The authors question the limits of pentests and posture assessments
The authors say legacy approaches, including pentests and posture assessments, are often limited because they primarily identify theoretical risk or cannot scale. They say malicious agents can turn risk into an attack almost instantly and that a pentest is “out of date the moment it ships.”
Supporting evidence
Original excerpt
You can’t retrofit this moment. Legacy approaches – pentests and posture assessments for example – are often limited because they either primarily identify areas of theoretical risk, or because they cannot scale. But the days of theoretical risk are over. Today malicious agents can turn a risk hot-spot into a real-world attack almost instantly. That pentest is out of date the moment it ships.
Context
Defenders today need a platform that can outpace weaponized AI, finding, demonstrating, validating, and remediating exploit paths before a malicious agent can actually exploit them.