Synack Market Research

The State of Continuous Security Validation

What enterprise security leaders reveal about coverage gaps, AI-assisted testing, and human validation.

June 2026|Enterprise Security Leaders
Executive Summary

Security leaders at large enterprises are confident in their security testing programs. Most say mission-critical assets are almost always being tested, and that their cadence keeps pace with how fast their environments change.

However, the operational data tells a more complicated story: a coverage gap with critical assets sitting untested for months, an AI trust gap where teams won't act on an AI finding without a human behind it, and a maturity gap because only 15% validate security findings continuously today. Together, they point to a market that has agreed on where security validation is headed, but hasn't closed the distance between direction and execution.

Key Takeaways
95%
discover high or critical vulnerabilities outside their scheduled testing windows at least a few times a year
See the coverage gap
79%
would not act on an AI-generated finding without human validation behind it
See AI + human validation
15%
describe their security validation as continuous today
See market direction
01 · Confidence vs. coverage

Confidence is outpacing coverage

Ask enterprise security leaders how their testing program is doing and the answer is upbeat. Six in ten are very confident their cadence keeps up with how fast their environment changes, and most feel covered because something is almost always being tested. Yet a different picture emerges between tests.

Most Teams Feel They Are Keeping Up
Q8 · Confidence that testing cadence keeps up with the pace of change
But Critical Vulnerabilities Keep Slipping Through
Q17 · How often high/critical vulns are found outside testing windows (past 12 mo.)
42%
keep finding high or critical vulnerabilities outside their scheduled testing windows—at least once a month.
Few Have Reached Continuous Validation
Q14 · Statement that best describes current security validation maturity
Key insight

Confidence and coverage have come apart. Teams feel like they’re keeping pace because assets are always being tested. But 95% still find high or critical vulnerabilities outside scheduled windows at some point in the year, 42% find them monthly. Only 15% say they continuously validate findings.

It simply means we operate with a constant blind spot, where new code changes run in production for days or weeks before they are finally validated.
CISO / CSO · Enterprise respondent
The core problem is an imbalance between change and validation velocity.
CISO / CSO · 5,000–19,999 employees
02 · The pace problem

The environment moves faster than a point-in-time test can see

Most enterprise environments change weekly or monthly across deployments, APIs, cloud configuration, and identity. AI-generated code is already part of that churn, merging to production at least weekly for half of respondents. Against that pace, a single test is a snapshot that ages quickly.

38%
of organizations carry a quarter or more of their attack surface untested at any given moment.
Enterprise Environments Change Weekly or Faster
Q7 · How often each type of change happens in your environment
A Single Test Takes Weeks to Deliver
Q4 · Time from kickoff to final findings delivery for a typical test
Most Teams Carry an Untested Blind Spot
Q3 · Share of critical attack surface not validated in the last 90 days
Key insight

A typical penetration test or validation effort takes between 1–4 weeks to deliver findings for nearly three-quarters of teams. In environments that change weekly, that means findings often land against a version of the system that has already moved on. Most organizations carry some untested blind spot at any given moment, and for over a third (38%) it spans a quarter or more of their attack surface.

The environment can change faster than our usual testing cycles, so by the time something gets fully validated, parts of it may already be outdated or behaving differently.
VP Security / Head of Security · Enterprise respondent
03 · AI + human

AI finds more. Humans prove what matters.

Security teams are not waiting for permission to use AI. They already run AI-assisted testing and merge AI-generated code. But they’re also clear about where AI stops: 79% of security leaders would not act on an AI-generated finding as-is. Instead, they would treat it as a useful signal that still needs a human to confirm before they move on it.

AI Findings Need a Human Before Action
Q18 · How the organization would treat an unvalidated AI-generated finding
79%
would not act on an AI-generated finding until a human has confirmed it is real and exploitable.
AI for Scale, Humans for Judgment
Q19 / Q20 · Who should primarily own each activity over the next 2–3 years
Key insight

Respondents lean on AI for repetitive work that can be scaled, including testing coverage and reconnaissance. On the flipside, human creativity and judgment are critical for tasks such as validating business risk and communicating it to stakeholders. AI finds more. Humans prove what’s real and what matters.

We need to either increase the number of testers we have available, or automate our testing and augment it with humans.
Security Architect · Enterprise respondent
04 · Market direction

The market is moving to continuous—most teams are not there yet

The market has decided where it is heading. Continuous pentesting and validation was found to be the most common method to confirm whether a finding is exploitable, named by 22% of respondents. When asked to look two to three years out, leaders said they expected continuous pentesting to displace the annual point-in-time method. That 22% is a plurality rather than a majority, which is the tell. The direction is settled, but most teams have not made the move. This is also why more teams (22%) name continuous as their primary method than describe the maturity of their overall program as continuous (15%). Adopting the method is a step ahead of building the mature practice around it. Several real-world barriers, explored below, still sit between most teams and a continuous program.

Continuous Validation Is the Leading Method
Q13 · Primary method for validating whether a finding is exploitable and worth prioritizing
#1
Continuous validation is the most common primary method for confirming which findings are exploitable and worth fixing.
What Replaces the Annual Pentest
Q21 · Will replace or reduce reliance on point-in-time pentests (up to three)
A Cluster of Organizational Barriers
Q22 · Biggest barriers to moving toward continuous validation (up to three)
Key insight

No single barrier dominates. The top obstacles cluster tightly together at a similar weight, which means teams are held back by several organizational factors at once rather than one budget line. Compliance cycles that still dictate timing, lack of trust in automated findings, and too many false positives rank among the most common, alongside integration complexity, difficulty proving return, and unclear ownership across teams. These are the friction points a continuous, human-validated approach is built to address.

I would transition from point-in-time penetration testing to continuous security validation so our testing cadence actually matches our daily AI code merge and weekly deployments, eliminating our 90-day coverage gap.
Security Director · Enterprise respondent
Methodology

How this study was conducted

This study surveyed security leaders and practitioners responsible for security testing, validation, or vulnerability prioritization at mid-size and large enterprises, ranging from 1,000 to more than 50,000 employees. All percentages are calculated on the 97-respondent clean base.

97
clean enterprise responses analyzed
Jun 2026
fielded June 9 to 12, 2026
1K–50K+
employee organizations represented
Respondents by Role
S1 · Current role
Respondents by Company Size
S3 · Number of employees

Single-select questions sum to 100%. Multi-select questions, including current approaches, testing triggers, future direction, barriers, and priority metrics, allow more than one answer and therefore sum to more than 100%. The future-direction, barriers, and metrics questions asked respondents to name up to three options each.

Discover what continuous security validation looks like firsthand

Synack pairs Sara AI Pentest with a vetted community of human researchers on the Synack Red Team who confirm what is actually exploitable. Security teams get continuous coverage and proof they can act on, instead of a snapshot that ages between tests.

AI finds more. Humans prove what matters.
Research powered by