Enterprises are struggling to keep pace with the rapid evolution of their attack surfaces, according to Synack's The State of Continuous Security Validation report. The study reveals that traditional point-in-time penetration testing is no longer sufficient as organizations increasingly adopt AI-assisted development, cloud technologies, and continuous software delivery. While AI is expanding security testing capabilities, human expertise remains essential for validating real-world exploitability and business risk.
Synack's latest market research highlights a widening gap between the speed of enterprise technology changes and the frequency of traditional security testing.
According to the survey, 95% of organizations identified high or critical vulnerabilities outside their scheduled penetration testing windows during the past year. Among them, 42% encountered these vulnerabilities at least once every month, demonstrating that point-in-time assessments are increasingly unable to capture today's rapidly changing attack surface.
The report identifies three interconnected challenges affecting enterprise cybersecurity programs.
Coverage Gap:
Thirty-eight percent of respondents said that at least one-quarter of their critical attack surface had not undergone independent testing or validation within the previous 90 days, leaving significant portions of enterprise environments exposed.
AI Trust Gap:
Although AI continues transforming cybersecurity operations, 79% of respondents stated they would not act on an AI-generated security finding without human validation, emphasizing the importance of expert oversight.
Maturity Gap:
Only 15% described their organization's security testing and validation program as fully continuous, despite widespread recognition that continuous validation provides stronger protection than periodic testing.
One enterprise respondent summarized the challenge:
"It simply means we operate with a constant blind spot, where new code changes run in production for days or weeks before they are finally validated." CISO/CSO, enterprise respondent
The research found strong support for AI-assisted penetration testing when paired with experienced human security researchers.
Respondents believe AI can effectively automate reconnaissance, expand testing coverage, and identify potential vulnerabilities at scale. However, they continue relying on human experts to validate exploitability, assess business impact, reduce false positives, evaluate complex attack paths, and communicate risk to stakeholders.
"Point-in-time testing is reaching its limit because the environment changes faster than a scheduled test can represent," said Angela Heindl-Schober, Chief Marketing Officer at Synack. "The market direction is clear: AI expands coverage, humans prove exploitability, and security validation becomes continuous. The gap is not awareness. It is execution."
While continuous penetration testing emerged as the most commonly cited approach for confirming exploitability, organizations continue facing implementation challenges.
Respondents identified several obstacles, including compliance-driven testing schedules, integration complexity, limited confidence in automated findings, false positives, difficulties demonstrating return on investment, and unclear ownership across security teams.
"Automation can surface more signals, but security teams need evidence, not noise," said Mark Kuhr, Co-Founder and Chief Technology Officer at Synack. "Human researchers bring the creativity and context to chain weaknesses, confirm exploitability and show what an attacker can actually do."
Synack positions its Human + AI approach as a way to bridge the gap between automation and expert analysis.
Its Sara AI Pentesting platform combines the Synack Autonomous Red Agent with the Synack Red Team to automate reconnaissance, attack surface mapping, and initial exploit validation while enabling human researchers to verify exploitability, identify chained attack paths, and provide contextual risk assessments that automation alone cannot replicate.
The research was based on responses from 97 security leaders, including CISOs, security directors, security architects, and offensive security professionals, examining enterprise security testing practices, vulnerability validation, attack surface coverage, and expectations for AI-driven security.
About Synack
Synack delivers continuous pentesting through its Human + AI platform for continuous security validation. Sara AI Pentesting, powered by the Synack Autonomous Red Agent, combines agentic AI with the Synack Red Team—the world's most rigorously vetted community of security researchers—to help organizations proactively reduce risk, stay compliant, and stay ahead of evolving cyber threats. Sara handles reconnaissance, attack surface mapping, and initial exploit validation at scale, while human experts validate real-world exploitability and provide the creativity and judgement automation cannot replicate. Founded by former NSA operatives, Synack has enabled nearly 10 million hours of security testing to protect critical assets, from global financial systems to U.S. Defense Department networks. Synack was recognized by both G2 and GigaOm as a Leader in Penetration Testing and PTaaS. Learn more at synack.com and on LinkedIn.