Organizations that found high/critical flaws outside a scheduled test window: 95% (past 12 months) (Source: Synack, State of Continuous Security Validation report (July 2026), via Help Net Security (July 22, 2026))
The Assessment Window Problem
Synack's State of Continuous Security Validation report, covered by Help Net Security on July 22, 2026, documents a structural gap in how enterprises test their own defenses: the assessment ends, but the environment keeps changing. Ninety-five percent of surveyed organizations reported discovering a high- or critical-severity vulnerability outside a scheduled testing window at some point in the past year. Point-in-time penetration tests and audits — the model most compliance frameworks still assume — capture a single moment. Anything that shifts afterward, from a new plugin install to a reconfigured endpoint, goes unverified until the next cycle opens.
Confidence Outpaces Practice
The report also shows a gap between how security leaders describe their programs and how those programs actually run. Eighty-three percent said their testing cadence keeps pace with how fast their environment changes. Only 15% describe their program as genuinely continuous. Forty-two percent said they encounter high- or critical-severity flaws outside a testing window at least once a month — a recurring pattern within the surveyed group, not an annual surprise.
Attack Surface Left Unwatched
The exposure is not spread evenly. Thirty-eight percent of respondents said at least a quarter of their critical attack surface had gone without independent testing or validation in the preceding 90 days. For infrastructure exposed to public traffic — the layer WebPulse scans continuously across detected frameworks — that is a 90-day window in which a new content plugin, an exposed admin panel, or an unpatched dependency can sit live and unverified between one scheduled assessment and the next.
What Asset Visibility Adds
WebPulse doesn't test for vulnerabilities — it tracks which frameworks are running where, continuously. That's a narrower problem than what Synack measures, but it's the precondition: you can't validate what you haven't inventoried. The platform has detected frameworks on more than 466,000 sites across over 100 top-level domains (detection is signature-based and skews toward frameworks with strong HTML fingerprints; undetected sites are not counted). That asset-visibility layer matters because the exploited-vulnerability landscape itself does not move in fixed cycles — the CISA Known Exploited Vulnerabilities catalog stood at 1,300+ entries as of July 2026, a list that grows continuously as new exploitation is confirmed. Remediation deadlines attached to KEV entries apply to U.S. federal agencies under Binding Operational Directive 22-01, not to enterprises generally — but the catalog's ongoing growth illustrates a parallel dynamic to the assessment drift the Synack survey measures.
None of this points to a single fix. It describes a measurement gap: point-in-time testing answers whether an environment was secure on the day it was checked, while the question budget-holders actually need answered is closer to whether it is secure now. Synack's data suggests most surveyed programs are still built to answer the first question.


