​The Case For Always-On Adversarial Exposure Validation

Direct Source Verification: This story is aggregated from Forbes (forbes.com). Full reporting rights and copyright belong to the primary publisher.
Validation should fire the same way tests fire in a CI/CD pipeline. When the environment changes, ask: What can be exploited right now?

Dr. Srinivas Mukkamala is CEO of Securin, founder of RiskSense, and an AI and cybersecurity advisor to New Mexico’s Governor.

gettyEvery penetration test report I’ve ever read was accurate the day it was written. By the time it reached the CISO’s desk, the environment had already moved. New code had shipped. A new cloud service had spun up. Somebody’s identity had been over-permissioned again. The report was a photograph of a moving target, and we keep treating the photograph like a map.

That used to be tolerable. Infrastructure changed every few months, and real exploits still took a long time to appear. Neither is true anymore. Teams push code daily. AI workloads, from models and pipelines to agents with their own credentials, appear and mutate faster than any application we used to secure. At the same time, the window between a vulnerability going public and someone actively exploiting it has collapsed. According to 2023 research, the median is roughly five days. Attackers are already using AI to automate reconnaissance and industrialize work that used to require actual people.

So, most security programs are stuck in a contradiction: defending environments that change constantly with assurance that’s still point-in-time. An annual pentest against a daily deployment cadence isn’t a control. It’s just a ritual.

The usual response is more scanning. In fact, for 20 years, we let CVSS score every vulnerability in a vacuum and prioritized by that number alone. It worked when the volume was still human-scale. It doesn’t work against AI that can generate and discover exploits faster than any team can triage by severity.

The findings themselves are incomplete anyway. My team’s research has shown popular scanners missing vulnerabilities that were already on CISA’s Known Exploited Vulnerabilities list. When we looked at real ransomware campaigns, more than three-quarters of the vulnerabilities being actively used had been public for years. Attackers aren’t just beating us with zero-days. They’re beating us with our own backlog.

Attackers don’t read finding lists. They walk paths. A critical vulnerability sitting behind three compensating controls can be noise. A handful of medium findings—a stale credential, a permissive role or an exposed service—can chain into something that hands them the crown jewels. If your program is still measuring findings while the adversary is exploiting paths, you’re keeping score in a different game.

This is why my team now asks three questions of every exposure. We call it RED:

• Reach: Can the exposure be reached?

• Defend: Can the system defend itself once it’s reached?

Reach, yes; exploit, yes; defend, no—that’s the emergency. Everything else is competing for attention it hasn’t earned.

Adversarial exposure validation (AEV) is the necessary next step. Breach-and-attack simulation, automated pentesting and continuous red teaming are already collapsing into one discipline with a single job: continuously prove what an attacker can do, safely, inside your real environment, rather than enumerate what might be wrong.

Match the validation cadence to the deployment cadence. If you ship weekly, annual testing leaves you unvalidated most of the year. Validation should fire the same way tests fire in a CI/CD pipeline. When the environment changes, ask: What can be exploited right now?

Prioritize proof over score. A validated path to a critical asset beats a thousand unexploitable criticals every time. When remediation teams get proof instead of possibility, the arguments tend to stop.

Treat AI systems as first-class attack surfaces. Models, training pipelines, vector stores and autonomous agents carry credentials, touch sensitive data and change constantly. Red-teaming them once before launch is the same mistake we made with applications two decades ago. They need standing pressure, not a pre-launch checkbox.

Keep the humans on the chains that truly matter. Automation gives you coverage. Expert operators still give you the creative jumps. The workable model is AI-scale validation with human judgment focused only on the paths the machines flag as consequential.

None of this diminishes skilled pentesters. It just moves their talent from annual compliance theater to continuous pressure, the same operating model attackers already use. Their reconnaissance is automated, always on, and indifferent to your assessment calendar.​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Original Source
https://www.forbes.com/councils/forbestechcouncil/2026/09/24/the-case-for-always-on-adversarial-exposure-validation/
Visit Forbes ↗
SHARE STORY:
𝕏 f in

Related Coverage in Business