TL;DR: A global enterprise with 2,000+ web applications moved from 40% annual coverage to 100% continuous exploit-validated testing, cut per-test cost by 80%, and reduced lead times from weeks to days while keeping false positives below 5%, according to FireCompass. The governance lesson is that coverage, cadence, and evidence quality now matter more than budget-driven sampling.
NHIMG editorial — based on content published by FireCompass: Customer Case Study Scaling Continuous Pen Testing Across a Global Enterprise
By the numbers:
- False positives stabilized below 5%, compared with 40% to 70% common to the customer’s prior DAST tools.
Questions worth separating out
A: Security teams should remove friction from test intake, standardize scope where possible, and focus human effort on validation and remediation quality.
Q: Why does proof-of-exploit validation matter more than raw scan volume?
A: Raw scan volume tells you how much was inspected, not whether a finding can actually be abused.
Q: What do teams get wrong about annual penetration tests?
A: They often treat a periodic test as proof that controls will hold the rest of the year.
Practitioner guidance
- Expand coverage to the full application estate Replace budget-driven sample testing with an inventory-backed programme that assigns a test cadence to every application, including internal systems and low-visibility assets.
- Prioritise exploit-validated findings Require proof of exploitability, chaining, or business logic impact before escalating findings into remediation queues or executive reporting.
- Tie test frequency to application criticality Use quarterly testing for high-risk applications, annual testing for lower-risk systems, and on-demand retesting after material code or access changes.
What's in the full article
FireCompass's full case study covers the operational detail this post intentionally leaves for the source:
- Cost and lead-time mechanics behind the move from £2K to £20K engagements to flat-rate continuous testing.
- How quarterly testing was assigned to critical applications while lower-risk systems stayed on annual or on-demand cadences.
- Why the platform reported only exploitable findings, including chained attack paths and business logic flaws.
- How the customer used continuous validation to cover the full 2,000+ application portfolio instead of a 40% sample.
👉 Read FireCompass's case study on scaling continuous pen testing across a global enterprise →
Continuous pen testing at scale: what changes for enterprise teams?
Explore further
Coverage debt is the real control gap in large application estates. When only 40% of a 2,000+ application portfolio is tested each year, the issue is not simply efficiency, it is governance failure. Risk exists in the untested 60% as much as in the known findings, and teams cannot claim assurance over assets they never validate. Practitioners should treat incomplete test coverage as a measurable control gap, not an acceptable operating state.
A question worth separating out:
Q: How do you know if continuous testing is actually working?
A: You should see faster conversion from raw findings to confirmed risk, fewer disputed remediation priorities, and clearer evidence that validation is happening between assessment cycles. If the programme still relies on quarterly snapshots to tell you what is exploitable, it is not continuous in operational terms.
👉 Read our full editorial: Continuous pen testing closes coverage gaps in large enterprise estates