TL;DR: Continuous pentesting is still rare, with only 15% of enterprises describing their programmes as continuous even though 95% say they found high or critical vulnerabilities outside scheduled testing windows, according to Synack. The gap shows that attack-surface change is outpacing point-in-time validation, and AI-assisted testing only works when humans still validate findings before action.
NHIMG editorial — based on content published by Synack: How Continuous Pentesting Became Standard Practice at Dow
Questions worth separating out
Q: What breaks when pentesting is only done on a schedule?
A: Scheduled testing misses the rate of asset change, so newly deployed services, changed configurations, and temporary exposures can remain live long enough to be exploited.
Q: When should organisations prioritise continuous validation over point-in-time pen testing?
A: Prioritise continuous validation when code releases, infrastructure changes, or identity changes happen frequently enough that a quarterly test cannot keep pace.
Q: What do security teams get wrong about AI-generated penetration testing findings?
A: The main mistake is treating AI output as proof rather than as a lead.
Practitioner guidance
- Measure validation latency across your environment Track the time between asset creation, exposure, and first security validation.
- Automate new-asset ingestion into testing workflows Connect discovery pipelines so newly provisioned assets are queued for validation in near real time.
- Require human sign-off on AI-generated findings Make analyst review mandatory before AI-produced exploit results move into remediation, incident response, or executive reporting.
What's in the full article
Synack's full article covers the operational detail this post intentionally leaves for the source:
- How Dow's internal red team and external testing model were divided across ownership and execution
- The automation pattern used to feed newly exposed assets into continuous testing in near real time
- How human review was applied to AI-generated findings before results reached the customer
- The practical shape of Synack's Sara Continuous model for recurring AI-led validation
👉 Read Synack's analysis of how continuous pentesting became standard practice at Dow →
Continuous pentesting and AI validation: are your controls keeping up?
Explore further
Continuous validation is becoming the only realistic answer to volatile attack surfaces. Point-in-time testing assumes the environment will remain stable long enough for a report to matter. That assumption breaks in modern cloud and application estates where assets, secrets, and access paths change continuously. The practical conclusion is that testing models must be tied to change velocity, not calendar cycles.
A question worth separating out:
Q: Who is accountable when continuous validation misses a newly exposed asset?
A: Accountability should sit with the team that owns asset discovery, test coverage, and remediation routing, not with tooling alone. Continuous validation only works when ownership is explicit, change events are monitored, and findings are acted on through a defined governance path.
👉 Read our full editorial: Continuous pentesting is becoming the baseline for changing attack surfaces