Close today

Go to Top

Go to Top

Security Insights

Security Insights

Security Insights

The Age of Continuous Pentesting

The Age of Continuous Pentesting

The Age of Continuous Pentesting

CEO Kim In-soon

Kim In-soon

Kim In-soon

Content

Content

Content

Beyond One-time Checks, Moving to Continuous Validation

In August 2021, an attacker first gained access to SK Telecom's internal network. They subsequently installed malware on multiple servers, and SK Telecom only detected the security breach on April 18, 2025. 

According to the investigation by the government and the Personal Information Protection Commission, the attacker stayed inside for over three years to expand their foothold, eventually leaking user information externally in April 2025. 

The ultimate lesson left by this incident is clear. The timeline of attacks and the timeline of security audits no longer move at the same speed

As a result, fundamental questions about security are also changing. 

The focus is no longer on “Have we run a pentest?” but on “Are we continuously validating at the speed of attacks?” 

An annual audit is essentially a single snapshot from the past. In the meantime, systems change, external connection points multiply, and hackers discover new entry points. 

An era of continuous pentesting does not mean randomly hitting every system daily, but rather establishing a loop where validation runs continuously around core assets.


침투테스트 상시 시대에는 자동화된 도구와 함께 전문가 협업이 필요하다.

caption - In the era of continuous pentesting, automated tools and expert collaboration are both needed. (Generated by Gemini)


First, government regulations are shifting in this direction. 

In its October 2025 interagency cybersecurity plan, the government announced it will audit some 1,600 major IT systems in public, finance, and telecom sectors both simultaneously and continuously, while building a continuous assessment system leveraging mock hacking and white-hat hackers

Specifically for telecom companies, they plan to run intensive unannounced audits using real hacking methods. In July of the same year, the Financial Services Commission announced it will conduct blind mock hacking across the entire financial sector starting September as part of its plan to prevent recurrences of security incidents. This means turning audits from events into ongoing operations.

One-time penetration tests have clear limitations. 

First, they are predictable. A scheduled test performed with prior preparation can hardly reveal bypassed controls, operational errors, or privilege abuses that actual attackers exploit. 

Second, they only show a snapshot of that day. While assets, credentials, and external attack surfaces change constantly, reports only capture that brief moment. 

Third, discovery and remediation often fall short of a loop. Unless the loop of finding, fixing, and verifying vulnerabilities is continuous, security levels cannot be sustained. That is why the government introduced unannounced audits and financial regulators chose blind mock hacking. 

Global markets have already transitioned to the era of continuous penetration testing. 

Under the US CISA, the CDM (Continuous Diagnostics and Mitigation) program is, as the name implies, a framework to continuously diagnose and mitigate the security posture of federal agencies. 

In 2025, the European Central Bank updated its Threat Intelligence-Based Ethical Red Teaming (TIBER-EU) framework to align with the Threat-Led Penetration Testing (TLPT) standards defined under the EU's Digital Operational Resilience Act (DORA). 

In short, this refines systems to test financial institutions more realistically based on actual threat intelligence. The Bank of England also relies on CBEST (Critical National Infrastructure Banking Supervision and Evaluation Testing) and STAR-FS (Simulated Targeted Attack and Response for Financial Services) to ensure financial institutions test controls using realistic attack scenarios. The names vary, but the direction is identical. The focus is shifting away from annual audits to continuous validation systems aligned with real-

Regulatory Changes in Korea

Regulation/System Name

Target Audience

Key Requirements

Inspection Cycle

Pan-government Comprehensive Information Security Measures

Approx. 1,650 public/financial/communication core IT systems (approx. 1,600 in official announcements)

Immediate security checks for 288 public institutions, 152 administrative agencies, 261 financial businesses, and 949 ISMS-certified companies. Unannounced inspections of telecom carriers using actual hacking methods. Establish a continuous inspection system utilizing mock hacking drills and ethical hackers. Transition ISMS and ISMS-P to focus on field assessments, and cancel certifications in cases of material defects.

Regular + Immediate Full Inspection

Measures to Prevent Recurrence of Cyber Incidents in the Financial Sector

Entire Financial Sector

Established following the July 2025 SGI Seoul Guarantee incident. Self-inspections across all financial sectors, on-site inspections by FSS, and joint blind mock hacking drills by FSS and FSI starting from September. Strengthened inspections of ransomware responses, backup systems, and hacking defense frameworks.

Immediate implementation from September 2025

Financial Sector Blind Mock Hacking Drills

Entire Financial Sector (banks, insurers, brokerages, savings banks, mutual finance, electronic finance companies, etc.)

Surprise drills conducted without prior notice of attack times or target companies. Financial Security Institute (FSI) RED IRIS team inspects server penetration and DDoS response capabilities. Expanding across all sectors from September 4 to October 31, 2025.

