Blog

AI-Driven exploits: Rethink pen testing & vulnerability remediation

For security teams in Canada, threat and vulnerability pressures are the same as they’ve always been: Not enough people. Not enough time. What’s changed in the AI era is the speed at which new vulnerabilities emerge.

Using frontier AI models, attackers can find exploitable vulnerabilities at a speed that far eclipses traditional security processes. Security researchers used to spend hundreds of days finding a new exploit; that same discovery process can now occur in a matter of hours.

So, while the distance between finding and fixing a vulnerability hasn’t changed, the rate at which potential exposures arrive has accelerated dramatically.

Why current vulnerability remediation can’t keep up

Most organizations still work on a patching cadence that’s measured in weeks. In fact, it’s common for a month to pass between identifying a vulnerability and applying a fix.

Part of the delay sits outside any single organization’s control. Before most security teams treat a vulnerability as broadly recognized and actionable, it will typically be assigned a Common Vulnerabilities and Exposures (CVE) identifier. Vulnerabilities are submitted through the CVE Program and its network of authorized CVE Numbering Authorities (CNAs), where they are reviewed and assigned a standardized CVE record. Once published, resources such as NIST’s National Vulnerability Database (NVD) can provide additional vulnerability information, while the Common Vulnerability Scoring System (CVSS) provides a standardized method for assessing vulnerability severity.

Both steps take time, and both happen well after the underlying flaw was first identified.

Lows and mediums deserve a second look

Security teams have traditionally been triaged by severity. The rule of thumb was to fix critical and highs first, tackling mediums and lows when time allowed and team capacity is available.  

That approach assumed that each vulnerability stands alone. Unfortunately, frontier AI models are effective at daisy chaining several low or medium severity vulnerabilities into one functioning exploit, chaining together smaller issues into something with real impact.

In other words, a vulnerability near the bottom of your priority list could already be part of a working exploit path today. Prioritizing based purely on individual CVSS scores misses these combinations.

Automated penetration testing: Machine defence for machine attacks

Continuous, automated penetration testing addresses this directly. Rather than an annual or quarterly point-in-time test, it runs on an ongoing basis. And it answers three questions for each finding:

  • Does an exposure exist?

  • If so, how severe?

  • And the biggest one: Can it be exploited in your specific environment?

Automation offers the flexibility to conduct penetration testing at a cadence that matches your risk of tolerance. Running tests weekly or even daily doesn’t add system cost. Depending on how closely you want to track your exposure, human-validated reporting can be delivered monthly or quarterly.

Automated penetration testing also surfaces configuration issues that traditional vulnerability scanning can miss entirely. Those problems may never receive a CVE because the flaw is in the setup rather than the software itself.

Find, fix, verify, repeat

Applying a patch or changing a configuration doesn’t guarantee the underlying problem is resolved. Confirming that a fix worked, through rescanning and retesting the environment; closes the loop.

This is another advantage of penetration testing as a service if your mid-market security team is already stretched thin. Thanks to regular reporting, last month’s findings become this month’s confirmation, giving your ongoing visibility into issues that persist or resurface over time.

What continuous pen testing replaces (and what it doesn’t)

Continuous automated testing isn’t a substitute for an annual, human-led pen test. In Canada, that requirement shows up in OSFI B-13 for federally regulated financial institutions and in ITSG-33 for departments handling Protected B information, on top of global frameworks like PCI DSS that don’t change at the border. That isn’t likely to change soon.

What continuous testing does is make the annual test much less eventful. If you’ve tracked your exposure all year, you should already know what the assessor is going to find.

The harder part is remediation. Patching, configuration changes, and other ongoing fixes require resources many security teams don’t have in-house. If you pair automated penetration testing with the professional services to act on the results, you’re better positioned to keep pace with an onslaught of emerging vulnerabilities.

AI security best practices: Where to start

If your team is short on time and resources, a Cybersecurity Maturity Assessment focused on your Continuous Threat Exposure Management (CTEM) posture is a reasonable starting point. This assessment yields an honest look at your current cadence for vulnerability management, patch management, and penetration testing. It also delivers a review of your change management and incident response capabilities.

To learn more about automated penetration testing or to schedule a CTEM posture assessment, talk with an OnX security specialist about where your environment stands.