❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdaySynack Blog

Executive-Ready Reporting Is Here: What’s New in the Synack Platform

11 September 2026 at 15:46

Synack's reporting experience now scopes to individual assets, generates AI-written executive summaries, and lets teams preview, save and share reports without leaving the platform.

The post Executive-Ready Reporting Is Here: What’s New in the Synack Platform appeared first on Synack.

Questions to Ask a Penetration Testing Vendor Before You Sign

9 September 2026 at 14:26

Before you sign with a penetration testing vendor, ask precise questions that turn marketing claims into measurable commitments. Confirm exact scope, learn which work is automated, AI-led, or human-led, and require that findings get reproduced and validated before they reach a report. Ask who can access your environment, how testers are vetted, and what the rules of engagement and stop conditions look like. Review sample reports, confirm remediation and retesting terms, and normalize every cost. Place every material promise in the contract rather than a slide deck.

The post Questions to Ask a Penetration Testing Vendor Before You Sign appeared first on Synack.

HIPAA Penetration Testing Requirements for Healthcare Enterprises

By: Paul Mote
8 September 2026 at 07:45

Many healthcare organizations have been told that HIPAA requires an annual penetration test. The current rule is more nuanced. Penetration testing for HIPAA compliance is not prescribed as one universal annual obligation, but regulated entities must conduct a comprehensive risk analysis, manage identified risks, and evaluate whether their safeguards remain effective. A well-scoped pentest can provide important evidence supporting those responsibilities. HHS has also proposed making annual penetration testing explicit, although that proposal is not yet binding.

The post HIPAA Penetration Testing Requirements for Healthcare Enterprises appeared first on Synack.

AI Can Find Vulnerabilities. Building a System That Proves Risk Is the Hard Part.

7 September 2026 at 10:52

The core components required to move from automated discovery to proven risk now exist: capable models, controlled execution, scalable orchestration, evidence capture and human judgement. The opportunity is to engineer them as one dependable system rather than treat each as a standalone feature.

The post AI Can Find Vulnerabilities. Building a System That Proves Risk Is the Hard Part. appeared first on Synack.

Offensive Security Is Becoming a Program, Not a Purchase

3 September 2026 at 11:06

You know what you spent on penetration testing last year. But can you explain what that investment covered between engagements? For many organizations the honest answer is that it covered the weeks the testers were working against a scope agreed before they started. That was a reasonable arrangement when systems changed a few times a year. It is worth revisiting, now that many of them change weekly.

The post Offensive Security Is Becoming a Program, Not a Purchase appeared first on Synack.

Penetration Testing for SOC 2 Compliance: What Auditors Expect

By: Paul Mote
1 September 2026 at 04:46

SOC 2 does not prescribe a universal penetration testing requirement for every organization. A pentest is still commonly used as evidence supporting security, risk assessment, and monitoring controls, and auditor expectations depend on the organization's risks, system boundary, and testing policies. Type II examinations require evidence that controls operated over a defined period, not merely that they existed on one date. A vulnerability scan should not be presented as equivalent to a penetration test, and findings, remediation, and retesting evidence matter as much as the original report.

The post Penetration Testing for SOC 2 Compliance: What Auditors Expect appeared first on Synack.

How to Evaluate a Penetration Testing Vendor: An Enterprise Buyer’s Checklist

26 August 2026 at 10:36

Penetration testing proposals are rarely easy to compare. One vendor prices by application, another by testing days, another by credits, and another by AI test runs. Choosing the right penetration testing vendor therefore requires more than comparing report length, brand recognition, or the initial quote. This guide provides an enterprise checklist and weighted scorecard for evaluating scope, methodology, tester quality, finding validation, reporting, remediation, governance, and total program cost.

The post How to Evaluate a Penetration Testing Vendor: An Enterprise Buyer’s Checklist appeared first on Synack.

PCI DSS Penetration Testing Requirements: What Enterprises Actually Need for Compliance

27 August 2026 at 06:55

Getting PCI DSS Requirement 11.4 Right From the Start
Enterprises often know they need PCI compliance penetration testing but remain uncertain about what makes a test compliant. PCI DSS v4.0.1 Requirement 11.4 involves considerably more than scheduling an annual external assessment. Scope, internal and external testing, methodology, tester qualifications, segmentation validation, remediation, retesting, and evidence all influence whether the work will satisfy assessor scrutiny. This guide explains what enterprise security and compliance teams should have in place before their next PCI DSS assessment.

Introduction
PCI DSS v4.0.1 Requirement 11.4 requires documented internal and external penetration testing, generally at least annually and after significant changes. Segmentation controls need separate testing where segmentation reduces cardholder data environment scope, and service providers face a shorter six-month cycle. Vulnerability scanning does not replace penetration testing, and exploitable findings need correction and retesting. Confirm your exact obligations with your QSA before treating any single testing model as sufficient evidence.

The post PCI DSS Penetration Testing Requirements: What Enterprises Actually Need for Compliance appeared first on Synack.

How Continuous Pentesting Became Standard Practice at Dow

25 August 2026 at 17:37

A few years ago, Dow's cyber engineering team made the switch from point-in-time pentesting to continuous coverage for their high-value assets. How'd they do it? By partnering with Synack. And keep in mind this was before the recent wave of AI-powered pentesting solutions. Dow was ahead of the curve.

The post How Continuous Pentesting Became Standard Practice at Dow appeared first on Synack.

How Often Should Enterprises Run a Penetration Test?

By: Paul Mote
20 August 2026 at 10:09

Most enterprises should treat annual penetration testing as a baseline, not a complete answer. PCI DSS is the one framework with an explicit annual and change-triggered mandate. SOC 2, the current HIPAA Security Rule, and ISO 27001 all expect testing to follow the organization's own risk assessment and control design, not one fixed calendar date. HHS has proposed an annual HIPAA pentesting requirement, but that rule has not been finalized. Enterprises that combine a formal annual assessment with change-triggered and continuous validation stay ahead of frameworks that were never designed around a single testing frequency.

The post How Often Should Enterprises Run a Penetration Test? appeared first on Synack.

AI Pentesting Works. Building It Yourself Is the Hard Part.

19 August 2026 at 11:46

AI pentesting works, but building it in-house is the hard part. Synack VP Chris Brown breaks down the reliability, token economics, model dependency and validation costs that come with building versus buying an AI pentesting capability.

The post AI Pentesting Works. Building It Yourself Is the Hard Part. appeared first on Synack.

Managed Bug Bounty: Why Provable Coverage Beats Blind Spend

11 August 2026 at 05:01

Most security leaders can report what they spent on bug bounty last year. Far fewer can understand the value being delivered by proving what it actually tested. Open programs show which bugs were reported, not which assets received real, skilled attention. Managed bug bounty closes that gap. Researcher-hour and traffic analytics turn testing depth into evidence you can measure, not an assumption you have to trust, giving you coverage you can hand to a board, an auditor, or a compliance team.

The post Managed Bug Bounty: Why Provable Coverage Beats Blind Spend appeared first on Synack.

From DARPA to Black Hat: An SRT Researcher’s Next Chapter

5 August 2026 at 10:41

Synack Red Team researcher Malcolm Stagg takes the stage at Black Hat USA 2026 on August 6 to present three years of independent research on a new class of network infrastructure attacks. Here's who he is and why the talk belongs on your calendar.

The post From DARPA to Black Hat: An SRT Researcher’s Next Chapter appeared first on Synack.

Build vs. Buy AI Pentesting: Why Dow Chose to Partner With Synack

5 August 2026 at 09:45

To hear both sides of the build vs buy debate around AI pentesting solutions, we spoke with Dow's cyber engineering team lead Dan Lacher and Synack's CTO Mark Kuhr. From Dow's perspective, Synack served as a force multiplier for a small internal red team. Meanwhile, building the Synack Autonomous Red Agent (Sara) from scratch definitely had some trial and error.

The post Build vs. Buy AI Pentesting: Why Dow Chose to Partner With Synack appeared first on Synack.

RufRoot Exposed the Hidden AI Agent Attack Surface

By: Paul Mote
1 August 2026 at 07:16

The critical RufRoot vulnerability gave unauthenticated attackers a path from an exposed MCP endpoint to shell access, stolen AI provider keys and poisoned agent memory. Paul Mote explains why the incident should change how security teams define, test and recover their AI attack surface.

The post RufRoot Exposed the Hidden AI Agent Attack Surface appeared first on Synack.

Europe Is Regulating AI. America Is Accelerating AI. Both Need Offensive Security Validation.

29 July 2026 at 14:52

Europe regulates AI through risk tiers and conformity checks. America accelerates AI through deregulation and infrastructure speed. Both models ask different questions but land on the same gap: neither tells you whether a live AI system actually holds up against real attacks. Enterprise AI security depends on evidence, not paperwork or policy. Continuous, human-validated offensive testing is the layer that both regulatory philosophies are missing and that every organization operating across borders actually needs.

The post Europe Is Regulating AI. America Is Accelerating AI. Both Need Offensive Security Validation. appeared first on Synack.

BOD 26-04 Makes Exploitability the Priority Signal: Scanners Can’t Measure It

29 July 2026 at 12:04

CISA's Binding Operational Directive 26-04, issued June 10, 2026, replaces the KEV directive with a four-variable risk model: asset exposure, KEV status, exploit automation, and technical impact. CISA publishes three of the four answers generically per CVE. The two that decide whether prioritization is defensible (real exposure and real impact in your environment) can only be proven by testing the asset the way an adversary would. Continuous, human-validated pentesting is built to produce that evidence.

The post BOD 26-04 Makes Exploitability the Priority Signal: Scanners Can’t Measure It appeared first on Synack.

❌
❌