Synack Research Finds Vulnerabilities
Synack research reveals 95% of enterprise security teams discover high or critical vulnerabilities outside scheduled tests
Recent research by Synack has found that 95% of enterprise security teams discover high or critical vulnerabilities outside scheduled tests, according to a market study of enterprise security leaders and practitioners published by the company. This finding highlights the importance of continuous security validation, as opposed to relying solely on scheduled tests. The study's results have significant implications for companies looking to protect themselves against cyber threats, and underscore the need for a more proactive approach to security. As companies like Phathom Pharmaceuticals prepare to report their financial results, they must also be mindful of the potential risks to their systems and data. The research found that 42% of enterprise security teams discovered high or critical vulnerabilities outside scheduled testing windows at least monthly, and 38% said at least one-quarter of their critical attack surface had not been independently tested or validated in the previous 90 days.
The discovery of high or critical vulnerabilities outside scheduled tests is a pressing concern, particularly in industries where intelligent transportation systems are being modernized, as is the case in New York. The potential consequences of a security breach in such systems could be severe, and companies must take steps to ensure that their security measures are robust and effective. According to Angela Heindl-Schober, Chief Marketing Officer at Synack, "Point-in-time testing is reaching its limit because the environment changes faster than a scheduled test can represent." Furthermore, Mark Kuhr, Co-Founder and Chief Technology Officer at Synack, noted that "Automation can surface more signals, but security teams need evidence, not noise." A CISO/CSO respondent to the survey described the real-world consequences of this issue, stating "It simply means we operate with a constant blind spot, where new code changes run in production for days or weeks before they are finally validated."
In light of these findings, it is essential for companies to adopt a more continuous and proactive approach to security validation, rather than relying on scheduled tests alone. The study shows strong interest in AI-assisted security testing, but not in AI operating without human judgment, with 79% of respondents stating they would not act on an AI-generated finding without human validation. Only 15% of respondents described their security testing and validation program as continuous, and the most common barriers to achieving continuous security validation centered around compliance-driven test cycles, integration complexity, lack of trust in automated findings, false positives, difficulty proving ROI, and unclear ownership across teams. This is particularly relevant in the context of recent UAP disclosures, which have raised questions about the potential risks and vulnerabilities associated with unidentified aerial phenomena. As the US government releases new UAP files, companies must be vigilant and take steps to protect themselves against potential threats. Furthermore, the issue of security vulnerabilities is not limited to the technology sector, as recent events such as the Nigeria abduction have highlighted the need for robust security measures in a variety of contexts.
Cross-reference independently — do not take our word for it.
This article is produced by NewsAnarchist's AI reporting system, not a human staff reporter. It's built from the primary source cited above (a declassified document, a FOIA release, an inspector general or congressional report, or a named whistleblower disclosure reported by outlets we cite) and reports what that source states, attributed to it — it reports what the document or disclosure states and does not speculate about what remains classified beyond that. Part of our Government Secrets hub. Found an error? Tell us.