By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Horizons.aiPublished January 14, 2026

TL;DR: A global payments provider shifted from semi-annual, sample-based pentests to quarterly, full-environment validation after human-led tests missed default credentials, exposed management ports, and exploitable attack paths, according to Horizons.ai. The lesson is that proving risk is closed now matters as much as finding it, because compliance coverage alone leaves blind spots.


At a glance

What this is: This is a practitioner case study arguing that point-in-time pentests are too narrow to prove security across large, distributed environments.

Why it matters: It matters because IAM, PAM, and adjacent security teams need evidence that credentials, defaults, and misconfigurations are actually remediated everywhere, not just in sampled assets.

👉 Read Horizons.ai's analysis of compliance testing and cyber resilience


Context

Compliance-oriented pentesting often samples a small part of the environment, then extrapolates risk from limited evidence. In large payment and banking estates, that approach can miss exposed credentials, default configurations, and unmanaged attack paths that real adversaries use first. The primary issue here is not whether testing exists, but whether it is broad and frequent enough to prove control effectiveness across the full footprint.

For identity practitioners, the interesting part is the access layer hidden inside infrastructure weakness. Weak credentials, default passwords, and exposed management interfaces are identity failures as much as they are hardening failures, because they create unnecessary trust in accounts and systems that should not be reachable. The starting position in this case is unusual in scale, but the governance gap it exposes is common.


Key questions

Q: How should security teams prove that pentest findings are actually closed?

A: Teams should require re-testing of the exact attack path, not just a ticket showing the issue was remediated. Closure should include evidence that the same credential, configuration, or access path can no longer be abused in the live environment. That turns pentesting from a reporting exercise into control verification.

Q: Why do weak credentials and defaults matter so much in large environments?

A: Because they compress attack time and reduce the effort needed to move from initial access to internal compromise. In distributed estates, a single weak credential or exposed management service can become the starting point for chaining access across many systems before the next test cycle.

Q: What do security teams get wrong about audit-friendly pentests?

A: They often confuse passing an audit with proving resilience. A report can satisfy a compliance requirement while still leaving the most exploitable paths untested. The mistake is assuming coverage was complete when it was only representative.

Q: Who is accountable when a tested weakness returns after remediation?

A: Accountability should sit with the control owner for the affected system and with the programme owner responsible for validation cadence. If a weakness reappears, that usually means the underlying configuration or lifecycle process was not fixed, only the symptom was patched.


Technical breakdown

Why sample-based pentesting misses identity and access risk

Traditional pentesting is often scoped to a small subset of assets, so it can miss the combinations that matter most: a weak credential on one host, a default password on another, and a management interface exposed somewhere else. In practice, attackers chain these weaknesses across environments faster than quarterly or semi-annual testing can observe them. The problem is not just test frequency. It is the assumption that a sample represents the whole estate. That assumption breaks down in distributed, heterogeneous infrastructures where identity exposure is uneven.

Practical implication: expand testing scope until it can validate the full attack surface, not just representative samples.

How exploitation evidence changes remediation priority

A report that lists vulnerabilities is easier to ignore than a demonstrated attack path. When a test shows how a weak credential leads to access, then to file exposure or lateral movement, remediation becomes a question of business risk rather than theoretical severity. This is especially relevant where credentials and defaults function as implicit trust. Proof of exploitation shortens debate, because the control failure is visible and repeatable.

Practical implication: use exploitation evidence to drive remediation ownership and eliminate arguments over whether a weakness is actually exploitable.

Continuous validation versus point-in-time assurance

Point-in-time pentesting produces a snapshot. Continuous or quarterly validation produces a trend line. That distinction matters because large environments change constantly through new assets, configuration drift, and privilege accumulation. In security governance terms, the control objective is not to produce a report, but to maintain confidence that exposed paths remain closed after changes, patches, and reconfigurations. That is closer to resilience than compliance alone.

Practical implication: align testing cadence to change rate so assurance keeps pace with environment drift.


Threat narrative

Attacker objective: The attacker aims to turn basic configuration and credential weaknesses into broad internal access and large-scale data exposure.

  1. Entry begins with weak credentials, default passwords, or exposed management services that create an initial path into infrastructure.
  2. Escalation follows when attackers chain those gaps across systems and reach sensitive internal assets or management functions.
  3. Impact occurs when the attacker can access large volumes of files or move through the environment in ways a sample-based pentest did not reveal.

NHI Mgmt Group analysis

Compliance evidence is not the same as resilience evidence. A pentest that satisfies an auditor can still miss the combinations attackers actually use, especially where credentials, defaults, and management exposure sit outside the tested sample. That creates a governance gap between what is signed off and what is truly closed. For practitioners, the lesson is to treat proof of exploitability as the real control objective, not the report itself.

Weak credentials and defaults are identity failures inside infrastructure problems. This article is about cyber resilience, but the identity angle is explicit: a password, token, or management account that should never have been exposed becomes the first trust boundary failure. When access paths are validated only intermittently, standing access assumptions persist longer than they should. For IAM and PAM teams, this is a reminder that credential governance must be tied to environmental validation, not just lifecycle policy.

