Most security programs still work on a yearly cycle: run a pentest, fix the critical findings, write the report, and then come back to it twelve months later.
That approach made more sense when infrastructure changed slowly enough for a yearly snapshot to remain useful.
Changes happen fast in this era.
New vulnerabilities can be exploited incredibly quickly, sometimes before organizations even have a patch available. In other words, by the time a traditional security test finds a problem, attackers may already be trying to exploit it.
The two real breaches below show what can slip through that gap, and what organizations are starting to do instead of relying only on an annual security test.
- Organizations in the top 10% for continuous pentesting remediate high-risk findings in a 10-day half-life, compared with 249 days for the bottom 10%, according to Cobalt's 2026 State of Pentesting Report. That's a 25x difference, and it comes down almost entirely to cadence.
- 78% of organizations run applications with critical vulnerable dependencies in production, according to Orca Security's 2026 State of Application Security Report. Discovery alone does not ensure that risk is prioritized and remediated.
Case studies
Two breaches, seven years apart, but the problem was basically the same: the weakness was there, and nobody found it before the attacker did.
Equifax: the scan that didn't find what everyone already knew about
In March 2017, a critical remote code execution flaw in Apache Struts (CVE-2017-5638) was publicly disclosed, along with a patch. Equifax ran the framework across multiple consumer-facing applications. The chain of failures:
- Equifax's internal security team circulated the patch notice to the relevant application owners within days of disclosure, as later testimony to Congress confirmed.
- The patch didn't get applied to the affected system. Equifax's own post-incident account pointed to a breakdown in the internal process for tracking which team owned which patch, not a lack of awareness that a fix existed.
- A vulnerability scan run shortly afterward was supposed to catch anything that had slipped through. It didn't flag the vulnerable Struts installation, because the scan wasn't configured to check the specific directory where the vulnerable software lived.
- Attackers found the same unpatched flaw independently and got in on May 13, 2017, more than a month after the patch was public.
- Nobody noticed for 76 days. Attackers had that entire window to move through internal systems and pull data on 147 million people before Equifax detected the intrusion at the end of July.
The patch was available, and the scan was run. But neither one actually fixed the problem.
A scan is useless if it's checking the wrong place. And getting a patch notification isn't the same as actually installing the patch and checking that it worked.
Equifax eventually agreed to pay up to $425 million to settle with the FTC. But the technical problem behind the breach was simple enough to explain in one sentence — and it was known months before the settlement.
Change Healthcare: one exception to a policy that otherwise worked
UnitedHealth Group had a clear policy: every system exposed to the internet was supposed to use multi-factor authentication (MFA). Change Healthcare, one of its subsidiaries, was an exception that nobody caught.
The failures happened in a simple chain:
- On February 12, 2024, attackers used stolen credentials to log into a Change Healthcare Citrix portal for remote access. The portal didn't have MFA enabled, even though company policy required it.
- When CEO Andrew Witty later testified before Congress, he said the company still didn't know exactly why that server wasn't covered by the MFA policy. It was simply missed.
- Because the attackers had valid credentials and there was no MFA to stop them, they stayed inside the network for nine days without being detected.
- They stole data belonging to approximately 190 million people, according to UnitedHealth's updated estimate, before deploying ransomware on February 21. The company's earlier estimate was about 100 million.
- The attack disrupted healthcare claims and payments across the US for more than a month. UnitedHealth paid the attackers $22 million, while the wider recovery and remediation costs eventually reached billions.
The bigger lesson is simple: having a security policy doesn't mean the policy is actually being followed. UnitedHealth had the right rule. What it was missing was a way to continuously check that every system was following it. That's the kind of gap an annual security assessment can easily miss. If a system isn't on the list, it may never get checked in the first place.
The incident shows why organizations should extend periodic testing into a continuous cycle of discovery, prioritization, validation, remediation, and retesting.
What replaces the annual test
Gartner calls this Continuous Threat Exposure Management (CTEM). It isn't a product you buy. It's a five-step process that runs continuously instead of once a year.
The idea is simple: keep looking for security gaps, fix them, and check again.
It's designed to catch the problems that were missed in both cases above.
Walking through what each stage would have actually done in the two cases above:
1. Start with what matters most CTEM starts by looking at the systems that matter most to the business, rather than relying on a fixed list that gets updated once a year.
A Citrix portal providing access to a system that handles billions of healthcare transactions should have been treated as a critical asset from the start. It shouldn't have had to wait until the next annual assessment to be included.
2. Keep finding problems CTEM isn't just about scanning for known vulnerabilities. It also looks for things like bad configurations, access problems, and security policies that aren't actually being followed.
That could have caught the missing MFA on the Change Healthcare portal. It could also have caught the Equifax issue, where the scanner wasn't checking the right place.
3. Focus on what attackers can actually reach Not every vulnerability creates the same level of risk. CTEM looks at how easy something is to exploit and what an attacker could reach if they got in.
This means a lower-severity issue on an exposed, important system may deserve attention before a higher-scoring issue that isn't reachable from outside.
4. Test it like an attacker would This is where you go beyond the checklist.
Instead of simply saying, "MFA is configured" or "this vulnerability exists," you safely test whether an attacker could actually use the weakness and reach something important.
Both breaches had gaps that a real validation test could have exposed before an attacker did.
5. Fix it and make someone responsible Finding a problem doesn't help if it just sits in a ticket queue.
Every finding needs a clear owner, a deadline, and a way to confirm that the fix actually worked. The goal is to get the problem from "we found it" to "it's fixed and we've verified the fix."
That's the main difference between an annual test and continuous exposure management: you don't just find problems once a year. You keep finding, fixing, and checking them.
A short list of what to check as you move toward this model:
- Your scope includes every internet-facing asset, refreshed automatically, not from a spreadsheet someone updates once a year
- Discovery covers misconfigurations and policy violations, not only known CVEs
- Findings are ranked by real-world exploitability (EPSS or equivalent) alongside business impact, not CVSS alone
- High-risk findings get an actual validation attempt before they're prioritized, not after
- Every finding has a named owner and a remediation deadline tracked against actual closure, not ticket status
- Critical assets are retested after every significant change, not just on the annual calendar
- You can answer, today, whether every policy (MFA, encryption, segmentation) is actually enforced everywhere it's supposed to be, not just where it was checked last time
The bottom line
So, is annual testing still enough? On its own, no.
Annual testing was never meant to answer the question security teams need to answer every day: “Do we have an exploitable weakness right now?” It only tells you what was found on the day the test happened.
Equifax had a patch and ran scans, but still missed the vulnerability because the scan was looking in the wrong place. Change Healthcare had an MFA policy, but nobody checked that every server was actually following it.
In both cases, the problem wasn't that the companies had the wrong security controls. The problem was that nobody kept checking whether those controls were actually working.
That's the reason to include CTEM for VAPT. Annual testing still has value, but it's only a snapshot. When your environment changes every week and attackers move quickly, you need security checks that keep running.
The goal isn't to test more just for the sake of testing. It's to reduce the time between “we think we're protected” and “we've checked, and we know we're protected.”
Sources
- Mandiant reports that mean time to exploit reached an estimated −7 days in 2025, meaning exploitation often precedes patch availability. See M-Trends 2026.
- Cobalt's 2026 report compares high-risk finding remediation half-lives of 10 days for the top 10% and 249 days for the bottom 10%, using data from more than 16,500 pentests across nearly 3,000 organizations. See the State of Pentesting Report 2026.
- Orca's 2026 report found 78% of organizations run applications with critical vulnerable dependencies in production. See the State of Application Security Report.
- The Equifax investigation found that a later security scan covered only part of the system and missed the unpatched Apache Struts flaw. See the U.S. Senate Committee investigation.
- UnitedHealth's updated estimate for the Change Healthcare breach was approximately 190 million people, up from its earlier estimate of about 100 million. See TechCrunch's report. The February 2024 intrusion involved stolen credentials and a remote access portal without MFA, as described in CEO Andrew Witty's congressional testimony.
- Gartner's Continuous Threat Exposure Management framework describes five stages: Scope, Discover, Prioritize, Validate, and Mobilize. See Use Continuous Threat Exposure Management to Reduce Cyberattacks.
