By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Sprocket SecurityPublished December 12, 2025

TL;DR: Resilient security programs depend on continuous testing, intentional vendor evaluation, and governance that lets teams adopt passwordless authentication and AI safely without sacrificing culture or operational focus, according to Sprocket Security’s interview with MacArthur Foundation engineer Seth Arnoff. The practical lesson is that measurable risk reduction matters more than one-off reports or fear-based leadership messaging.


At a glance

What this is: A Sprocket Security interview explores how a small security team is balancing continuous penetration testing, passwordless authentication, AI guardrails, and vendor risk management.

Why it matters: It matters to IAM and security practitioners because the episode ties identity changes, third-party oversight, and leadership reporting to real operational capacity rather than abstract best practice.

By the numbers:

👉 Read Sprocket Security's interview on continuous testing, passwordless auth, and AI guardrails


Context

Continuous security programmes fail when they depend on annual validation, disconnected reporting, or controls that look strong on paper but do not change day-to-day risk. In identity-heavy environments, that gap shows up in passwordless authentication, third-party access, and secrets governance, where trust and lifecycle control matter as much as tooling.

This episode is best read as an operations and governance discussion, not a product story. The strongest thread is that small teams need repeatable control loops, clear identity boundaries, and measured leadership reporting if they want to modernise access without creating new blind spots.


Key questions

Q: How should security teams use continuous penetration testing alongside vulnerability scanning?

A: Use vulnerability scanning to maintain breadth and coverage, then use continuous penetration testing to validate which findings are actually exploitable. The two controls answer different questions. Scanning supports inventory and compliance reporting, while continuous testing supports risk prioritisation, attack-path validation, and remediation decisions based on evidence rather than severity alone.

Q: When does passwordless authentication create more risk than it reduces?

A: It creates more risk when organisations adopt it without strong device governance, fallback controls, or recovery rules. If an attacker can steal a token, hijack a mobile device, or abuse a weak reset flow, the organisation has simply moved the problem from passwords to another credential path.

Q: What do security teams get wrong about AI access risk?

A: Many teams focus on the model while ignoring the identity path that reaches it. If a service account or token can invoke AI infrastructure, then that credential becomes the real control point. The mistake is treating AI risk as a model problem instead of an access governance problem.

Q: How should organisations assess third-party risk when vendors touch sensitive workflows?

A: Use repeatable criteria for every vendor, especially around access scope, data handling, evidence quality, and offboarding. The point is not to create a larger questionnaire, but to make decisions consistent enough to audit and defend. For sensitive workflows, vendor access should be time-bound, reviewed, and removed as part of the same process.


Technical breakdown

Continuous penetration testing as a control loop

Continuous penetration testing replaces the snapshot model of annual assessments with repeated validation of real attack paths over time. The value is not just more findings, but faster evidence about whether remediation actually reduced exposure. For smaller teams, this also reduces coordination overhead because the test cadence becomes part of the programme rather than a one-off project. In practice, continuous testing only works when it feeds into ownership, remediation tracking, and revalidation, otherwise it becomes a recurring report with no control effect.

Practical implication: tie each finding to a named owner, a remediation deadline, and a re-test trigger so testing changes posture, not just dashboards.

Passwordless authentication and identity trust boundaries

Passwordless authentication shifts the security burden away from memorised secrets and toward device trust, strong identity proofing, and lifecycle governance. Windows Hello can reduce password exposure, but it does not remove the need to manage enrollment, recovery, device compromise, or privileged fallback paths. The governance challenge is that users experience the change as convenience while defenders must treat it as an identity boundary redesign. In mixed environments, the control quality depends on how consistently recovery, conditional access, and exception handling are defined.

Practical implication: treat passwordless rollout as an identity programme change, with recovery, exceptions, and device trust rules documented before broad adoption.

AI guardrails, third-party risk, and data ownership

Allowing AI use safely is less about banning tools and more about defining acceptable data handling, vendor review, and legal accountability. The article shows a pragmatic model: accept usage, then wrap it in guidelines, legal review, and monitoring that informs training without becoming invasive. That aligns with broader governance patterns in which data classification, vendor due diligence, and usage telemetry are used to bound risk. The identity angle appears when AI tools create new access paths to sensitive information and need explicit permission boundaries.

Practical implication: require data-use rules and vendor review before allowing AI tools into workflows that touch sensitive identity or business data.


NHI Mgmt Group analysis

Continuous validation is becoming a governance requirement, not a maturity luxury. Annual testing and static assurance artefacts cannot keep pace with modern exposure, especially where access paths, credentials, and external dependencies change constantly. Continuous penetration testing only has value when it is tied to remediation proof, not just discovery volume. Practitioners should treat validation cadence as part of control design, not a separate assurance exercise.

Passwordless authentication changes the control surface, not the need for control. Moving away from passwords reduces one class of compromise, but it raises the importance of device integrity, recovery governance, and exception handling. That makes identity assurance more contextual, because the trust boundary now includes the endpoint and the fallback path. Practitioners should plan for lifecycle and recovery controls before scaling passwordless adoption.

