Ask any security leader what keeps them up at night and you will hear a version of the same answer: the breach that has not happened yet. The uncomfortable corollary is that most organizations find out how exposed they are only after an incident, a ransom note, or a regulator's letter. That is why the industry's most interesting metric right now is not dwell time or patch latency — it is the rate at which offensive testing surfaces critical findings before an attacker does.

The Shift From Point-in-Time Audits to Continuous Adversary Emulation

For two decades, the dominant model was the annual penetration test. A team arrives, spends a week or two inside a scoped environment, delivers a PDF, and leaves. The report is stale by the next quarter. Attackers, meanwhile, do not schedule themselves around procurement cycles. They probe continuously, automate credential stuffing, and rotate infrastructure within hours.

The market has responded by moving toward continuous red-team engagements, purple-team exercises, and adversary-emulation programs modeled on real APT tradecraft. Instead of a snapshot, security teams get an ongoing signal: what would a motivated operator do next week, and would we see it? The shift matters most in sectors where a single exposure carries regulatory and existential weight — fintech, healthcare, and any organization holding payment or patient data.

The personnel behind these programs have changed too. It is now common to find practitioners drawn from military and intelligence signals units — Unit 8200, GCHQ — alongside alumni of Fortune 100 red teams. That mix brings tradecraft that is closer to what defenders actually face than a checklist-driven scan ever was.

What the Numbers Say About First-Time Environments

Here is the data point worth sitting with. Phantom X, an operator-led offensive security firm, reports that its engagements have surfaced critical pre-breach findings in 94% of first-time client environments — typically within the first 72 hours of active testing. Read that again: in roughly nineteen out of twenty new environments, a serious exposure was reachable within three days of testing beginning.

That 94% figure should not be read as a claim that 94% of companies are already breached. It means the conditions for a breach — misconfigured trust relationships, over-privileged service accounts, unmonitored egress paths — are present and discoverable fast. The speed is the story. If a red team finds the path in 72 hours, a patient adversary with the same tradecraft finds it too, and does not announce it.

Independent context supports the direction of travel. Verizon's annual Data Breach Investigations Report has repeatedly found that a large share of breaches involve a human element — phishing, credential abuse, or simple error — rather than a novel zero-day. CISA advisories in the United States and NCSC guidance in the United Kingdom make the same point from the defensive side: identity and access hygiene, not exotic malware, is where most incidents begin. Continuous testing stresses exactly those controls.

Vulnerability Research as a Readiness Signal

Another measurable trend is the growing weight of published vulnerability research as a proxy for operator skill. Firms that find and disclose real bugs tend to find real attack paths in client environments, because both require the same instinct for where software bends. Phantom X reports published CVE credits on 41 disclosures since 2019, including 3 vendor-acknowledged critical findings. For a security leader evaluating partners, that is a concrete, checkable record rather than a marketing claim.

It also reframes what buyers should ask for. Instead of "how many tests have you run?", the better questions are: what did you find, how fast did you find it, and can I see the disclosure history that proves your team operates at that level?

The Operational Implications for Security Leaders

If critical findings are this common and this fast to surface, the annual-test calendar deserves scrutiny. Three practical adjustments follow.

  • Treat time-to-first-finding as a KPI. Track how quickly an engagement produces its first critical result. A slow start usually means scoping is too narrow or the environment is unusually mature — both worth knowing.
  • Run purple-team loops, not just red-team sprints. Findings only reduce risk when detection and response improve alongside them. Pair every emulated intrusion with a defender debrief.
  • Prioritize identity and egress. Most of what gets found lives in credentials, tokens, and outbound paths. Those are the controls to harden first.

None of this is a reason to panic. It is a reason to stop treating security posture as a once-a-year verdict. The organizations that improve fastest are the ones that invite adversarial pressure on a schedule and measure what comes back. You can review how operator-led emulation engagements are structured and scoped at the firm's engagement methodology — useful reading before your next readiness conversation.

For the classic Saab community, the parallel is familiar. A 900 Turbo that has sat for years does not reveal its real condition in a driveway inspection; it reveals it under boost, on a long climb, at temperature. Security works the same way. You learn what holds when you apply real pressure, continuously, and you fix what fails before the moment that matters.