How Continuous Pentesting Became Standard Practice at Dow
A few years ago, Dow's cyber engineering team made the switch from point-in-time pentesting to continuous coverage for their high-value assets. How'd they do it? By partnering with Synack. And keep in mind this was before the recent wave of AI-powered pentesting solutions. Dow was ahead of the curve.
Key Takeaways
- Dow moved from point-in-time to continuous pentesting starting in 2022, years before AI pentesting became a category.
- Dow's internal red team directs Synack's scale toward its highest-value assets rather than trying to match that scale itself.
- Automation feeds newly exposed assets to Synack in near real time, so testing keeps pace with a constantly changing attack surface.
- Every AI-found exploit is reviewed by a human before it reaches Dow, matching the trust level of fully human-run testing.
- Sara Continuous extends Sara AI Pentesting into a recurring model built to deliver that same standard by default.
A few years ago, Dow’s cyber engineering team made the switch from point-in-time pentesting to continuous coverage for their high-value assets. How’d they do it? By partnering with Synack. And keep in mind this was before the recent wave of AI-powered pentesting solutions. Dow was ahead of the curve.
Fast forward to today and the rest of the industry is just starting to catch up. In our latest State of Continuous Security Validation report, we surveyed security leaders to understand their approach to continuous pentesting and exploit validation. Overall, only 15% describe their pentesting programs as continuous. This is despite 95% saying they discovered high or critical vulnerabilities outside their scheduled testing windows in the past year. They know testing coverage is a problem, but haven’t made the leap yet.
Against that context, Dow’s story is even more remarkable. So interesting, in fact, that we invited Dan Lacher, Dow’s cybersecurity engineering team lead, to join our webinar with Synack CTO Mark Kuhr. If you haven’t checked it out yet, it’s worth a watch. Dan walked through why his team moved to continuous coverage and Mark explained where he sees continuous testing heading next. Here’s how they did it.
Why Did Dow Move Away From Point-in-Time Pentesting?
Dow’s relationship with Synack goes back to 2022. At the time, Dan’s internal red team had gone through starts and stops as people left the company or moved into new roles, and the security program was running point-in-time assessments instead. The team would get a report, set it aside for a while, then come back to it once a year, by which point the environment had already evolved. Dow’s e-commerce sites and other high-value web-facing assets were changing constantly as developers shipped new code, and an annual report couldn’t keep pace with that rate of change.
As Dan put it, “You’re not gonna leave your front door wide open all night.” That reasoning pushed Dow toward continuous coverage on its most valuable assets.
What Does Continuous Coverage Look Like Day to Day at Dow?
Dow has since rebuilt its internal red team, though it’s intentionally still small. Its role is to direct Synack’s scale toward the assets that matter most, since Dan’s team is the one that knows the business well enough to make that call. That division of labor extends into how Dow keeps its testing current. Engineers stand up new infrastructure constantly, an S3 bucket here, a blob storage instance there, and Dow’s team built automation that captures those new assets as they appear and feeds them to Synack in near real time, rather than waiting for the next scheduled review to catch them.
Human oversight runs through all of it. When AI agents test an asset and attempt to exploit a finding, a person still reviews the result before it reaches Dow, the same standard of validation Dow expects from fully human-run testing. That’s what let Dan’s team trust an AI-assisted process with production assets in the first place.
Is Continuous Pentesting the Norm?
Synack’s State of Continuous Security Validation report found that 42% of enterprises discover high or critical vulnerabilities outside their testing windows at least monthly, and 38% leave a quarter or more of their attack surface untested at any given moment. Only 22% currently name continuous pentesting as their primary way of confirming which findings are actually exploitable.
One CISO surveyed for the report described it well: “It simply means we operate with a constant blind spot, where new code changes run in production for days or weeks before validation.” A security architect phrased the issue similarly: “We need to either increase testers or automate testing augmented with humans.” That’s close to the exact model Dow built years ahead of the research confirming it was necessary.
The report also found that 79% of enterprises won’t act on AI-generated findings without a human validating them first, which lines up with how Dow’s team has approached AI pentesting from day one. Speed from automation only helps if someone still vouches for what the automation found.
How Does AI Enable Continuous Pentesting?
Dow was able to operate continuous pentests even before AI-powered solutions were widely available. That’s because Synack has run continuous, human-led pentests for 13 years, rotating groups of researchers onto an engagement every six to eight weeks so a program never goes stale. Looking ahead, the next evolution of continuous pentesting will involve swarms of specialized AI agents working alongside those rotating human teams. Agents will handle breadth and speed across a growing attack surface while researchers go deeper on business logic and the kind of exploit chaining AI can’t yet replicate reliably.
What Is Sara Continuous?
Sara Continuous is Synack’s answer to that trajectory. It extends Sara AI Pentesting into a recurring model for AI-led offensive testing, continuously validating the assets that matter most, confirming which findings are actually exploitable, and tracking how exposure changes over time. Dan described building near real-time asset feeds and putting a human review on every finding so testing never really stops. That’s the same standard Sara Continuous is built to deliver by default.
A continuous pentest only earns its name if security teams trust the results enough to act on them. That’s the measure Dow has held Synack to since 2022, and it’s the one Sara Continuous is designed to meet at scale. If your own testing calendar still looks more like Dow’s did in 2021, Synack is running a free trial of Sara AI Pentest right now. Request a demo to see how continuous validation fits into your program.
Related reading: Build vs. Buy AI Pentesting: Why Dow Chose to Partner With Synack • AI Can’t Fix What It Can’t Trust: Why Continuous Security Validation Matters • What GigaOm and Synack Got Right About AI Pentesting
Frequently Asked Questions
Continuous pentesting replaces a single annual or quarterly assessment with ongoing testing that tracks an environment as it changes. Instead of a report that goes stale the day it’s delivered, security teams get an updated read on which assets are exposed and which findings are actually exploitable on an ongoing basis.
Dow’s cyber engineering team found that annual and quarterly reports were already outdated by the time they arrived, since the company’s web-facing assets and e-commerce infrastructure kept changing in the interim. Starting in 2022, Dow shifted to continuous coverage on its highest-value assets specifically to solve that timing problem.
At Dow, AI agents handle the speed and scale of testing a constantly changing attack surface, while human researchers review every finding before it reaches the customer. Synack’s research found 79% of enterprises won’t act on AI-generated findings without that same kind of human validation.
Sara Continuous is Synack’s AI-led continuous pentest built for the enterprise. It extends Sara AI Pentesting into a recurring model, continuously testing high-value assets, validating exploitable risk, and tracking how exposure changes over time.
Continuous security validation is still rare. Synack’s State of Continuous Security Validation report found only 15% of enterprises describe their current validation as continuous, and just 22% name continuous pentesting as their primary way of confirming exploitable risk, even though 95% report discovering critical vulnerabilities between scheduled testing windows.


