TL;DR: Weekly validation can expose exploitable cloud and hybrid exposure long before an annual pentest would, according to Horizons.ai’s account of a regulated financial and insurance organisation. The core lesson is that security assurance must follow environment change, not the calendar, or remediation will always trail risk.
NHIMG editorial — based on content published by Horizons.ai: From Patch Tuesday to Pentest Wednesday®: Continuous Validation in a Regulated Environment
By the numbers:
- One AWS read-only credential was involved in 39 distinct attack paths
- Full AWS account compromise was safely achieved in under 10 minutes
Questions worth separating out
Q: What breaks when application security relies on annual pentest snapshots?
A: Annual pentest snapshots break down when applications, secrets, and access paths change faster than the next test cycle.
Q: Why do cloud identities create hidden escalation risk?
A: Cloud identities are risky because their power often comes from relationships, not obvious labels.
Q: How do you know if continuous remediation is actually working?
A: Look for reduced dwell time between risk detection and entitlement change, fewer identities outside lifecycle ownership, and fewer stale permissions surviving the review cycle.
Practitioner guidance
- Adopt continuous exposure validation Replace annual-only pentest assumptions with recurring testing that tracks cloud, on-prem, and third-party change as it happens.
- Map identity relationships to attack paths Build a view of how roles, policies, and delegated permissions connect across AWS, Azure, GCP, and hybrid systems.
- Require verification before closure Do not close high-risk findings on the basis of a ticket or patch alone.
What's in the full article
Horizons.ai's full blog covers the operational detail this post intentionally leaves for the source:
- Step-by-step examples of how weekly pentesting was operationalised across cloud, on-prem, and third-party environments
- Specific attack-path screenshots and remediation evidence that show how findings were validated and then closed
- The team's workflow for reducing debate by pairing exploit proof with remediation recommendations and retesting
- How the organisation used repeated validation to uncover issues in Active Directory, EDR coverage, and cloud estates
👉 Read Horizons.ai's analysis of continuous validation in regulated environments →
Continuous validation in regulated environments: are annual tests enough?
Explore further
Continuous validation is becoming a governance requirement, not a testing preference. Annual snapshots assume the environment stays stable long enough for the results to remain useful. In cloud and hybrid estates, that assumption fails quickly because permissions, workloads, and third-party access evolve continuously. Practitioners should treat validation cadence as part of control design, not just an operational convenience.
A question worth separating out:
Q: What should teams do when a cloud finding affects identity access?
A: Teams should treat the finding as both a security issue and an identity governance issue. The immediate task is to identify the roles, policies, and delegated permissions that made the path possible, then retest after the fix. That approach is more reliable than relying on owners to confirm the issue is resolved in their own systems.
👉 Read our full editorial: Continuous validation exposes the gap between compliance and reality