Close today

Go to Top

Go to Top

Faster Automation, More Crucial Human Judgment...Gartner’s Vision for the ‘Future of Penetration Testing’
Faster Automation, More Crucial Human Judgment...Gartner’s Vision for the ‘Future of Penetration Testing’

Security Insights

Security Insights

Security Insights

Faster Automation, More Crucial Human Judgment...Gartners Vision for the Future of Penetration Testing

Faster Automation, More Crucial Human Judgment...Gartners Vision for the Future of Penetration Testing

Faster Automation, More Crucial Human Judgment...Gartners Vision for the Future of Penetration Testing

Insoon Kim

Insoon Kim

Content

Content

Content

AI & automation are shaking up the pen testing market.  

In March 2026, Gartner published 『The Future of Pen Testing Is Continuous Offensive Security Testing』. 

While focusing on continuous pen testing, security leaders must not miss another key point:  in the era of automation, define humans' role more clearly.


Why "continuous"?

Environments change too fast. Clouds deploy daily, accounts and permissions shift often, and APIs keep growing. AI-driven attacks speed this up. In this setup, annual security audits are just like snapshots of a system that no longer exists. 

Gartner points out the futility of 'annual' pentests and urges a shift to 'continuous' testing. They call this COST (Continuous Offensive Security Testing). It is structured so validation triggers automatically when new assets expose, key flaws unlock, or core controls change.



Gartner predicts that by 2028, over 60% of corporate pentesting programs will move past annual audits, running as continuous validation integrated directly inside the DevSecOps pipeline.


What the report actually stressed: Human-in-the-loop

Gartner notes automation can't solve all. The conclusion: use humans and automation together. 

Automation and AI speed up pentesting and broaden coverage. Yet, in depth, context, and creativity, expert judgment remains irreplaceable. 

This is, in fact, not a new concept. 

Companies apply this same rule when deploying AI in areas outside of security. 

Firms task AI with code deployment, billing, and customer service. Simple tasks done by humans speed up. But at critical points involving money or data, humans verify. This is called Human-in-the-loop. 

AI is used widely, but human verification is placed at key check-points. This structure cuts hallucination and catches what AI misses. 

Gartner's view on pentesting's future is the exact same structure. Lessons from deploying various AIs apply directly to pentesting.


Tools look wide, people look deep

What AI does best differs from what humans do best. They are not in competition. They simply have different roles.

Automation tools look 'broadly and often'. They scan changing assets, new endpoints, and basic vulnerabilities daily. Humans cannot do this 24/7.

Experts look 'deeply'. They find bypasses like attackers, linking scattered flaws into one path. They catch context-heavy issues like business logic or privilege abuse.

If AI warns "this door is open," a human proves "entering that door leads to the safe." Counting open doors is different from judging their real risk.

The market trend is clear: adopt broad automation, but place skilled humans at key bottlenecks. Neither do humans do all, nor is all left to machines. Designing this mix is the edge.


Why humans are needed: The trap of 'noise'

Switching to AI-powered continuous pentesting inevitably brings a challenge: a massive surge in vulnerability findings.

Gartner does not miss this point. What truly deserves remediation are the 'vulnerabilities actually exploitable in our environment.' 

Why does this matter? Most security teams are already buried under an overwhelming number of security alerts. Adding raw automated findings on top of this paralyzes the team instead of making them safer.

The numbers back this up. 

In 2025 alone, about 48,000 new CVEs were published—over 130 per day, a 20% increase from the prior year. Chasing this entire list from the start is simply impossible.

This is why 'validation' is crucial. Is it real? Is it actually exploitable in our system? If so, what is at risk and how far? Distinguishing real threats from noise is what automation does worst and humans do best. As automation drives up findings, the value of humans to filter them only rises.


One size does not fit all

Another warning from Gartner is that no single method can cover everything.

So they advise combining pentesting, control validation, red teaming, bug bounty, and attack exposure validation (AEV) as needed. Do not let tools multiply, but orchestrate them into one flow.

There is a place for humans here too: deciding which method to use on which asset and when, and translating automated findings into actual risk priorities. This is the role of the conductor leading the orchestra, and the conductor is human.

The future of penetration testing envisioned by Gartner can be summarized in one sentence.


"Monitor broadly with automation, judge deeply with humans."


This is not just about security. It perfectly mirrors the principles that every company adopting AI is learning right now. Automation is not meant to replace humans, but to help them focus on truly critical decisions.

Speed can be left to AI. Yet, faced with the questions "Is this truly dangerous?" and "What must be blocked first?", capable humans are still needed. Remember, as automation speeds up, the value of that human judgment grows rather than shrinks. 



Note: Gartner, "The Future of Pen Testing Is Continuous Offensive Security Testing" (Dhivya Poole, Carlos De Sola Caraballo, Mitchell Schneider, March 6, 2026, ID G00845606) and companion implementation report. Gartner does not endorse any vendor or product in its research publications. 

CVE statistics based on independent aggregation of public CVEs in 2025 (approx. 48,185 cases, up approx. 20% year-on-year).

Insoon Kim

Insoon Kim

Start-up College Adjunct Professor at Gachon University
Start-up College Adjunct Professor at Gachon University

Former desk member of the Electronic Newspaper ICT Convergence Department, active as a cyber security journalist and communication expert for 20 years.

Former desk member of the Electronic Newspaper ICT Convergence Department, active as a cyber security journalist and communication expert for 20 years.

The Beginning of Flawless Security System, From the Expertise of the No.1 White Hacker

Prepare Before a Security Incident Occurs

The Beginning of Flawless Security System, From the Expertise of the No.1 White Hacker

Prepare Before a Security Incident Occurs

The Beginning of Flawless Security System, From the Expertise of the No.1 White Hacker

Prepare Before a Security Incident Occurs

Subscribe

Find this content useful?
Subscribe to the Enki Letter!

Copyright © 2025. ENKI WhiteHat Co., Ltd. All rights reserved.

Copyright © 2025. ENKI WhiteHat Co., Ltd. All rights reserved.

Copyright © 2025. ENKI WhiteHat Co., Ltd. All rights reserved.