Continuous penetration testing must become standard, cybersecurity firm warns 

Continuous penetration testing should become standard practice for organisations as cyber threats evolve at speed, according to a senior executive at cybersecurity company Horizon3.ai. 

Tamer Odeh, Middle East and Africa Regional Lead at the firm, said companies relying on annual or infrequent penetration tests are leaving themselves exposed to growing visibility gaps in their IT security. 

His comments follow the release of the Horizon3.ai Cybersecurity Survey 2025/26, which found that while 80 per cent of organisations conduct some form of penetration testing, only 21 per cent use automated tools or platforms. Nearly half of respondents (49 per cent) said they test their systems just once a year or even less frequently. 

“You only know how resilient an IT network really is to cyberattacks if you actively put it to the test. Only penetration tests can determine whether an organization is actually protected against cyber attacks. Ideally, the networks and systems that matter most should be tested continuously-automated where possible-so boards see consistent progress rather than irregular snapshots,” Odeh said. 

The survey, which gathered responses from 150 organisations across multiple sectors, underlines the scale of the threat. Two-thirds (66 per cent) reported experiencing a cyber breach or attack in the past two years. Of those, 22 per cent faced one incident, 25 per cent reported two incidents, and 38 per cent said they had suffered three or more. 

Odeh warned that many organisations place too much confidence in their existing security tools without validating whether they work effectively in real-world conditions. 

“Many organizations rely on dozens of cyber defence tools, assuming they are fully protected against attacks. But you can’t trust that everything will work perfectly without active testing. The best way to test for risk is to safely attack yourself using the same TTPs adversaries use. That is precisely what Horizon3.ai’s Offensive Security Platform enables-revealing what is exploitable, not just what appears vulnerable,” he said. 

The cybersecurity specialist urged organisations to shift from ad hoc penetration testing to a continuous and proactive approach. He said this would help protect systems against real-world attacks, maximise returns on security investments, and provide boards with clearer evidence for compliance and regulatory reporting. 

“Human judgement still matters. Automation doesn’t completely replace experts. Instead, it removes repetitive manual tasks and ensures autonomous risk assessments can be launched consistently and at scale, showing what attackers could actually exploit,” Odeh stated. 

“With remote work, the Internet of Things, and mobile access, more devices are connecting to company networks from external locations, increasing the potential attack surface. Modern security strategies must assume that hackers will breach the outer defenses and gain initial access to a network segment, from which they can then launch internal attacks,” he explained. 

“Even a demilitarised zone (DMZ) should not be trusted by default,” he added. “With credential misuse and configuration drift driving many breaches, a DMZ must be treated as an untrusted segment—reinforced with strict access controls, continuous monitoring, and clear separation from core systems.” 

According to Horizon3.ai, continuous autonomous penetration testing allows organisations to replace assumptions with evidence by safely simulating attacker techniques to identify what can actually be exploited and to verify whether fixes remain effective over time. 

The company says its Offensive Security Platform is designed to support this approach by running attacker-like techniques in production environments, revealing viable attack paths, validating remediation efforts and tracking improvement over time. 

Odeh said frequent validation should be embedded into routine operations so that progress can be measured consistently. 

“I recommend that every board member, managing director, and IT manager across all industries subject their organization to this critical assessment — because the threat landscape is evolving far faster than traditional defences,” he added. 

Tags:
,
No Comments

Sorry, the comment form is closed at this time.

1