A: They should prioritise continuous compliance once application portfolios, release frequency, or AI-assisted development make manual review too slow to cover the work. If a security team cannot keep pace with delivery, the organisation is already operating with an assurance gap. Continuous controls are then a governance requirement, not a maturity upgrade.
Technical breakdown
Why point-in-time pentesting misses exposure drift
Traditional pentesting produces a snapshot of exposure at a specific moment. That approach works when environments are stable, but cloud assets, configurations, and externally reachable services often change daily. The result is exposure drift, where yesterday’s validated state no longer matches today’s attack surface. In practice, this creates blind spots between assessments, especially when remediation queues are long or asset inventories are incomplete. Offensive testing still matters, but its value drops when the environment mutates faster than the test cadence. Continuous validation is therefore less about replacing human testers and more about closing the gap between discovery and verification.
Practical implication: pair manual pentests with continuous asset and exposure monitoring so validation does not go stale between testing cycles.
How agentic testing changes the operating model
Agentic testing uses software agents to perform repeated, context-aware checks that mimic parts of a tester’s workflow. The point is not full automation of every exploit chain, but faster iteration across discovery, prioritisation, and verification. This matters because many environments do not fail at the vulnerability detection stage. They fail at context, where teams cannot quickly tell which issues are real, reachable, and materially exploitable. An agentic model can reduce the time spent on repetitive enumeration and triage, allowing human testers to focus on the highest-value paths and edge cases that require judgment.
Practical implication: use agentic systems to accelerate discovery and triage, but keep humans responsible for validation of high-impact attack paths.
Why asset context matters more than raw findings
A large finding set is not the same as a risk picture. Asset context tells security teams whether a service is internet-facing, business-critical, identity-linked, or part of a privileged path into another system. Without that context, false positives and low-value findings bury the issues that actually matter. This is where exposure management and identity governance overlap: access paths, privileged dependencies, and externally reachable control planes determine whether a technical issue becomes an incident. Context is therefore the control that turns testing into prioritisation.
Practical implication: enrich findings with asset ownership, exposure, and privilege context before routing them into remediation workflows.
NHI Mgmt Group analysis
Agentic pentesting is a response to exposure velocity, not a replacement for assurance. Manual testing still has value, but the tempo of modern infrastructure change means point-in-time assessments can age almost immediately. The operational problem is not finding fewer vulnerabilities, but preserving meaningful validation across a moving attack surface. Practitioners should treat agentic testing as a coverage multiplier, not a strategy substitute.
Exposure context is the real differentiator: the important question is whether a finding is reachable, privileged, and connected to a path that matters. That makes the discipline adjacent to IAM and PAM, because access paths and identity-linked dependencies often determine exploitability more than the flaw itself. Security teams should prioritise context-rich validation over raw scan volume.
False positive reduction is a governance issue, not just a tooling feature. When teams spend too much time triaging low-value findings, they delay work on exposures that affect real business services. That creates a remediation economy problem in which effort is misallocated, and attackers benefit from the delay. Practitioners should align testing output to risk ownership and remediation SLAs.
Continuous testing changes the question from what is vulnerable to what is exploitable now. That shift is especially relevant in environments with frequent configuration change, ephemeral workloads, and identity-heavy service architectures. It aligns better with zero trust thinking because trust is assumed transient, not static. Practitioners should use this model to tighten the feedback loop between exposure discovery and control enforcement.
Agentic testing will push security programmes toward machine-assisted assurance, but humans still own judgement. The strategic value lies in scaling repetitive validation while preserving expert oversight for complex chains and high-impact paths. That balance is what will separate mature programmes from those that simply increase output volume. Practitioners should define where automation ends and human sign-off begins.
What this signals
Exposure velocity is now a programme design issue. When assets, permissions, and interfaces change continuously, assurance has to move from periodic validation to recurring verification. Teams that still depend on annual or quarterly confidence checks will find that the control result lags the environment it is supposed to describe.
Identity-linked exposure is where testing and governance meet. External attack surface work increasingly overlaps with service accounts, automation credentials, and privileged interfaces. That means exposure management needs to inform IAM and PAM decisions, not sit beside them as a separate function.
Context-rich findings will matter more than raw scan volume. Security programmes should expect machine-assisted validation to increase output, but the real value comes from asset criticality, ownership, and exploit path context. Teams that can route findings by business impact will remediate faster and with less noise.
For practitioners
- Implement continuous exposure validation Run repeated checks on internet-facing assets, configuration changes, and privilege-bearing services between manual tests so exposure does not drift unnoticed. Use this to complement, not replace, scheduled pentests.
- Triage findings by exploitability context Score findings using reachability, business criticality, and identity-linked privilege paths before sending them to remediation teams. This reduces time spent on issues that are technically real but operationally low priority.
- Separate automation from final judgement Use agentic testing for discovery, enumeration, and repetitive verification, but require human review for chaining, business impact assessment, and decisions that change access or production posture.
- Map privileged access dependencies Identify which externally exposed services, admin interfaces, and automation accounts can lead to lateral movement or privilege escalation. Prioritise testing where identity pathways can convert exposure into compromise.
Key takeaways
- Traditional pentesting still matters, but it cannot on its own keep pace with environments that change faster than assessment cycles.
- The value of agentic testing is in continuous context, faster triage, and better prioritisation, not in replacing human judgement.
- IAM and PAM teams should care because exploitability often depends on identity-linked paths, not just the underlying technical flaw.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM-7 | Continuous monitoring is central to keeping pentest validation current as exposure changes. |
| NIST SP 800-53 Rev 5 | CA-7 | Security assessments need continuous improvement and feedback loops when environments change fast. |
| CIS Controls v8 | CIS-13 , Network Monitoring and Defense | Exposure monitoring and validation depend on observing changing attack surfaces. |
| MITRE ATT&CK | TA0007 , Discovery; TA0043 , Reconnaissance | Pentesting and agentic exposure testing both map to discovery of reachable attack paths. |
Map validation findings to discovery tactics so prioritisation reflects real attacker pathways.
Key terms
- Exposure Drift: Exposure drift is the gap between the state a security team last validated and the state the environment has reached since then. In fast-changing cloud and identity-heavy environments, that gap can be large enough to make a previous pentest result unreliable for operational decisions.
- Agentic Testing: Security testing in which software agents can choose actions, sequence steps, and adapt during a validation workflow. In practice, it combines automation with governance, because the agent is not just running a script. It is operating with enough decision-making to require scope limits, auditability, and oversight.
- Exploitability context: Exploitability context is the evidence used to decide whether a vulnerability matters in a specific environment. It includes reachability, code path exposure, compensating controls, and product-specific advisories, and it turns raw scan data into a decision that can be defended.
What's in the full article
Hadrian's full blog covers the operational detail this post intentionally leaves for the source:
- How the agentic testing workflow handles asset discovery, context enrichment, and repeated validation in practice.
- What kinds of risks the platform prioritises first when exposed services, configurations, or attack paths change.
- How the output is structured for remediation teams that need faster action, not just more findings.
- Where human oversight remains necessary when testing moves from manual assessment to agentic execution.
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It gives security practitioners a shared language for controlling access paths across modern identity programmes.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org