TL;DR: Point-in-time pentests miss rapidly changing exposure as cloud workloads, APIs, and code releases shift, and Synack says organisations test only 32% of their attack surface under conventional fixed-scope programmes. The governance problem is not more reports, but continuous validation that prioritises what is exploitable now.
NHIMG editorial — based on content published by Synack: Guest Blog: The Annual Pentest Is No Longer Enough
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, with 46% confirmed and 26% suspected.
Questions worth separating out
Q: How should security teams validate attack surface changes in fast-moving environments?
A: They should tie validation to change events, not fixed intervals.
Q: Why do annual pentests fail to catch modern application risk?
A: Annual pentests assume the attack surface stays stable long enough for a point-in-time review to remain valid.
Q: What do organisations get wrong about vulnerability discovery?
A: They often treat discovery as proof of risk.
Practitioner guidance
- Re-scope assurance around change, not calendar cycles Tie re-testing to major releases, infrastructure changes, and API additions so validation follows exposure rather than a quarterly schedule.
- Separate discovery from exploitability Use automated discovery to find assets and routes, then require human validation before a finding is treated as security-relevant.
- Prioritise attack paths that reach identity and privilege boundaries Focus remediation on paths that can lead to service accounts, tokens, exposed admin interfaces, or other privileged control points.
What's in the full article
Synack's full blog covers the operational detail this post intentionally leaves for the source:
- How Sara AI Pentesting is positioned to discover and validate exposure across approved external web and host assets
- What the free trial includes for a small web application or up to 100 IP addresses
- The workflow for combining autonomous discovery with human-validated findings
- How the vendor frames ROI, remediation prioritisation, and integration into existing security workflows
👉 Read Synack's analysis of continuous pentesting and AI validation →
Continuous pentesting and AI validation: what changes for security teams?
Explore further
Continuous validation is becoming the correct governance model for fast-moving attack surfaces. Annual assurance assumes the asset picture is stable long enough for a scheduled test to remain meaningful. That assumption no longer holds in cloud and API-heavy environments, where exposure can change between releases. The discipline is shifting from evidence of past testing to evidence of current exploitability, which aligns better with NIST-CSF risk treatment and continuous control monitoring.
A question worth separating out:
Q: How do teams know continuous validation is actually working?
A: They should see fewer unknown gaps, faster confirmation of control drift, and more reliable response outcomes when access patterns change. If testing only produces reports but not operational correction, it is not validating control effectiveness. The signal of success is measurable improvement in what teams can prove and contain.
👉 Read our full editorial: Continuous pentesting is replacing annual assurance models