Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Continuous security validation: are your tests keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20377
Topic starter  

TL;DR: Security teams discover high or critical vulnerabilities outside scheduled testing windows 95% of the time, and 79% will not act on AI-generated findings without human validation, according to Synack’s early research. The data suggests continuous security validation is becoming a distinct operating model because cadence alone no longer matches the speed of modern attack surfaces.

NHIMG editorial — based on content published by Synack: The State of Continuous Security Validation: An Early Look at the Data

By the numbers:

Questions worth separating out

Q: How should security teams implement continuous validation in fast-moving release pipelines?

A: Teams should embed validation into the release and change-management cycle, not treat it as a separate event.

Q: Why do periodic tests miss so many serious vulnerabilities?

A: Periodic tests miss exposures because modern environments change between scheduled windows.

Q: What do security teams get wrong about AI-assisted cloud validation?

A: They often assume a fluent answer is the same as a validated result.

Practitioner guidance

  • Measure validation coverage, not just test volume Track what percentage of critical assets, identities, and internet-facing services are validated between changes, not just per quarter.
  • Insert human approval for AI-generated findings Require human review before AI-assisted findings move into remediation queues, especially for exploitable access paths, secret exposure, or privilege anomalies.
  • Extend continuous validation to identity estates Apply the same validation loop to non-human identities, service accounts, and secret-bearing workflows so access drift is checked as often as infrastructure drift.

What's in the full report

Synack's full preview covers the survey detail this post intentionally leaves at headline level:

  • Methodology context for the 97 security leaders surveyed, including role mix and testing patterns.
  • The full breakdown of how teams trigger validation, prioritise findings, and confirm exploitability.
  • Additional findings on AI usage in security workflows and where human validation still dominates decisions.

👉 Read Synack's early findings on continuous security validation →

Continuous security validation: are your tests keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19968
 

Coverage gaps, not test frequency, are now the real control failure. The article’s central signal is that teams can test often and still miss high-severity exposure because the environment changes faster than the testing model. That is a governance problem, not a tooling problem. In IAM and NHI programmes, the same failure appears when access review cadence lags credential lifecycle and privilege drift. Practitioners should treat exposure coverage as the primary measure of assurance.

A question worth separating out:

Q: Who is accountable when a validated exposure is found after a scheduled test has already passed?

A: Accountability sits with the programme owner that defined the assurance model, not with the analyst who found the issue. If exposure repeatedly appears between test windows, that indicates a governance gap in validation cadence, asset visibility, or change control. The right response is to redesign assurance around current exposure, not defend the schedule.

👉 Read our full editorial: Continuous security validation is outpacing periodic testing models



   
ReplyQuote
Share: