- Synack CTO Mark Kuhr has discussed how continuous penetration testing could help government agencies close security gaps
- Kuhr said human-led testing remains essential alongside automation and artificial intelligence
- Shadow IT and identity flaws remain common blind spots in government networks
Mark Kuhr, chief technology officer and co-founder of Synack, said continuous penetration testing, or pentesting, could help government agencies simulate how threat actors operate and uncover hidden vulnerabilities as their attack surface continues to expand.
In an article published on Carahsoft.com, Kuhr wrote that pentesting goes beyond automated vulnerability scans by testing how real adversaries operate and by exposing weaknesses that defenders may not know exist.
Why Do Government Agencies Need Pentesting?
Kuhr said one of the most frequent discoveries during pentesting is forgotten or unmanaged assets, often called shadow IT. He explained that these systems tend to go unpatched and unmonitored, and often sit outside an agency’s existing security controls — making them an easy entry point for attackers who find them through automated reconnaissance.
Kuhr also pointed to identity and authorization gaps that automated scanning tools tend to miss.
“Broken access controls, excessive permissions and privilege escalation paths may appear harmless in isolation, but skilled human researchers can connect those weaknesses together to demonstrate how an attacker could move laterally across systems or gain privileged access,” said Kuhr.
How Does Synack’s Continuous Security Validation Approach Support Agencies?
Kuhr said periodic or annual pentests can no longer keep up with how quickly government attack surfaces change. He explained that Synack instead relies on continuous security validation, an ongoing cycle of discovering exposed assets, ranking them by risk and feeding them into active testing.
According to Kuhr, this approach helps agencies:
- Continuously identify emerging exposure
- Validate exploitable risk instead of generating false positives
- Accelerate remediation efforts
- Demonstrate measurable risk reduction over time
He added that every validated finding comes with remediation guidance and retest verification to confirm the issue was fixed.
What Role Do Humans Play Alongside Automation in Testing?
Kuhr said the scale of government networks makes manual testing alone unworkable, especially as attackers use automation and artificial intelligence to find targets faster. But he said automation without human judgment has its own blind spots.
He explained that Synack pairs agentic artificial intelligence with the Synack Red Team, a vetted community of security researchers, treating AI as a force multiplier rather than a replacement for human expertise. Kuhr noted that this combination lets agencies scale up discovery and testing while still confirming real exploitability through human analysis.
He added that Synack’s platform is FedRAMP Moderate authorized, allowing agencies to track remediation progress and show measurable security improvements to leadership and oversight bodies.














