← Technology Pulse
Cybersecurity · Managed IT

Security testing is becoming continuous—and AI-driven

A new generation of security services is moving exposure testing from periodic assessments to continuous, AI-assisted validation. The opportunity is faster discovery—but only with disciplined scope, evidence, and remediation.

Neon enterprise security network with the NXT logo embedded into the central protected server rack.
Original NXT Technology Pulse illustration: continuous exposure testing across connected enterprise systems.

From an annual test to an always-on control

On September 22, Palo Alto Networks announced Unit 42 Continuous Frontier AI Defense, an agentic offensive-security service designed to test enterprise environments as they change. The company says the service establishes a full-estate baseline and then continuously examines first- and third-party web applications, APIs, cloud infrastructure, source-code repositories, and network assets.

That is a meaningful shift in operating model. Traditional penetration tests produce a valuable point-in-time view, but applications, identities, integrations, and cloud configurations can change every day. Continuous validation tries to shorten the interval between a risky change and its discovery.

AI changes speed, not accountability

The service uses a multi-model harness that routes work across cyber-specialized frontier and open-weight models. It is designed to validate attack paths, prioritize exploitable findings, and provide code-level guidance or virtual-patch recommendations.

Palo Alto Networks reports that its earlier exposure-analysis work found issues in every one of more than 100 customer engagements, with 37% rated high or critical. Those are vendor-reported results, not an independent benchmark, but they reinforce an important lesson: consequential weaknesses often combine configuration, code, identity, and reachability rather than one known vulnerability.

Continuous testing needs firm guardrails

An always-on offensive capability should be treated as a privileged production system. Organizations need an agreed scope, protected credentials, safe-testing limits, change windows for disruptive checks, complete audit logs, and a human escalation path. Findings should enter the same ownership and service-management workflows used for incidents and material vulnerabilities.

Microsoft’s September security update points in the same direction for agentic systems: teams need visibility into agents, control over what they can reach, and Zero Trust policies for both human and on-behalf-of traffic.

A practical starting plan

Begin by identifying the crown-jewel applications, external attack surface, cloud control planes, APIs, source repositories, and identity systems that matter most. Set a baseline test, define what automated validation may and may not do, and measure three outcomes: time to validate, time to assign, and time to remediate.

The strategic point is not to automate attacks for their own sake. It is to make evidence-based exposure management continuous. Organizations that connect testing to ownership, change control, and recovery will gain more value than those that simply generate more findings.

Primary sources

  1. Palo Alto Networks — Continuous Frontier AI Defense
  2. Microsoft Security — What’s new in Microsoft Security, September 2026
Turn security findings into coordinated action.Talk with NXT Gen about managed IT, continuous exposure management, and practical remediation workflows.
Request an assessment ↗