Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI pentesting is becoming a continuous control, not an annual exercise


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 17031
Topic starter  

TL;DR: Traditional point-in-time penetration tests can create false confidence, while continuous AI-assisted testing is emerging as a better fit for regulated environments that need recurring validation, business-logic coverage, and traceable findings, according to Synack. The practical shift is toward more frequent offensive testing between deeper engagements, because AI is lowering attacker cost while shrinking remediation windows.

NHIMG editorial — based on content published by Synack: How Iberia Cards Uses Sara AI Pentesting to Stay Ahead of Modern Threats

By the numbers:

  • Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, followed by inadequate monitoring and logging at 37% and over-privileged accounts at 37%.

Questions worth separating out

Q: What breaks when penetration testing is only done annually?

A: Annual testing breaks down when environments change faster than the assessment cycle.

Q: Why do AI-enabled attackers change the value of offensive security testing?

A: AI lowers the cost of reconnaissance and tailored probing, which means attackers can focus on business-specific weaknesses faster and more often.

Q: How do security teams know whether offensive testing is actually reducing exposure?

A: Look for closed-loop outcomes, not raw finding counts.

Practitioner guidance

  • Increase testing frequency for high-change assets Run recurring offensive tests on internet-facing applications, authenticated portals, and APIs between deeper annual or semi-annual engagements so exposure does not age unchecked.
  • Include authenticated workflows in every critical test scope Require grey-box or credentialed testing for payment, banking, and admin workflows where role changes, session state, and chained actions determine real impact.
  • Track remediation speed as a control metric Measure the time from finding to fix for externally reachable issues, because AI-driven adversaries compress the window between disclosure and attempted exploitation.

What's in the full article

Synack's full case study covers the operational detail this post intentionally leaves for the source:

  • A practical account of how Iberia Cards compared AI pentesting with human researcher-led testing across real production assets
  • The grey-box testing setup used for authenticated business logic and why credentials changed the depth of findings
  • The CISO's operational criteria for deciding when AI pentesting is useful between deeper red-team engagements
  • The reporting and traceability details that help regulated teams demonstrate control effectiveness to auditors

👉 Read Synack’s case study on Iberia Cards and AI pentesting for regulated environments →

AI pentesting is becoming a continuous control, not an annual exercise?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 16116
 

Continuous offensive validation is becoming a governance control, not just a testing method. Iberia Cards’ model reflects a broader shift: organisations need repeated evidence that controls still work after changes, not just proof that they once worked. In regulated environments, the real issue is control decay between annual cycles. NHI Mgmt Group sees this as a governance problem because exposure windows, not audit timing, now define risk.

A question worth separating out:

Q: Who should own the response when offensive tests repeatedly uncover the same access flaws?

A: Accountability should sit with the teams that control the affected application, identity, or platform boundary, not with the testing provider. Repeated findings usually indicate a control gap in ownership, prioritisation, or change management, which means remediation must be tied to operational accountability and tracked through governance.

👉 Read our full editorial: AI pentesting is becoming a continuous control, not an annual exercise



   
ReplyQuote
Share: