38% of enterprise security leaders report that at least one-quarter of their critical attack surface had not been independently tested or validated in the previous 90 days.
| Publisher | Synack |
| Report | The State of Continuous Security Validation |
| Published | 21 July 2026 |
| Topics | Attack Surface, Security Testing, Threat Exposure, Enterprise Security |
Published by Synack in The State of Continuous Security Validation , 21 July 2026. The figure is taken from the report as published; the full methodology is in the source.