TL;DR: BAS, CTEM, CART, pen testing, VA and AEV solve different security problems, but most programs blur them and waste budget on mismatched controls, according to FireCompass. The practical shift is toward continuous offensive validation, because exposure discovery without exploitability testing leaves a measurable gap between visibility and risk reduction.
NHIMG editorial — based on content published by FireCompass: BAS, CTEM, CART, Pen Test, VA, AEV, COST: What Each Actually Does, and When to Use What
By the numbers:
- The average enterprise now manages 25x to 50x more non-human identities than human identities.
- Only 5.7% of organisations have full visibility into their service accounts.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
Questions worth separating out
Q: How should security teams choose between VA, BAS, CART and pen testing?
A: Choose by the question you need answered.
Q: Why do exposure scans often fail to reduce real risk?
A: Exposure scans often fail because they stop at discovery.
Q: What breaks when attack surface management cannot validate critical risk?
A: When ASM cannot validate critical risk, teams over-trust raw findings and under-invest in the exposures that matter most.
Practitioner guidance
- Differentiate validation layers in your programme Map VA, DAST, BAS, pen testing, ASM, AEV and CART to distinct control objectives so procurement, operations and reporting do not blur them together.
- Validate exposures before prioritising remediation Use exploit testing or adversarial validation on the subset of assets that appear most reachable, most exposed or most connected to sensitive identities.
- Align offensive testing to attack paths Prioritise attack paths that cross identity, application and infrastructure boundaries, especially where service accounts or API credentials can be abused.
What's in the full article
FireCompass's full article covers the operational detail this post intentionally leaves for the source:
- Per-category breakdowns of what each testing type catches and misses in practice.
- Detailed guidance on when to use each category in a real security programme.
- Examples of how continuous offensive testing is positioned alongside CTEM and exposure validation.
- A vendor-specific explanation of how the platform chains findings into attack paths.
👉 Read FireCompass's breakdown of BAS, CTEM, CART, VA and AEV →
Offensive security testing categories: what do BAS, CTEM and CART do?
Explore further
Category confusion is now a governance problem, not a naming problem. The article is right that VA, BAS, pen testing, ASM, AEV and CART answer different questions, but many programmes still buy them as if they were interchangeable. That creates budget leakage and a false sense of coverage. For identity-heavy environments, the same issue shows up when teams assume credential discovery, privilege validation and exploitability testing are the same thing. They are not, and governance should separate them clearly.
A question worth separating out:
Q: How do continuous offensive testing programs support zero trust and NHI governance?
A: They test whether assumptions about access, exposure and privilege still hold under realistic attack conditions. For NHI governance, that means checking whether exposed secrets, service accounts or tokens can actually be abused to reach data or control planes. For zero trust, it means proving that exposure does not automatically become trusted access just because it is authenticated.
👉 Read our full editorial: BAS, CTEM and CART: where offensive security categories diverge