Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Continuous security validation and ATT&CK coverage: are your tests current?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Periodic penetration testing no longer matches how fast cloud, SaaS, API, and identity environments change, according to Synack, while AI expands coverage but still needs human validation to prove exploitability and reduce noise. The shift toward continuous security validation makes exposure management evidence-based rather than calendar-based, and that changes how teams prioritise real risk.

NHIMG editorial — based on content published by Synack: Continuous Security Validation Is Replacing Periodic Penetration Testing

Questions worth separating out

Q: How should security teams implement continuous validation across identity-heavy environments?

A: Start by linking testing triggers to identity and infrastructure change events, including account creation, permission changes, consent grants, secret rotation, and workload deployment.

Q: Why do periodic pentests miss the most important exposure in modern environments?

A: Because the environment changes faster than the assessment cycle.

Q: What do security teams get wrong about AI safety testing?

A: The common mistake is treating AI safety testing as if it were just another security scan.

Practitioner guidance

  • Map validation triggers to identity change events Tie continuous tests to service account creation, OAuth consent changes, token issuance, secret rotation, and privileged role assignment so exposure is rechecked when risk changes, not on a fixed calendar.
  • Prioritise exploitability over scan volume Use continuous validation to determine whether a finding can be chained into access, lateral movement, or data exposure.
  • Include NHIs in the validation scope by design Ensure service accounts, API keys, workload identities, and delegated SaaS access are explicitly in the coverage model.

What's in the full article

Synack's full blog covers the operational detail this post intentionally leaves for the source:

  • How Sara AI Pentesting is positioned to expand coverage across AWS, Microsoft, and Google Cloud Marketplace environments
  • The article's explanation of AEV, COST, and CTEM as separate but related operating models for continuous validation
  • Synack's discussion of human plus AI validation, including where human researchers are still needed to prove exploitability
  • The FAQ examples and product positioning details that translate the model into procurement and deployment decisions

👉 Read Synack's analysis of continuous security validation and AI-assisted pentesting →

Continuous security validation and ATT&CK coverage: are your tests current?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Continuous validation is becoming an evidence standard, not an optional enhancement. The article shows that periodic assessment no longer matches operational reality in cloud, SaaS, API, and identity-heavy environments. Security leaders are increasingly judged on whether they can prove current exposure, not whether they can produce a quarterly report. For IAM and NHI programmes, the lesson is that stale review cycles are now a governance liability, not just an operational inconvenience.

A question worth separating out:

Q: How do you know continuous validation is actually improving risk decisions?

A: Look for shorter time to confirm exploitability, fewer low-value findings entering remediation, and better prioritisation of paths that lead to privilege escalation or material exposure. If the programme only increases test volume, it is producing activity. If it sharpens prioritisation, it is improving control effectiveness.

👉 Read our full editorial: Continuous security validation is replacing periodic pentesting



   
ReplyQuote
Share: