Most enterprise security teams are finding critical vulnerabilities after scheduled penetration tests have ended, raising concerns that traditional security assessments are struggling to keep pace with today’s rapidly changing IT environments.
According to Synack’s newly released State of Continuous Security Validation report, 95% of surveyed organizations discovered high or critical vulnerabilities outside their scheduled testing windows during the past year. More than four in 10 respondents said they uncovered serious vulnerabilities at least once a month.
The findings suggest that periodic security testing is leaving organizations with gaps in visibility as cloud infrastructure, applications and enterprise environments evolve more rapidly.
Enterprises Continue to Face Security Coverage Gaps
The report found that many organizations are unable to maintain consistent testing across their entire attack surface.
Nearly four in 10 respondents said at least 25% of their critical systems had not been independently tested or validated during the previous 90 days.
Only 15% described their organization’s security testing and validation program as continuous, despite increasing awareness that point-in-time assessments often fail to capture newly introduced vulnerabilities.
One enterprise chief information security officer surveyed described the challenge as operating with “a constant blind spot,” where new code changes can remain in production for days or weeks before being validated.
AI Expands Security Testing, but Human Experts Remain Essential
The survey found growing interest in artificial intelligence for cybersecurity, but organizations remain cautious about relying on AI without human oversight.
Seventy-nine percent of respondents said they would not act on an AI-generated security finding unless it had first been validated by a human expert.
Respondents said AI can improve reconnaissance, attack surface discovery and vulnerability identification, while human security researchers remain critical for confirming exploitability, evaluating business risk, reducing false positives and identifying complex attack paths.
“Point-in-time testing is reaching its limit because the environment changes faster than a scheduled test can represent,” said Angela Heindl-Schober, chief marketing officer at Synack. “The market direction is clear: AI expands coverage, humans prove exploitability, and security validation becomes continuous.”
Organizations Seek Continuous Security Validation
While continuous penetration testing was the most commonly cited approach for confirming whether vulnerabilities are exploitable, relatively few organizations said they have fully adopted continuous validation practices.
Respondents identified several obstacles, including compliance-driven testing schedules, integration complexity, limited trust in automated findings, false positives, uncertain return on investment and unclear ownership across security teams.
Synack said these challenges continue to slow the transition from periodic penetration testing toward continuous security validation.
Human and AI Collaboration Drives Security Testing
The company believes enterprise security programs will increasingly rely on a combination of AI automation and human expertise.
Synack’s Human + AI approach combines its Sara AI Pentesting platform with the Synack Red Team to automate reconnaissance and vulnerability discovery while using human researchers to validate exploitability and provide context around real-world attack scenarios.
The company said the approach is intended to help organizations continuously evaluate their security posture rather than relying solely on scheduled assessments.
The Bottom Line
Enterprise environments are changing faster than traditional penetration testing cycles can keep up. As organizations deploy cloud services, AI applications and continuous software updates, new vulnerabilities can emerge long before the next scheduled security assessment. Synack’s research suggests that continuous security validation, supported by both AI automation and human expertise, is becoming increasingly important for identifying exploitable risks before attackers do.