AI governance will fail if it starts with prohibition instead of bounded enablement. Employees will use AI tools whether policy approves them or not, so the programme question is how to define acceptable data use, vendor review, and monitoring without creating surveillance culture. This is where identity and access governance intersects with AI security: the issue is who can send which data to which system under what conditions. Practitioners should build rules that are usable enough to follow and precise enough to audit.

Third-party risk becomes more credible when it is repeatable and identity-aware. Vendor review processes often fail because they are inconsistent, not because the security questionnaires are incomplete. A repeatable model needs clear thresholds for data access, access revocation, and evidence review, especially when external services can touch identity-related or confidential workflows. Practitioners should make vendor governance measurable so exceptions are visible and defensible.

Leadership reporting should optimise for decision quality, not alarm volume. Security leaders lose credibility when they present large numbers that do not map to action or risk reduction. The better pattern is trend-based reporting that shows drift, remediation progress, and whether controls are actually working. Practitioners should use metrics that support governance decisions, not just attention.

What this signals

Identity modernisation succeeds when it is governed as a lifecycle change, not a feature rollout. Passwordless, AI usage controls, and vendor access review all depend on the same discipline: define trust boundaries, assign ownership, and verify that exceptions do not become the default path. That is why the Ultimate Guide to NHIs , Key Challenges and Risks remains relevant even in broader security programmes.

Continuous validation will increasingly be expected across identity-adjacent controls. Boards and executives do not need more alert volume, but they do need evidence that remediation changes exposure. That aligns with the practical direction in CISA cyber threat advisories, where repeatable response and control verification matter more than one-time assessments.

AI adoption introduces a governance debt problem: organisations move faster than their access, data, and approval boundaries are updated. The result is not just shadow AI, but undocumented trust paths that bypass normal review. Security teams should treat AI enablement as a policy-and-access design exercise, not as an exception to governance.


For practitioners

  • Turn penetration testing into a recurring remediation loop Define a continuous testing cadence, assign every finding to an owner, and require revalidation after remediation so the test programme proves control improvement rather than generating static reports.
  • Document passwordless recovery and exception paths early Map enrollment, device trust, fallback authentication, and account recovery before broad rollout so passwordless authentication does not create unmanaged identity exceptions.
  • Set AI usage rules around data, not slogans Create explicit policies for what data may be sent to AI tools, involve legal in the review process, and use usage trends to target training without over-collecting employee activity data.
  • Standardise third-party review criteria Use the same evidence thresholds for every vendor, including access scope, data handling, and offboarding expectations, so third-party risk decisions are repeatable and auditable.
  • Report risk in trends, not fear-based totals Track remediation progress, drift, and control effectiveness over time, and tie board reporting to outcomes such as reduced exposure or fewer high-risk exceptions.

Key takeaways

  • The episode’s core lesson is that resilient security programs depend on repeatable control loops, not one-off assessments or fear-based leadership messaging.
  • Passwordless authentication, AI usage, and third-party oversight all create new governance obligations when identity boundaries are redesigned without lifecycle control.
  • Security reporting is most effective when it measures drift, remediation, and decision quality rather than simply counting problems.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM-1Continuous testing and monitoring map to ongoing security posture validation.
NIST SP 800-53 Rev 5CA-7Continuous assessment and verified remediation align with security assessment controls.
NIST AI RMFGOVERNAI usage governance and accountability are central to the article's AI discussion.
NIST Zero Trust (SP 800-207)Passwordless and contextual trust decisions fit zero-trust identity assumptions.

Apply CA-7 to require recurring control assessments and documented remediation verification.


Key terms

  • Continuous Penetration Testing as a Service: A delivery model that runs penetration testing as an ongoing process rather than a one-time engagement. It uses change detection, human validation, and remediation loops to keep security findings aligned with the current environment instead of a stale snapshot.
  • Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
  • Third-party risk management: Third-party risk management is the process of identifying, assessing, monitoring, and reducing risk introduced by external vendors and service providers. In identity terms, it governs who outside the organisation can reach systems or data, how that access is approved, and when it must be removed.
  • AI Governance: AI governance is the set of controls used to discover, classify, approve, restrict, monitor, and revoke AI-enabled access. It connects identity, data, and policy so organisations can manage what AI can reach, what it can share, and when it should be stopped.

What's in the full article

Sprocket Security's full interview covers the operational detail this post intentionally leaves for the source:

  • How MacArthur Foundation approaches continuous penetration testing as a living assurance process rather than a yearly exercise
  • The practical communication and trust patterns behind the move to Windows Hello passwordless authentication
  • How the team frames AI usage rules, legal review, and vendor assessment without relying on blanket prohibition
  • What security leaders should report to executives when they want measurable risk reduction instead of attention-grabbing metrics

👉 Sprocket Security's full interview adds the leadership, culture, and reporting detail behind these security decisions

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, identity lifecycle, and secrets management. It helps practitioners connect identity controls to broader security operations and programme decisions.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 20, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org