Key Takeaways
- Periodic penetration testing is too slow for today’s threat velocity; vulnerabilities are exploited within hours, not weeks.
- Gartner recommends a Continuous Offensive Security Testing (COST) model that validates exposures continuously, triggered by real‑time changes rather than a calendar.
- COST rests on three pillars: change‑driven validation triggers, a continuous sensing layer that correlates exposure, threat, and control data, and an orchestrated mix of testing methods (penetration testing, control validation, red teaming, bug bounty, Adversarial Exposure Validation).
- No single method can cover the entire environment; live exploitation is limited to ~10‑15% of assets, so TTP‑chain validation is needed for the rest.
- The COST loop—validate → decide → fix → re‑validate—closes the decision gap, provides auditable evidence, and integrates with existing ticketing systems.
- Picus exemplifies the COST approach by combining autonomous penetration testing, exposure validation via TTP‑chaining, and breach‑and‑attack simulation, all driven by a continuous sensing layer.
- Customers using Picus report dramatic improvements: up to 92% fewer SLA violations on high/critical flaws, 89% faster MTTR on emerging threats, 2× control effectiveness in three months, and up to a 98% reduction in critical‑ticket backlog.
- The board’s question has shifted from “Are we patched?” to “Are we secure right now, and can we prove it?”—a question only a continuous, validated loop can answer reliably.
Why periodic pentesting quietly stopped working
The traditional model—scan on a schedule, rank findings by severity, patch the worst, and assume controls remain effective—was built for slower adversaries and simpler infrastructures. Today, exploit development and deployment happen at machine speed, rendering a quarterly or annual test obsolete almost as soon as the report is finished.
The accelerating threat landscape and the Zero Day Clock
AI‑driven discovery has pushed the industry past the “Mythos threshold,” where models can autonomously find and weaponize vulnerabilities. Consequently, the window between a CVE’s public disclosure and its first exploitation has collapsed from weeks to under 10 hours on average in 2026, according to the Zero Day Clock. With roughly 49,000 new CVEs published in 2025 (about 135 per day) and fewer than 0.5% ever patched, defenders cannot keep pace with the volume or velocity of threats.
The decision gap felt by SOCs
Security operations centers see vulnerabilities pile up faster than they can remediate them. They can list what exists but lack confidence that an exploit chain would actually succeed against their specific controls. When an attack lands in minutes, there is no time to prove which defensive decision is defensible to auditors or the board, creating a persistent decision gap.
Gartner’s three legs of the COST framework
Gartner frames COST as a cyclical journey—Design, Build, Run, Improve—supported by three core elements. First, validation is triggered by change, not a calendar: risk‑tiered triggers (new internet‑exposed asset, zero‑day alert, critical control update, code commit) map to urgency and completion windows, ensuring high‑risk changes are validated within hours. Second, a continuous sensing layer provides a unified view of exposure, attack surface, threat intelligence, and control signals, separating material changes from noise. Third, because no single technique answers “is this exploitable here?” across the entire estate, organizations must orchestrate—rather than sprawl—multiple methods: penetration testing, control validation, red teaming, bug bounty, and Adversarial Exposure Validation (AEV), which blends breach‑and‑attack simulation with pentesting.
Orchestrating methods: don’t sprawl, build a loop
Simply stacking tools adds integration overhead without closing the decision gap. COST treats the methods as a single loop: validate → decide → fix → re‑validate. Autonomous penetration testing runs AI‑guided agents that chain real‑world attacks within defined guardrails, revealing what is truly exploitable and what controls stop. Exposure validation uses TTP‑chaining to prove exploitability without detonating a live exploit, covering business‑critical, restricted, and air‑gapped assets as well as brand‑day‑zero CVEs. Breach‑and‑Attack Simulation continuously stresses the prevention and detection stack against the newest techniques, catching control drift before attackers do. Findings flow directly into ticketing systems (Jira, ServiceNow) with evidence, ensuring traceability and accountability.
Where Picus fits
Picus appears in Gartner’s COST vendor matrix under Adversarial Exposure Validation (BAS plus pentesting), reflecting the framework’s vision of coordinated methods as a single engine. The Picus platform operates the full COST loop, triggered by real‑world changes in threat intelligence, asset topology, or control effectiveness—not by a schedule. When live exploitation is safe, its Autonomous Penetration Testing executes the actual attack chain; when it is not, Exposure Validation proves exploitability via TTP‑chaining, requiring no detonation. Meanwhile, its Breach‑and‑Attack Simulation continuously tests defenses against emerging techniques. The solution is open by design, ingesting assets, vulnerabilities, and business context from existing scanners, and it delivers findings as actionable tickets with attached evidence.
Measured outcomes from Picus customers
Based on Picus client data, organizations that adopt this continuous validation loop achieve: a 92% reduction in SLA violations for high‑ and critical‑severity vulnerabilities; an 89% cut in mean‑time‑to‑respond (MTTR) to emerging threats; a two‑fold increase in control effectiveness within three months; and up to a 98% shrinkage of the critical‑ticket backlog. These gains stem from closing real exploitable gaps rather than merely acquiring more tools.
The board‑level question COST answers
The executive query has evolved from “Are we patched?” to “Are we secure right now, and can we prove it?” Periodic pentests cannot answer this because their relevance expires the moment the scan ends. By making validation continuous and covering the entire environment—including untouchable assets through TTP‑chain inference—COST turns every exposure into a defensible decision. The loop provides the evidence auditors and boards demand, ensuring that security posture is not only current but also provably resilient.

