Explore The Latest in Cybersecurity

Blog / Penetration testing: A collaborative, architecture-first approach
Layered translucent purple panels illustrating the interconnected layers of a cybersecurity architecture.

Penetration testing: A collaborative, architecture-first approach

Naunet
September 30, 2026
pentestarchitectureAIPTaaS

A traditional penetration test provides only a snapshot of an organization’s security posture, as both its operating environment and infrastructure are constantly evolving. Organizations that still treat penetration testing as an annual checklist risk overlooking vulnerabilities and exposures that emerge between assessments.

What will you learn from this article?

  • Why relying on point-in-time security testing alone can create significant blind spots

  • How human experts and AI assistants work together during a modern penetration test

  • What an architecture-first approach means in the age of cloud computing, identity and access management, and artificial intelligence

  • How the Naunet approach reconciles continuous testing with internal access controls

The changing role of point-in-time security testing

The traditional testing model is straightforward: an external team assesses the system within a defined testing window and then delivers a report detailing the vulnerabilities identified.

Point-in-time security assessments are often driven by compliance obligations, audit requirements, or client expectations. NIS2, ISO 27001, and SOC 2 set different expectations for how security controls should be assessed, so the appropriate type and frequency of testing should always be determined based on the applicable requirements and the organization’s risk profile.

The problem is not the traditional model itself. It arises when an organization relies on it as its only source of security feedback throughout the year.

A point-in-time assessment captures the organization’s security posture during a specific testing window. If the development team deploys a new service or modifies an access rule the following day, that change may remain unvalidated until the next assessment. This is why modern penetration testing is increasingly viewed not as a one-off project, but as an ongoing process. By simulating realistic attack paths and techniques, it helps organizations understand what could happen during an actual security incident.

How human experts and AI work together during a penetration test

Where AI assistants add value today

According to HackerOne’s 2025 Hacker-Powered Security Report, 70% of security researchers use some form of AI in their workflow. Yet only 12% believe that artificial intelligence could fully replace human testers. The report also found that the number of programs with AI assets in scope increased by 270% year over year.

Taken together, these figures provide a clear picture of the current landscape. AI assistants, including agentic tools integrated into Burp Suite, support testers by automating routine tasks. They can analyze minified JavaScript, identify patterns associated with known vulnerability classes, and quickly generate working proofs of concept (PoCs) for identified flaws.

Where human expertise remains essential

AI still requires human context and verification when assessing business logic flaws and multi-stage attack paths. Issues such as IDOR (Insecure Direct Object Reference, where a user gains unauthorized access to another user’s data by modifying an identifier) and attack paths created by chaining several low-severity vulnerabilities typically require creative, context-aware human analysis.

At the same time, senior testers are increasingly encoding their expertise into custom scanning templates. This allows part of their specialized knowledge to be scaled and shared across the wider security team.

Beyond technical accuracy, another important consideration is often overlooked: penetration testing findings only create value for decision-makers when they can be translated into meaningful business risk.

Why annual scoping is no longer enough

How quickly does an organization’s attack surface grow?

Palo Alto Networks’ Unit 42 research team analyzed data from 265 organizations over the course of a year for its 2024 Attack Surface Threat Report. The research found that the average organization adds more than 300 new services to its attack surface every month. It also found that more than 23% of the exposures identified affected critical IT and security infrastructure, including the administrative interfaces of routers, firewalls, VPNs, and other network devices.

If the scope of an assessment is fixed at a single point in time, any service, subdomain, or API endpoint deployed afterward may remain unvalidated until the next testing cycle.

Research by GreyNoise shows that when a new asset becomes accessible from the internet, legitimate scanning services (including attack surface management tools) typically identify it within minutes. Even slower scanners tend to discover it within a few hours. Because the study examined benign scanners rather than malicious actors, it does not directly reveal how quickly attackers respond. However, it clearly illustrates how quickly a new internet-facing asset can become discoverable.

This insight underpins the growing adoption of continuous penetration testing as an approach.

What does continuous penetration testing mean in practice?

The core idea is that external attack surface management (EASM) and traditional penetration testing should operate as integrated rather than separate, parallel processes. In a continuous testing model, the organization uses risk to determine which significant changes warrant an automated or manual security assessment.

This does not mean that every organization needs comprehensive daily testing. Instead, higher-risk changes should be reassessed much sooner than an annual testing cycle would allow.

Why an architecture-first approach matters

Attackers rarely limit themselves to a single, isolated entry point. Attack paths often extend across network and cloud layers, with the most critical risks emerging at the points where these environments intersect. Traditional port scanning alone reveals increasingly little about a cloud-native environment. The focus must therefore shift toward analyzing cloud identity and access management (IAM), platform APIs, and the trust relationships between systems.

Large language models (LLMs) introduce another, relatively new layer of risk. As they become more deeply embedded in enterprise systems, organizations must account for AI-specific vulnerability classes such as prompt injection (where manipulated input causes a model to behave in unintended ways) and jailbreaking, which involves bypassing the model’s built-in safeguards.

The OpenClaw case covered on the Naunet blog illustrates how even a useful AI assistant can become an attack surface when message processing, web access, and stored credentials converge within a single runtime environment. If an AI component supports an organization’s production workflows, its security should also be considered during the scoping phase.

Another frequently overlooked issue is the distinction between theoretical exposure and practical exploitability, commonly referred to as the validation gap. A vulnerability scanner may flag a component as potentially affected by a known vulnerability, but it cannot establish whether that vulnerability is genuinely exploitable within the organization’s specific control environment.

This is where a penetration test creates real value: it demonstrates whether a vulnerability that exists on paper can actually lead to unauthorized access or data exposure.

How the Naunet approach works in practice

The Naunet approach is based on the premise that an isolated assessment rarely provides a complete picture of an organization’s risk profile. Our team works in close partnership with the client to map their infrastructure and understand their architectural design.

We also identify risks that arise not from a single component, but from the unique ways in which different components interact.

Addressing the challenges of continuous testing

Continuous testing creates a practical challenge: organizations need regular security feedback, but internal access policies may prevent external testers from maintaining permanent VPN access to development (DEV) and user acceptance testing (UAT) environments. This can limit the use of conventional Penetration Testing as a Service (PTaaS) platforms in these environments.

Naunet addresses this challenge through continuous engagement. During a long-term partnership, we work with the client to bring different modules and system components into scope for testing over time. This allows development teams to receive regular, up-to-date security feedback without compromising internal access policies.

The findings are delivered through detailed reports. For example, you can view a sample report from a web application penetration test.

What does proactive scoping look like in practice?

During the scoping phase, our team acts as an active advisor rather than a passive executor. We help determine which components should be prioritized, what can reasonably be excluded from a particular testing cycle, and where the scope should be expanded. This ensures that the available resources are aligned with the organization’s actual risks.

For organizations accustomed to testing only a narrow area (such as a single application through a one-off assessment), this flexible approach, which can expand over time, represents a significant shift from traditional practice.

The comparison below outlines typical operating models. The exact service scope, access arrangements, and retesting terms may vary between providers.

Comparison of penetration testing models
CriterionTraditional PentestPTaaSNaunet Approach: Continuous Engagement
Testing modelTypically delivered as a time-limited projectContinuous and dashboard-basedOngoing, with prioritized modules brought into scope over time
DEV/UAT accessMay be limited or require a new agreementMay be restricted by internal VPN policiesAdapted flexibly to the client’s internal access policies
DeliverablesStatic reportLive dashboard with Jira or SDLC integrationRegularly updated feedback and detailed reports
RetestingMay require separate arrangements and additional fees, depending on the contractCan usually be initiated quickly through the platformBuilt into the long-term engagement

This model can be applied using the same underlying principles to both mid-sized companies and international corporate groups. The determining factors are not company size, but the complexity of the architecture and the pace of change.

What does this mean for decision-makers?

Penetration testing should be far more than a checkbox on a compliance list. Today, an organization’s resilience depends more on continuous feedback and context-aware testing than on the outcome of a single annual audit.

Close collaboration, a scope that can evolve as risks change, and an architecture-first approach are interconnected elements of a mature security program. These are the principles on which the Naunet approach is built.

If your organization is looking for a partner for a vulnerability assessment, a red team exercise, or compliance readiness support related to NIS2, ISO 27001, or SOC 2, request a free consultation. Together, we will identify the testing approach best suited to your systems, risks, and business needs.

Request a free consultation

Frequently asked questions about penetration testing

Can agentic penetration testing replace traditional vulnerability scanners?

In most cases, security teams need both approaches because they answer different questions. Vulnerability scanning provides broad but relatively shallow coverage of the IT environment. It identifies potential issues based on known vulnerability patterns, misconfigurations, and outdated software, but it may also generate false positives and cannot prove that a vulnerability is exploitable.

Agentic penetration testing is more targeted and typically focuses on external web applications and APIs. Rather than simply flagging potential issues, it can help plan, execute, and validate exploitation attempts, providing reproducible proofs of concept (PoCs).

Can artificial intelligence replace security experts?

Based on the current state of the technology, this appears unlikely in the foreseeable future. AI is effective at automating repetitive tasks such as code analysis and generating exploit templates. However, complex business logic flaws and multi-stage attack paths still require human judgment and contextual understanding.

How often should an organization conduct a penetration test?

There is no universal testing frequency. The appropriate schedule depends on the organization’s risk profile, rate of development, and the frequency of significant changes to its systems. In fast-changing environments, relying on a single annual test is increasingly insufficient.

What is the difference between PTaaS and a traditional penetration test?

The main differences lie in how the assessment is delivered, how the parties collaborate, and how testing is integrated into development processes. A traditional penetration test is usually a project-based assessment conducted within a fixed time window, with a static report delivered at the end. Penetration Testing as a Service (PTaaS) is a platform-based approach that typically provides a continuously updated dashboard and faster access to retesting.

What should a good penetration test report include?

A well-structured penetration test report is more than a technical write-up. It should be an actionable business and technical document that enables internal teams to begin remediation immediately. A comprehensive report should include: the scope, methodology, and testing period; an executive summary that presents the risks in business terms; validated findings ranked by severity, often using the Common Vulnerability Scoring System (CVSS); clear reproduction steps supported by evidence; practical, prioritized remediation guidance.

Explore the Latest in Cybersecurity

Stay ahead of cyber threats with insights from the Naunet blog. Our experts share their knowledge on the latest cyber defense trends, techniques, and technologies. Whether you want to deepen your understanding or apply new strategies, our blog is your go-to resource for reliable, expert-backed content in the cybersecurity domain. Join our community of professionals and elevate your security posture with every post.