TL;DR: Annual penetration tests leave long windows of unverified exposure as cloud drift, forgotten assets, and third-party endpoints change the perimeter faster than teams can review it, according to Sprocket Security’s analysis. Continuous attack surface monitoring, validated by human testing, is becoming the practical answer to an environment attackers can map in minutes.
NHIMG editorial — based on content published by Sprocket Security: Continuous attack surface visibility and attacker-perspective perimeter testing
By the numbers:
- According to Verizon’s 2024 DBIR, exploitation of vulnerabilities as an initial access vector grew 180% in a single year.
- According to Mandiant’s M-Trends 2024 Report, the global median dwell time was 10 days.
Questions worth separating out
Q: How should security teams validate attack surface changes in fast-moving environments?
A: They should tie validation to change events, not fixed intervals.
Q: Why do stale external assets create such a high breach risk?
A: Stale assets create risk because they retain trust relationships long after teams stop watching them.
Q: What do teams get wrong about annual penetration tests?
A: They often treat a periodic test as proof that controls will hold the rest of the year.
Practitioner guidance
- Build external discovery around attacker pathways Map DNS, certificate transparency, IP ranges, and non-standard ports continuously so new services are discovered the same way an attacker would find them.
- Reconcile discovered assets to owners and retirement status Require every newly surfaced subdomain, endpoint, or service to be matched to a business owner, an explicit purpose, and a decommissioning decision if it should no longer exist.
- Prioritise internet-facing services with authentication exposure Focus first on VPNs, admin consoles, APIs, and any reachable systems that handle login, session creation, or credential storage because they compress the path to compromise.
What's in the full article
Sprocket Security's full analysis covers the operational detail this post intentionally leaves for the source:
- Exact reconnaissance workflow used to discover forgotten subdomains and non-standard services
- Engagement-level example of the Check Point Security Gateway exposure and how it was validated
- Practical continuous penetration testing model used to convert discovery into verified remediation
- Comparison of continuous attack surface monitoring outputs versus point-in-time pentest findings
External attack surface drift: are your perimeter controls keeping up?
Explore further
Annual perimeter testing is a governance artefact, not an operational control. A once-a-year test can document exposure, but it cannot govern change. In environments where assets appear and disappear continuously, the control failure is stale visibility rather than absent tooling. Practitioners should treat external exposure as a living governance problem, not a periodic audit event.
A question worth separating out:
Q: How should organisations respond when a new exposed service is found?
A: They should triage it before assuming it is low risk. Confirm ownership, verify whether authentication or privileged access is involved, determine whether the service should exist at all, and push any exploitable finding into remediation with a clear verification step before the next change cycle closes.
👉 Read our full editorial: Continuous attack surface visibility is replacing annual perimeter testing