Skip to content

Pentests: Critical Gap Between Test Cycles and Threat Dynamics

Bottom line: Organizations need continuous security validation instead of point-in-time testing, as infrastructures change faster than traditional cycles can cover.

Traditional, point-in-time penetration tests can no longer keep pace with the speed of modern IT environments – 95 percent of surveyed security leaders discovered critical vulnerabilities outside regular test windows in the past year.

The Synack study “The State of Continuous Security Validation” reveals a structural management problem: 95 percent of participants found severe or critical vulnerabilities in phases outside their planned test windows. In 42 percent of cases, this occurred at least once monthly. This demonstrates that corporate environments are changing faster than point-in-time pentests can capture them.

The study identifies three interconnected problem areas: Regarding coverage gaps, 38 percent report that at least one quarter of their critical attack surface was not independently tested in the preceding 90 days. A trust gap with AI is evident in the fact that 79 percent would not act based solely on AI-generated results without human validation. The maturity gap is particularly striking: only 15 percent characterize their own security testing and validation program as continuous. One cited security leader describes the situation as a “constant blind spot,” because new code changes remained in production for days or weeks before validation took place.

AI deployment requires human oversight as a core principle. Respondents do not reject AI as a tool, but rather autonomous decisions without human monitoring. They see AI primarily for reconnaissance, identification of potential vulnerabilities, and scaling test coverage. Assessing actual exploitability, business risk, stakeholder communication, testing complex workflows, and filtering false positives remain human tasks.

Respondents cite the greatest practical obstacles as rigid compliance requirements with fixed test cycles, complex process integration, skepticism toward automated results, excessive false positives, difficult-to-demonstrate ROI, and unclear team responsibilities. Continuous pentesting is named by 22 percent as the preferred method for checking vulnerability exploitability – yet only 15 percent rate their overall program as continuous. The central issue does not lie in lack of awareness, but in practical implementation: automation generates more signals, but security teams need reliable insights rather than additional noise.


Source: www.it-daily.net · Published 24 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: