Guest Blog: The Annual Pentest Is No Longer Enough
Craig Rosewarne, Managing Director of Wolfpack Information Risk, explains why continuous, AI-enabled validation, paired with human-verified exploitability, gives security leaders a real-time view of what's actually at risk.
Key Takeaways
- Point-in-time pentests capture only a snapshot; attack surfaces change continuously as cloud workloads, APIs, and code releases shift.
- Most organizations test only a fraction of their total attack surface, leaving significant blind spots for attackers.
- Security leaders should be asking what's exploitable now, not just did we complete the annual pentest.
- Continuous validation shrinks the window of unknown exposure between scheduled assessments and major releases.
- Combining AI-driven discovery with human-verified exploitability lets teams prioritize real risk instead of theoretical vulnerabilities.
This is a guest blog written by Craig Rosewarne, Managing Director, Wolfpack Information Risk.
Why Continuous, AI-Enabled Validation Must Become the New Standard
For years, organisations have treated penetration testing as an annual—or at best quarterly—event. Scope the engagement, test a defined set of systems, receive a report, remediate the most serious findings, and repeat the cycle next year.
That model made sense when infrastructure changed slowly. It does not make sense now.
Modern attack surfaces are dynamic: cloud workloads appear and disappear, APIs proliferate, third-party integrations expand, and code releases happen continuously. Security leaders need to understand how AI-enabled validation can keep pace with these rapid changes, ensuring they are not vulnerable between scheduled assessments.
A point-in-time pentest is valuable, but it is precisely that: a snapshot. By the time the final report has been delivered and socialised, the environment it assessed may already have changed materially. From a business-risk perspective, that creates an uncomfortable truth: an organisation may be able to demonstrate that it tested an application last quarter, while having little assurance about whether it is exploitable this week.
This is why security leaders should be reassessing the operating model, not simply procuring more tests.
The Risk Case: Unknown Exposure Is Still Exposure
The fundamental weakness in periodic testing is coverage. Security teams generally prioritise their most visible or business-critical assets, but attackers are more opportunistic. They look for forgotten subdomains, exposed cloud services, neglected APIs, misconfigured hosts and weak integration points that can become a route into more valuable systems, making proactive, continuous testing essential for confidence in security.
Synack reports that organisations test only a fraction of their total attack surface, leaving substantial areas beyond the scope of conventional test programmes. Its recent research is blunt: the gap between scheduled testing and a continually changing environment has become a material business-risk issue. Synack’s Sara AI Pentesting overview describes the result as incomplete coverage, undiscovered vulnerabilities and untested attack paths.
The board-level question should therefore move beyond, “Did we complete the annual pentest?” It should become, “What is exploitable now, and how quickly will we know when that changes?” This shift helps board members better understand ongoing risk and supports strategic decision-making around cybersecurity investments.
This matters for operational resilience, regulatory scrutiny, customer trust and cyber-insurance conversations alike. A compliance report may demonstrate that a control was performed. It does not necessarily demonstrate that current exposure is understood, prioritised and being reduced.
For IT leaders, the business case is increasingly clear:
- Reduce the window of unknown exposure between major releases and scheduled assessments.
- Test more of the environment than a fixed-scope manual engagement can economically cover.
- Prioritise remediation around proven exploitability, rather than a long list of theoretical vulnerabilities.
- Generate meaningful trend data for executives and boards, showing whether risk is reducing over time.
- Preserve scarce security expertise for the complex decisions and attack paths where human judgement adds the greatest value.
A Practical Next Step: Test the Model, Not Just the Marketing
Synack’s Sara AI Pentesting is designed around this combined model. Sara (the Synack Autonomous Red Agent) continuously discovers and analyses exposure across approved external web and host assets, while the Synack Red Team validates genuine, exploitable risk. This approach offers a scalable, efficient solution that integrates seamlessly into existing security workflows, providing measurable ROI and reducing manual effort.
For organisations ready to assess the model in their own environment, Synack is offering a free Sara AI Pentest trial: an attack-surface discovery scan and a Sara AI Pentest for an approved small web application or up to 100 IP addresses, with human-validated findings.
In closing, the annual pentest should not disappear overnight, but it should no longer be the centrepiece of assurance. The organisations that will manage cyber risk most effectively are those that stop treating testing as an event and start treating it as a continuous, evidence-led discipline.
Related reading: The AI Pentesting Platform Checklist for Regulated Enterprises • Why the Future of Pentesting Needs Humans and Agentic AI Working Together • Considering Build vs. Buy for AI Pentesting? Top 5 Questions to Ask
About the Author
Craig Rosewarne is the Managing Director of Wolfpack Information Risk, a Synack partner and a specialist firm. Craig has 20+ years management experience in the fields of cybersecurity, privacy and resilience. He has provided oversight to 750+ projects in this domain. Wolfpack Information Risk was established in 2011 and assists countries, companies and communities to defend against cyber threats.
Frequently Asked Questions
Continuous penetration testing is an ongoing process of discovering and validating exposure across an organization’s attack surface, rather than testing on a fixed annual or quarterly schedule. It combines continuous discovery (often AI-enabled) with regular human validation to confirm which vulnerabilities are actually exploitable.
Modern attack surfaces change constantly as cloud workloads, APIs, and code releases are added or updated. A pentest is a snapshot of a fixed point in time, so by the time a report is delivered, the environment it assessed may have already changed. This leaves a gap where new exposure can go undetected until the next scheduled test.
According to Synack’s research with analyst firm Omdia, on average, organizations test 32% of their total attack surface under conventional, fixed-scope test programs. That leaves substantial areas, such as forgotten subdomains, exposed cloud services, and neglected APIs, outside the scope of testing and available to opportunistic attackers.


