Scheduled scans

Recurring full-depth scans on a cadence you set, available from the Professional plan.

EASM re-checks

Agentless continuous monitoring re-checks the external perimeter between scheduled scans, with real-time alerts (Enterprise).

7-day re-verification

Every asset in the inventory is re-verified on a 7-day cycle, so scope always reflects what is actually live.

Drift detection

A full change ledger records new hosts, missing hosts and unauthorised changes across the estate.

Exploit validation

Findings are validated with safe, RoE-gated exploitation, so alerts carry proof, not guesswork.

Posture over time

Scan comparison shows what changed between runs: fixed findings, new findings and recurring ones.

What is continuous penetration testing?

Continuous penetration testing is the practice of testing an environment on an ongoing schedule rather than once a year. Discovery, scanning, exploitation and reporting run repeatedly, with lighter re-checks between the deeper runs, so newly deployed services, configuration drift and freshly published vulnerabilities are found close to when they appear.

It suits any organisation whose estate changes faster than its testing cycle: teams shipping weekly, cloud-first businesses where accounts and workloads appear outside procurement, and security functions asked to show a current position rather than a report dated months ago. It is normally adopted alongside a periodic human-led engagement rather than instead of one. On PentestOps it is delivered through scheduled scans, agentless perimeter re-checks and a 7-day asset re-verification cycle with drift detection.

The problem with point-in-time penetration testing

The traditional model is a fixed engagement: scope in advance, test for a window, receive a report. It works, but it describes a moment. The day after the window closes, teams keep deploying, cloud accounts keep changing, and new CVEs keep landing against services that passed the test.

A vulnerability introduced the week after an annual pentest can sit exposed for months before anyone qualified looks at that system again. For estates that change daily, the gap between tests is the real finding.

Continuous penetration testing closes that gap. Instead of a single snapshot, the platform maintains a live picture of your assets and keeps testing them on a schedule, with lighter re-checks running between full scans. For a vendor-neutral primer, read what continuous penetration testing is.

Point-in-time vs continuous validation

The difference is not scan frequency alone. It is what happens between scans, and whether findings are validated or merely detected.

DimensionPoint-in-time pentestContinuous penetration testing
Coverage windowA fixed test window, typically annualAlways on: scheduled scans plus re-checks between them
New assetsSeen only if they existed at scoping timeInventory re-verified on a 7-day cycle with drift detection
RegressionsMissed until the next engagementScan comparison flags new and recurring findings each run
Perimeter changeInvisible between engagementsAgentless EASM re-checks with real-time alerts (Enterprise)
Stakeholder evidenceOne report that ages quicklyCurrent findings with evidence, exported as PDF, CSV or JSON/API
Cost modelQuoted per engagementAsset-wise pricing, scans unlimited within fair use

How continuous testing works on PentestOps

PentestOps layers four mechanisms so coverage never falls back to zero between engagements.

  • A live asset inventory. AI classification with criticality, bulk CSV/XLSX import, cloud sync across AWS, Azure, GCP and M365, and multi-method LAN discovery through the on-premise agent.
  • 7-day re-verification and drift detection. Every asset is re-verified on a 7-day cycle, and a full change ledger records what appeared, changed or disappeared.
  • Scheduled scans. Recurring full-depth scans on the cadence you choose, with Stealth, Balanced or Aggressive profiles, following the same 7-phase methodology as a one-off engagement.
  • Continuous monitoring (EASM). Agentless external attack surface management re-checks the perimeter between scheduled scans, with HMAC-signed log shipping and real-time threat alerts.

One pipeline for every layer

Findings from every layer flow into the same pipeline: CVSS v3.1 scoring, exploit-availability indicators, CISA KEV prioritisation, and safe, RoE-gated exploitation to prove which exposures are actually exploitable.

Always-on inside the network too

Continuous coverage cannot stop at the perimeter. The on-premise agent provides 24/7 continuous monitoring inside the network: asset inventory, drift detection and unauthorised-change alerts on a schedule, plus internal scanning that runs natively on the LAN instead of tunnelling every packet out to a remote scanner.

Deployment takes about 5 minutes, requires 0 inbound firewall rules, and connects outbound-only over TLS 443. The agent ships as Docker, RPM or DEB, and one host can cover multiple subnets.

Continuous does not mean noisy

The usual objection to always-on testing is alert fatigue. PentestOps addresses it three ways: false-positive reduction before findings reach your queue, prioritisation by CVSS v3.1 severity, exploit availability and CISA KEV listing, and safe exploitation that separates proven attack paths from theoretical risk.

Scan comparison then shows the delta between runs: what was fixed, what is new and what keeps recurring, so your team reviews changes instead of re-reading the same report.

Where continuous fits alongside annual engagements

Continuous testing is not an argument for cancelling your human-led pentest. It is the coverage layer between those engagements. Automation runs the repetitive, high-volume work continuously; human testers focus on the creative work that automation handles poorly, and arrive with a current, validated picture of the estate instead of a stale scoping document. Many compliance regimes still expect a periodic formal test, and continuous validation strengthens that evidence rather than replacing it.

Why PentestOps

  • Asset-wise pricing with unlimited scans within fair use: a continuous cadence does not multiply your bill, because you pay for assets in scope, not scan counts.
  • Findings map to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes, so evidence stays current between audits.
  • Safe, RoE-gated exploitation validates findings instead of only detecting them: proof, not guesswork.
  • Scheduled scans and scan comparison are available from the Professional plan; continuous monitoring (EASM) and advanced exploitation are Enterprise capabilities.
  • Australian-built and operated. The platform is hosted in Australia, customer data is stored in Australia, and Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified.

Frequently Asked Questions

What is continuous penetration testing?

A programme that keeps validating your environment between formal engagements instead of testing once a year. On PentestOps that means scheduled full-depth scans, agentless perimeter re-checks between scans, a 7-day asset re-verification cycle with drift detection, and safe exploitation to confirm which findings are real.

Does continuous testing replace an annual penetration test?

Not necessarily, and we do not recommend framing it that way. Continuous testing removes the long blind spot between engagements; a periodic human-led test still adds creative depth, and many auditors expect a formal exercise. The two work best together.

How often do scans run?

You choose. Scheduled scans run on the cadence you configure, and scans are unlimited within fair use under asset-wise pricing, so cadence is a risk decision rather than a budget one. Between scheduled scans, EASM re-checks the perimeter continuously and the inventory re-verifies every asset on a 7-day cycle.

What happens when something changes between scans?

Drift detection records the change in a full change ledger, the 7-day re-verification cycle picks up new or disappeared assets, and continuous monitoring raises real-time threat alerts for perimeter changes (Enterprise). Inside the network, the agent alerts on new hosts, missing hosts and unauthorised changes.

Is it safe to run exploitation on a continuous schedule?

Exploitation only runs under a signed Rules of Engagement, with scope enforcement that automatically stops activity outside authorised assets. Scan profiles (Stealth, Balanced and Aggressive) control intensity, and every action is captured in a full evidence trail.

Which plans include continuous capabilities?

Scheduled scans and scan comparison are included from the Professional plan. Continuous monitoring (EASM) is an Enterprise capability. All plans use asset-wise pricing with unlimited scans within fair use; see pricing for live details.

Will continuous testing overwhelm the team with alerts?

It is designed not to. False-positive reduction filters findings before they reach you, prioritisation uses CVSS v3.1, exploit availability and CISA KEV, and scan comparison surfaces only what changed between runs. Alerts focus on validated, exploitable exposure.

How do we get started?

Run a free demo scan to see the platform in action, then start a trial. All paid plans start with a 7-day free trial. A card is required to start your trial and is only charged after the trial ends, unless you cancel first.

Close the gap between tests

Start with the estate you have today. All paid plans start with a 7-day free trial. A card is required to start your trial and is only charged after the trial ends, unless you cancel first.