Enterprise security teams are consistently missing critical vulnerabilities because their testing schedules cannot keep pace with how rapidly their environments change, according to new research from Synack. The company's State of Continuous Security Validation report found that 95% of surveyed security leaders discovered high or critical vulnerabilities outside their scheduled testing windows within the past year, with 42% reporting this happening at least once per month.
The research identifies three interconnected problems undermining security assurance programs. First, a coverage gap exists where 38% of respondents admitted at least a quarter of their critical attack surface went untested for more than 90 days. Second, an AI trust gap persists, with 79% of security teams refusing to act on AI-generated findings without human validation. Third, a maturity gap shows only 15% of organizations have implemented continuous testing programs, despite continuous testing being the most commonly cited method for confirming exploitability.
While enterprises show enthusiasm for AI-assisted security testing to expand coverage and surface potential vulnerabilities, they remain unwilling to let it operate autonomously. Survey respondents indicated human expertise remains essential for validating exploitability, assessing severity and business risk, testing complex workflows, reducing false positives, and communicating risk to stakeholders. One participating CISO noted that current approaches mean organizations operate with a constant blind spot where new code changes run in production for days or weeks before validation.
The main barriers preventing continuous security validation include compliance-driven test cycles, integration complexity, lack of trust in automated findings, false positive rates, difficulty demonstrating return on investment, and unclear ownership across teams. Mark Kuhr, Synack's Co-Founder and CTO, emphasized that while automation can surface more signals, security teams need evidence rather than noise, with human researchers providing the creativity and context to chain weaknesses and confirm what attackers can actually accomplish.
Security teams should evaluate their current testing cadence against the rate of change in their environments and consider hybrid approaches that combine AI-powered reconnaissance with human validation. Organizations should assess whether critical assets are being tested frequently enough, establish clear processes for validating automated findings, and work toward continuous validation models that can keep pace with modern development cycles rather than relying solely on periodic point-in-time assessments.
Source: https://www.itsecurityguru.org/2026/07/21/95-of-security-teams-blindsided-by-vulnerabilities-between-tests/?utm_source=rss&utm_medium=rss&utm_campaign=95-of-security-teams-blindsided-by-vulnerabilities-between-tests