Continuous attack-path validation is a named control gap, not just a tooling preference. The specific failure mode here is sampling blindness: assuming a small test set can represent a much larger, dynamic environment. That assumption works poorly when configuration drift and privilege sprawl are constant. The practical conclusion is that governance needs evidence across the whole estate, because partial validation can leave the most exploitable paths untouched.

Audit acceptance should follow demonstrated closure, not annual rituals. The article shows that banking and PCI stakeholders accepted quarterly, full-environment testing once remediation and methodology were evidenced consistently. That signals a broader market shift toward proof-based assurance. For security leaders, the implication is that compliance programmes are moving toward continuous validation models that can stand up to both auditors and attackers.

What this signals

Sampling blindness: security programmes that validate only a subset of assets will continue to underestimate exposure, especially in estates where credentials, defaults, and configuration drift change faster than formal review cycles. The operating signal to watch is whether your testing cadence matches your change cadence, not whether a report was filed.

For identity and PAM teams, the more important shift is that exploitability evidence will increasingly be expected alongside policy compliance. Where access is granted broadly, tested narrowly, and revoked slowly, assurance remains fragile. Pairing validation discipline with controls such as least privilege and lifecycle governance will matter more than another annual point-in-time review.

The practical planning question is whether your programme can prove closure across the whole environment after remediation. If it cannot, the organisation is relying on assumptions about access and control effectiveness. That is where resilience claims tend to fail first.


For practitioners

  • Replace sample-based pentest scope with full-asset validation Test every IP, every quarter, or at a cadence that reflects your environment change rate. The aim is to eliminate blind spots created by representative sampling and to prove that exposed paths are closed across the whole estate.
  • Prioritise exposed credentials and default access paths first Use attack-path evidence to rank findings that involve weak passwords, default credentials, and unmanaged management interfaces ahead of abstract vulnerability counts. These conditions are often the fastest route to internal compromise.
  • Require remediation proof before closing findings Do not rely on static tickets or declaration-only closure. Re-test the specific attack path, verify the fix in the same environment, and retain evidence that the issue is no longer exploitable.
  • Align audit reporting with exploitability evidence Package reports so auditors and internal stakeholders can see how access was achieved, what control failed, and what changed after remediation. This makes compliance evidence more defensible and less dependent on narrative alone.

Key takeaways

  • This case shows that audit coverage can still leave exploitable paths untouched when testing is too narrow or too infrequent.
  • The evidence points to credentials, defaults, and exposed interfaces as the fastest route from weakness to broad internal impact.
  • The control that changes outcomes is full-environment validation with proof that the same attack path no longer works.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM-1Continuous validation maps to ongoing monitoring of security controls and attack surface.
NIST SP 800-53 Rev 5CA-8CA-8 directly supports security assessment and continuous validation of control effectiveness.
CIS Controls v8CIS-4 , Secure Configuration of Enterprise Assets and SoftwareDefault credentials and exposed management services are configuration failures covered by CIS hardening.
MITRE ATT&CKTA0006 , Credential Access; TA0004 , Privilege EscalationThe article centers on weak credentials and chained access paths leading to deeper compromise.
ISO/IEC 27001:2022A.8.8Technical vulnerability management applies where validation and remediation cycles need stronger assurance.

Map findings to credential access and privilege escalation tactics to prioritise the attack paths that matter most.


Key terms

  • Continuous validation: Continuous validation is the practice of re-checking user, device, or session risk after login instead of trusting access indefinitely. It recognizes that identity assurance can drift during a session, especially when endpoint state or user context changes after authentication.
  • Sampling blindness: Sampling blindness is the governance failure that occurs when a small set of tested assets is assumed to represent a much larger environment. In complex estates, that assumption hides exposure created by drift, defaults, and uneven access controls.
  • Exploitability context: Exploitability context is the evidence used to decide whether a vulnerability matters in a specific environment. It includes reachability, code path exposure, compensating controls, and product-specific advisories, and it turns raw scan data into a decision that can be defended.
  • Attack-path validation: Attack-path validation is the practice of proving whether an attacker can move from one weakness to another until they reach meaningful impact. It goes beyond scanning by testing how exposures connect across identity, network, cloud, and application layers under realistic adversarial conditions.

What's in the full article

Horizons.ai's full blog covers the operational detail this post intentionally leaves for the source:

  • The exact NodeZero run structure used to move from sample testing to quarterly full-environment validation.
  • The exploitation evidence shown to IT and product teams to accelerate remediation decisions.
  • The specific changes to audit reporting that helped banking partners accept the new testing cadence.
  • The operational use of Tripwires and 1-Click Verify to replace older deception and verification tooling.

👉 The full Horizons.ai post covers the testing workflow, remediation proof, and audit acceptance details.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, secrets management, and identity lifecycle thinking. It helps practitioners connect access control, validation, and governance across identity-led security programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org