Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Compliance validation vs real resilience: what are teams missing?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: A global payments provider shifted from semi-annual, sample-based pentests to quarterly, full-environment validation after human-led tests missed default credentials, exposed management ports, and exploitable attack paths, according to Horizons.ai. The lesson is that proving risk is closed now matters as much as finding it, because compliance coverage alone leaves blind spots.

NHIMG editorial — based on content published by Horizons.ai: From Patch Tuesday to Pentest Wednesday®: When Proving Compliance Becomes Cyber Resilience

Questions worth separating out

Q: How should security teams prove that pentest findings are actually closed?

A: Teams should require re-testing of the exact attack path, not just a ticket showing the issue was remediated.

Q: Why do weak credentials and defaults matter so much in large environments?

A: Because they compress attack time and reduce the effort needed to move from initial access to internal compromise.

Q: What do security teams get wrong about audit-friendly pentests?

A: They often confuse passing an audit with proving resilience.

Practitioner guidance

  • Replace sample-based pentest scope with full-asset validation Test every IP, every quarter, or at a cadence that reflects your environment change rate.
  • Prioritise exposed credentials and default access paths first Use attack-path evidence to rank findings that involve weak passwords, default credentials, and unmanaged management interfaces ahead of abstract vulnerability counts.
  • Require remediation proof before closing findings Do not rely on static tickets or declaration-only closure.

What's in the full article

Horizons.ai's full blog covers the operational detail this post intentionally leaves for the source:

  • The exact NodeZero run structure used to move from sample testing to quarterly full-environment validation.
  • The exploitation evidence shown to IT and product teams to accelerate remediation decisions.
  • The specific changes to audit reporting that helped banking partners accept the new testing cadence.
  • The operational use of Tripwires and 1-Click Verify to replace older deception and verification tooling.

👉 Read Horizons.ai's analysis of compliance testing and cyber resilience →

Compliance validation vs real resilience: what are teams missing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Compliance evidence is not the same as resilience evidence. A pentest that satisfies an auditor can still miss the combinations attackers actually use, especially where credentials, defaults, and management exposure sit outside the tested sample. That creates a governance gap between what is signed off and what is truly closed. For practitioners, the lesson is to treat proof of exploitability as the real control objective, not the report itself.

A question worth separating out:

Q: Who is accountable when a tested weakness returns after remediation?

A: Accountability should sit with the control owner for the affected system and with the programme owner responsible for validation cadence. If a weakness reappears, that usually means the underlying configuration or lifecycle process was not fixed, only the symptom was patched.

👉 Read our full editorial: Compliance testing is not enough for cyber resilience



   
ReplyQuote
Share: