For decades, security assurance has been a largely mundane, compliance-driven and episodic exercise. Testing was triggered by the calendar, the next audit or a regulatory obligation — not by the fluidity of the threat landscape or the pace of digital transformation. Testing reports then lay on SharePoint like dead fish until the next audit, a major breach or an enforceable undertaking forced them back into view.
But tightening regulatory screws, machine-powered threats and an expanded attack surface have effectively deprecated this model. The gap between how organizations test security and how quickly their environments and adversaries evolve has become too wide to ignore. To sustain cyber resilience, testing must quickly adapt to the pace of the environments it is supposed to protect.
As I wrote in The Five Anchors of Cyber Resilience, attempting to build a cyber-resilient enterprise without modernizing technology infrastructure is akin to deploying North American Aviation P-51 Mustangs — 1940s long-range fighter-bombers — against an adversary equipped with modern F-35 Lightning IIs, with advanced stealth, supersonic speed, exceptional agility and several other superior capabilities. No matter how skilled or motivated your pilots are, you will likely be beaten.
The same principle now applies to security assurance. Cyber leaders cannot rely predominantly on periodic, heavily manual testing while adversaries increasingly use AI and automation to search continuously for weaknesses. Three decisive moves can help close that gap.
Move 1: Shift From Periodic Testing to Continuous Validation
The first move is to stop treating security assurance primarily as an event. A penetration test completed in March may provide useful evidence at that point in time, but by April a new application may have gone live, permissions changed, an API exposed or a supplier integration added. The assurance starts ageing almost immediately.
The better question is no longer, “Did we pass our latest penetration test?” It is, “Can we continuously demonstrate that our most important systems and attack paths remain resilient?” Importantly, regulators across major markets are increasingly reinforcing that direction.
- Europe: test resilience, not just compliance. DORA requires regular resilience testing of systems supporting critical or important functions, with threat-led penetration testing applying to designated organizations.
- United States: test as environments change. New York’s amended cybersecurity regulation requires annual penetration testing, risk-based vulnerability scanning and testing following material system changes, while SEC requirements have pushed cyber risk further into Board governance and disclosure.
- Australia: align testing to the threat. APRA’s CPS 234 requires systematic testing of security controls, with the nature and frequency of testing reflecting changes in threats, vulnerabilities and information assets.
The regulations use different language, but the trajectory is remarkably consistent. A point-in-time assessment is increasingly difficult to defend as sufficient evidence of resilience when technology environments and attacker capabilities are changing every day. Regulators increasingly expect organizations to demonstrate the ongoing operating effectiveness of key controls, not rely on point-in-time snapshots.
But let me be increasingly clear: Continuous validation does not mean rerunning the same penetration test every night. It means repeatedly testing the attack paths that matter most and rapidly revalidating them whenever technology, controls or threat conditions materially change.
Cyber leaders should ask:
- Can compromised credentials reach sensitive systems today?
- Can seemingly minor weaknesses be chained into a material attack path?
- Can sensitive data leave through approved cloud or SaaS services?
- Do preventive and detective controls actually interrupt the attack?
- After a material change, how quickly are affected attack paths revalidated?
The objective is simple: dramatically reduce the gap between a control becoming ineffective and the organization discovering it. That is the shift from episodic testing towards continuous assurance.
Move 2: Redesign Assurance for Co-Intelligence
The second move is to redesign assurance around co-intelligence — agentic AI operating at machine scale, with human judgement deliberately inserted where context, consequence and accountability matter most. Traditional penetration testing is constrained by human time, but simply replacing people with autonomous agents would create a different set of problems.
Agentic AI can increasingly enumerate assets, generate and test attack hypotheses, explore alternative pathways, validate vulnerabilities and continuously retest remediation. This can radically improve the breadth, frequency and economics of offensive assessment. But finding a weakness and determining whether it genuinely matters are very different capabilities.
