IT Brief US - Technology news for CIOs & IT decision-makers
United States
Synack study finds major blind spots in security testing

Synack study finds major blind spots in security testing

Wed, 22nd Jul 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Synack has published research showing that 95% of enterprise security leaders and practitioners found high or critical vulnerabilities outside scheduled testing windows, highlighting a gap between fast-changing corporate systems and periodic security testing.

The study surveyed 97 security leaders, including Chief Information Security Officers, security directors, security architects, and offensive security professionals, on testing practices, attack-surface coverage, and views on AI and human expertise.

Among respondents, 42% discovered high or critical vulnerabilities outside formal testing windows at least monthly. The findings suggest many organisations rely on test cycles that do not keep pace with software changes, infrastructure updates, and shifting online exposure.

Coverage was another concern. Some 38% said at least a quarter of their critical attack surface had not been independently tested or validated in the previous 90 days, suggesting parts of key systems may go unchecked for extended periods.

The survey also found limited confidence in fully automated outputs. Nearly four in five respondents, or 79%, said they would not act on an AI-generated finding without human validation.

That reluctance sits alongside growing interest in AI tools for parts of the testing process. Respondents said AI could help scale reconnaissance, identify possible vulnerabilities, and widen testing coverage, while people remained important for confirming exploitability, judging severity, understanding business risk, and reducing false positives.

A separate gap emerged around programme maturity. Only 15% of respondents described their security testing and validation programme as continuous, even though continuous pentesting or validation was the most frequently cited method for confirming whether a finding is exploitable, at 22%.

Blind spots

The findings included a direct comment from one enterprise security executive on the practical effect of periodic testing.

"It simply means we operate with a constant blind spot, where new code changes run in production for days or weeks before they are finally validated."

Respondents identified several barriers to moving towards more continuous validation, including compliance-driven test cycles, integration complexity, lack of trust in automated findings, false positives, difficulty proving return on investment, and unclear ownership across teams.

The data adds to a broader debate in the cybersecurity market over how much work can be handed to AI systems and where human specialists remain essential. Companies across the sector have been adding AI features to scanning, detection, and testing tools, but many security teams still want evidence that a reported weakness is real, relevant, and exploitable before committing resources to fixing it.

Angela Heindl-Schober, Chief Marketing Officer at Synack, said the pace of change in enterprise environments was undermining traditional approaches. "Point-in-time testing is reaching its limit because the environment changes faster than a scheduled test can represent," she said. "The market direction is clear: AI expands coverage, humans prove exploitability, and security validation becomes continuous. The gap is not awareness. It is execution."

Synack argues that a combined model is more likely to address the shortcomings highlighted by the survey. In that approach, AI broadens the scope and frequency of testing, while human researchers assess whether weaknesses can be chained together, determine their practical impact, and explain risk to decision-makers.

Mark Kuhr, Co-Founder and Chief Technology Officer at Synack, said security teams need proof rather than a larger stream of alerts. "Automation can surface more signals, but security teams need evidence, not noise," he said. "Human researchers bring the creativity and context to chain weaknesses, confirm exploitability, and show what an attacker can actually do."

The survey suggests many large organisations still face a structural challenge: systems and code can change daily, while formal security validation often happens on a fixed timetable. That mismatch can leave newly introduced weaknesses undiscovered until after they enter live environments, a risk that becomes harder to manage as companies add more applications, cloud services, and third-party connections.

For vendors and buyers alike, the findings underline a market still in transition. AI may be gaining a larger role in finding possible issues, but the final decision on what matters appears to remain firmly with human experts. Only 15% of respondents said their current testing and validation programme is continuous.