2-month intensive execution as of 2025

Analysis and Evaluation of Vulnerabilities in Electronic Financial Infrastructure

178 Financial Companies (as of 2026)

Operated through comprehensive audits, independent checks, and public website evaluations. 2026 evaluation metrics expanded to 869 items across 15 fields. Extension of audit scope to mobile apps, cloud services, and websites.

Once a Year

Global Big Tech companies are already moving with continuous vulnerability validation set as their default standard. 

Since 2014, Google has run a dedicated research team called Project Zero, dedicating 100% of its researchers' time to discovering vulnerabilities and structurally improving security. In 2024 alone, Google paid nearly $12 million in rewards to over 600 researchers worldwide through its vulnerability reward programs. It also individually managed an AI-related bug bounty, receiving over 150 submissions. 

Microsoft has operated its AI Red Team since 2018. In 2025, it distributed $17 million through its bug bounty program, bolstering vulnerability hunting alongside external researchers. Moreover, via "Zero Day Quest," it concentrated on discovering high-risk vulnerabilities in cloud and AI. In its Secure Future Initiative (SFI) progress report, Microsoft revealed that it preemptively discovered and mitigated 180 new vulnerabilities through this process.

Coupled with this, AI is further accelerating the speed of cyberattacks. 

In its August 2025 Threat Intelligence Report, Anthropic disclosed that Claude Code has been used to automate reconnaissance, credential harvesting, and network penetration, and was exploited in data extortion schemes targeting various international organizations. 

The report features cases where low-skilled attackers leverages AI to develop and sell ransomware. Additionally, in its January 2026 follow-up assessment, it explained that current Claude models have improved to a level where they can successfully launch multi-stage attacks across dozens of networks using only standard open-source tools

AI is not a magic wand creating completely new hacks; it acts as an accelerator that lowers the technical barrier and speeds up the preparation and execution of attacks.

In this environment, we must shift our defensive strategy. Continuous penetration testing does not mean shaking up every system every day. 

First, we must always maintain an up-to-date understanding of high-risk assets, such as externally exposed systems, key data, authentication mechanisms, and partner integration boundaries. Over this, we must layer periodic penetration tests, blind testing, red teaming, and bug bounties. 

The most crucial final step is retesting after remediation. It shouldn't be a test that ends upon finding the issues; it must be a loop of finding, fixing, and verifying again.

Of course, in reality, not every company can build an in-house dedicated red team. To house an organization that continuously designs attack scenarios, hunts vulnerabilities, and executes re-verification like Google or Microsoft requires headcount, budget, and operational experience. Particularly for companies with small security teams, mid-sized enterprises, SMEs, and agile service operators, building such a system independently is extremely difficult.

Even so, continuous validation cannot be neglected. In these cases, a realistic alternative is leveraging external experts and Penetration Testing as a Service (PTaaS). Continuous penetration testing is completed neither by humans alone nor by tools alone.


caption - Combining Automation Tools with Human Experts (Created by Gemini)

Automated tools excel at looking broadly and checking frequently. They can quickly scan asset changes, external exposure states, basic vulnerabilities, and areas requiring repetitive verification. On the other hand, human experts excel at digging deep. They look through the eyes of an attacker to find bypass paths, chain multiple weaknesses to verify actual exploitability, and identify issues requiring context—such as business logic flaws or privilege abuse. To put it simply, tools look broad, while experts look deep. For a continuous validation system to function properly, these two must work hand in hand.

This involves conducting penetration tests with the help of experts whenever necessary, and ensuring that results are not just left as a single report but lead to repetitive checks and re-verifications. Even companies unable to maintain a large internal red team can utilize external expertise to build an operational model that mimics a continuous validation system

What matters is not the structure of your organization, but the continuity of validation. If internal capabilities are lacking, leveraging experts and services to keep the check-fix-verify loop running uninterrupted is a more realistic and effective solution.



CEO Kim In-soon

Kim In-soon

Kim In-soon

Start-up College Adjunct Professor at Gachon University
Start-up College Adjunct Professor at Gachon University

Former desk member of the Electronic Newspaper ICT Convergence Department, active as a cyber security journalist and communication expert for 20 years.

Former desk member of the Electronic Newspaper ICT Convergence Department, active as a cyber security journalist and communication expert for 20 years.

The Beginning of Flawless Security System, From the Expertise of the No.1 White Hacker

Prepare Before a Security Incident Occurs

The Beginning of Flawless Security System, From the Expertise of the No.1 White Hacker

Prepare Before a Security Incident Occurs

The Beginning of Flawless Security System, From the Expertise of the No.1 White Hacker

Prepare Before a Security Incident Occurs

Subscribe

Find this content useful?
Subscribe to the Enki Letter!

Copyright © 2025. ENKI WhiteHat Co., Ltd. All rights reserved.

Copyright © 2025. ENKI WhiteHat Co., Ltd. All rights reserved.

Copyright © 2025. ENKI WhiteHat Co., Ltd. All rights reserved.