In my experience, the greatest value of an experienced penetration tester has rarely been finding another vulnerability. It is the judgment to determine whether weaknesses can genuinely be exploited, chained together and translated into meaningful business impact. The future model should therefore combine machine-scale exploration with human judgement.
Cyber leaders should design that model deliberately:
- Let AI search at machine scale. Continuously explore attack surfaces, test hypotheses, validate controls and retest remediated weaknesses.
- Insert humans at material decision points. Validate consequential attack paths, challenge false positives and apply business context.
- Prioritize attack paths, not finding volumes. Two thousand vulnerabilities matter far less than the five combinations that could expose crown-jewel systems.
- Translate evidence into business consequence. Show what an attacker can reach, what could happen next and what management needs to do.
- Build Board communication into the model. Convert machine-generated evidence into concise executive narratives, attack-path visualizations and clear decisions.
- Keep accountability human. AI can recommend priorities, but accountable leaders remain responsible for accepting material risk and making investment decisions.
If agentic AI simply enables organizations to generate more vulnerabilities, longer reports and more technical noise, we will have automated one of the least useful features of traditional assurance. The objective is better judgment at greater scale, not simply more findings.
The strongest model will resemble an integrated offensive-security team. AI provides persistence, speed and scale; humans provide judgment, context, challenge and communication. Together, they create continuous, intelligent and decision-ready security assurance.
Move 3: Turn Technical Findings into Decisions
The third move is to radically change what security assurance produces. The output should no longer be a vulnerability report; it should be a decision-making instrument that shows leaders where the organization can genuinely be compromised, what is at stake and what needs to happen next.
Let’s illustrate this with a CISO with whom I collaborated. The CISO was receiving lengthy penetration-testing reports packed with technical findings, severity scores and remediation recommendations, but the volume of findings made it difficult to distinguish what was genuinely exploitable from what was merely theoretically severe.
Rather than treating every high-rated vulnerability as equally urgent, the CISO began sandboxing selected vulnerabilities and attack paths to test whether they could actually be exploited in practice. This created a much stronger basis for prioritization: vulnerabilities that could be chained, weaponized or used to reach sensitive systems moved rapidly to the top of the remediation queue, while lower-consequence findings were treated accordingly.
The result was a far clearer picture of what really mattered. Instead of asking technology teams to respond to a long list of severity scores, the organization could rank weaknesses by demonstrated exploitability, attack-path relevance and potential business impact.
That is the standard modern assurance should aim for:
- Prove what is genuinely exploitable. Sandbox material vulnerabilities, test whether they can actually be exploited and identify where multiple weaknesses combine into a credible attack path.
- Prioritize by business consequence. Rank findings according to what an attacker could ultimately access, disrupt, steal or manipulate — not simply by severity score.
- Close the loop with evidence. Assign remediation owners, retest the exploit after fixes are implemented and report only the material attack paths, residual exposure and decisions required.
This moves assurance from finding vulnerabilities to proving which ones matter, fixing them and demonstrating that the risk is actually reduced.
The Assurance Model Must Catch Up with the Threat Model
The traditional assurance model no longer holds. Periodic penetration tests, static reports and calendar-driven assessments were built for an environment that changed more slowly and an adversary that operated largely at human speed. That is no longer the environment cyber leaders are defending.
What is required now is a continuous, intelligence-led assurance model that tests the organization as it changes, uses agentic AI to scale adversarial assessment and applies human judgment to determine what is genuinely exploitable and materially important. Assurance must move from producing snapshots to continuously generating evidence about whether critical controls and attack paths remain resilient.
Cyber leaders should therefore make three moves now: shift from episodic testing to continuous validation, redesign assurance around AI-human co-intelligence and turn technical findings into evidence that drives decisions. The upside is greater resilience, faster risk reduction and stronger commercial outcomes — by identifying exploitable attack paths earlier, directing investment to the issues that matter most and reducing the time between exposure, remediation and proof of control effectiveness.