The State of Continuous Security Validation
What enterprise security leaders reveal about coverage gaps, AI-assisted testing, and human validation.
Security leaders at large enterprises are confident in their security testing programs. Most say mission-critical assets are almost always being tested, and that their cadence keeps pace with how fast their environments change.
However, the operational data tells a more complicated story: a coverage gap with critical assets sitting untested for months, an AI trust gap where teams won't act on an AI finding without a human behind it, and a maturity gap because only 15% validate security findings continuously today. Together, they point to a market that has agreed on where security validation is headed, but hasn't closed the distance between direction and execution.
Confidence is outpacing coverage
Ask enterprise security leaders how their testing program is doing and the answer is upbeat. Six in ten are very confident their cadence keeps up with how fast their environment changes, and most feel covered because something is almost always being tested. Yet a different picture emerges between tests.
Confidence and coverage have come apart. Teams feel like they’re keeping pace because assets are always being tested. But 95% still find high or critical vulnerabilities outside scheduled windows at some point in the year, 42% find them monthly. Only 15% say they continuously validate findings.
It simply means we operate with a constant blind spot, where new code changes run in production for days or weeks before they are finally validated.
The core problem is an imbalance between change and validation velocity.
The environment moves faster than a point-in-time test can see
Most enterprise environments change weekly or monthly across deployments, APIs, cloud configuration, and identity. AI-generated code is already part of that churn, merging to production at least weekly for half of respondents. Against that pace, a single test is a snapshot that ages quickly.
A typical penetration test or validation effort takes between 1–4 weeks to deliver findings for nearly three-quarters of teams. In environments that change weekly, that means findings often land against a version of the system that has already moved on. Most organizations carry some untested blind spot at any given moment, and for over a third (38%) it spans a quarter or more of their attack surface.
The environment can change faster than our usual testing cycles, so by the time something gets fully validated, parts of it may already be outdated or behaving differently.
AI finds more. Humans prove what matters.
Security teams are not waiting for permission to use AI. They already run AI-assisted testing and merge AI-generated code. But they’re also clear about where AI stops: 79% of security leaders would not act on an AI-generated finding as-is. Instead, they would treat it as a useful signal that still needs a human to confirm before they move on it.
Respondents lean on AI for repetitive work that can be scaled, including testing coverage and reconnaissance. On the flipside, human creativity and judgment are critical for tasks such as validating business risk and communicating it to stakeholders. AI finds more. Humans prove what’s real and what matters.
We need to either increase the number of testers we have available, or automate our testing and augment it with humans.
The market is moving to continuous—most teams are not there yet
The market has decided where it is heading. Continuous pentesting and validation was found to be the most common method to confirm whether a finding is exploitable, named by 22% of respondents. When asked to look two to three years out, leaders said they expected continuous pentesting to displace the annual point-in-time method. That 22% is a plurality rather than a majority, which is the tell. The direction is settled, but most teams have not made the move. This is also why more teams (22%) name continuous as their primary method than describe the maturity of their overall program as continuous (15%). Adopting the method is a step ahead of building the mature practice around it. Several real-world barriers, explored below, still sit between most teams and a continuous program.
No single barrier dominates. The top obstacles cluster tightly together at a similar weight, which means teams are held back by several organizational factors at once rather than one budget line. Compliance cycles that still dictate timing, lack of trust in automated findings, and too many false positives rank among the most common, alongside integration complexity, difficulty proving return, and unclear ownership across teams. These are the friction points a continuous, human-validated approach is built to address.
I would transition from point-in-time penetration testing to continuous security validation so our testing cadence actually matches our daily AI code merge and weekly deployments, eliminating our 90-day coverage gap.
How this study was conducted
This study surveyed security leaders and practitioners responsible for security testing, validation, or vulnerability prioritization at mid-size and large enterprises, ranging from 1,000 to more than 50,000 employees. All percentages are calculated on the 97-respondent clean base.
Single-select questions sum to 100%. Multi-select questions, including current approaches, testing triggers, future direction, barriers, and priority metrics, allow more than one answer and therefore sum to more than 100%. The future-direction, barriers, and metrics questions asked respondents to name up to three options each.
Discover what continuous security validation looks like firsthand
Synack pairs Sara AI Pentest with a vetted community of human researchers on the Synack Red Team who confirm what is actually exploitable. Security teams get continuous coverage and proof they can act on, instead of a snapshot that ages between tests.


