The vast majority of enterprise security teams are being blindsided by vulnerabilities that scheduled testing never catches, according to new research from Synack, which describes itself as the provider of the first AI-powered continuous pentest for enterprises.
The company’s new report, The State of Continuous Security Validation, surveyed enterprise security leaders and practitioners and found that 95% had discovered high or critical vulnerabilities outside their scheduled testing windows within the past year. Of those, 42% said this had happened at least once a month, underscoring a widening gap between how quickly enterprise environments change and how infrequently they are actually tested.
Three connected gaps
Synack’s researchers point to three related problems undermining enterprise security assurance. The first is a coverage gap: 38% of respondents said at least a quarter of their critical attack surface had gone independently tested or validated for more than 90 days.
The second is what the report calls an AI trust gap. Despite growing enthusiasm for AI-assisted testing, 79% of respondents said they would not act on an AI-generated finding without a human validating it first.
The third is a maturity gap: only 15% of respondents described their security testing and validation programme as continuous, despite continuous testing being the most commonly cited method (named by 22%) for confirming whether a finding is actually exploitable.
One CISO who took part in the study summed up the operational impact: “It simply means we operate with a constant blind spot, where new code changes run in production for days or weeks before they are finally validated.”
AI expands coverage, but humans are still needed to prove exploitability
The research suggests enterprises are keen for AI to take on a bigger role in reconnaissance, surfacing potential vulnerabilities and expanding testing coverage, but are far less willing to let it operate without human oversight. Respondents said human expertise remains essential for validating exploitability, assessing severity and business risk, testing complex workflows, cutting down false positives, and communicating risk to stakeholders.
“Point-in-time testing is reaching its limit because the environment changes faster than a scheduled test can represent,” said Angela Heindl-Schober, Chief Marketing Officer at Synack. “The market direction is clear: AI expands coverage, humans prove exploitability, and security validation becomes continuous. The gap is not awareness. It is execution.”
The study also identifies the main barriers to continuous security validation, including compliance-driven test cycles, integration complexity, a lack of trust in automated findings, false positives, difficulty demonstrating return on investment, and unclear ownership across teams.
“Automation can surface more signals, but security teams need evidence, not noise,” said Mark Kuhr, Co-Founder and Chief Technology Officer at Synack. “Human researchers bring the creativity and context to chain weaknesses, confirm exploitability and show what an attacker can actually do.”
A Human + AI model for continuous validation
Synack argues the findings reinforce the case for a combined Human + AI approach to security validation. Its Sara AI Pentesting offering uses what the company calls the Synack Autonomous Red Agent to scale reconnaissance and testing, while the Synack Red Team, a vetted network of more than 1,500 security researchers, is used to validate real-world exploitability, uncover chained attack paths, and provide context that automation alone cannot supply.
Together, the company says, the two approaches are designed to help organisations move away from periodic, point-in-time security snapshots and towards continuous security validation.





