TL;DR: Security teams discover high or critical vulnerabilities outside scheduled testing windows 95% of the time, and 79% will not act on AI-generated findings without human validation, according to Synack’s early research. The data suggests continuous security validation is becoming a distinct operating model because cadence alone no longer matches the speed of modern attack surfaces.
NHIMG editorial — based on content published by Synack: The State of Continuous Security Validation: An Early Look at the Data
By the numbers:
- 79% would not act on an AI-generated finding without human validation.
Questions worth separating out
Q: How should security teams implement continuous validation in fast-moving release pipelines?
A: Teams should embed validation into the release and change-management cycle, not treat it as a separate event.
Q: Why do periodic tests miss so many serious vulnerabilities?
A: Periodic tests miss exposures because modern environments change between scheduled windows.
Q: What do security teams get wrong about AI-assisted cloud validation?
A: They often assume a fluent answer is the same as a validated result.
Practitioner guidance
- Measure validation coverage, not just test volume Track what percentage of critical assets, identities, and internet-facing services are validated between changes, not just per quarter.
- Insert human approval for AI-generated findings Require human review before AI-assisted findings move into remediation queues, especially for exploitable access paths, secret exposure, or privilege anomalies.
- Extend continuous validation to identity estates Apply the same validation loop to non-human identities, service accounts, and secret-bearing workflows so access drift is checked as often as infrastructure drift.
What's in the full report
Synack's full preview covers the survey detail this post intentionally leaves at headline level:
- Methodology context for the 97 security leaders surveyed, including role mix and testing patterns.
- The full breakdown of how teams trigger validation, prioritise findings, and confirm exploitability.
- Additional findings on AI usage in security workflows and where human validation still dominates decisions.
👉 Read Synack's early findings on continuous security validation →
Continuous security validation: are your tests keeping up?
Explore further
Coverage gaps, not test frequency, are now the real control failure. The article’s central signal is that teams can test often and still miss high-severity exposure because the environment changes faster than the testing model. That is a governance problem, not a tooling problem. In IAM and NHI programmes, the same failure appears when access review cadence lags credential lifecycle and privilege drift. Practitioners should treat exposure coverage as the primary measure of assurance.
A question worth separating out:
Q: Who is accountable when a validated exposure is found after a scheduled test has already passed?
A: Accountability sits with the programme owner that defined the assurance model, not with the analyst who found the issue. If exposure repeatedly appears between test windows, that indicates a governance gap in validation cadence, asset visibility, or change control. The right response is to redesign assurance around current exposure, not defend the schedule.
👉 Read our full editorial: Continuous security validation is outpacing periodic testing models