The Red Team Bluff: Why Your Annual Pen Test Is a Waste

The annual penetration test is one of the most expensive line items in the security budget, and one of the least useful. The defender who runs the annual test gets a report. The defender who does the continuous testing gets…

A worn deck of playing cards in a leather case on a green baize card table, the top card lying face-down beside the deck, a few chips stacked nearby, under warm tungsten pendant light.

The annual penetration test is one of the most expensive line items in the security budget, and one of the least useful. The typical enterprise spends $50K to $250K per year on the pen test. The pen test produces a report. The report sits in a shared drive. The report gets a CDE. The CDE gets the same fix the report called out last year. The penetration becomes the same as last year. The pen test report amounts to the same as last year. The defender has spent a lot of money to learn nothing new. Here is why the annual pen test fails, and what works in 2026.

What is wrong with the annual pen test

Three problems, in roughly that order of impact.

1. The time horizon. The pen test runs for 2 to 4 weeks, once per year. The pen test exercises the security posture at one point in time. The pen test does not exercise the security posture the other 48 weeks. The attacker does not have a similar constraint. The attacker runs continuously. The pen test gives the defender a snapshot. The attacker has a movie. The snapshot loses.

2. The scope. The pen test scope is usually the external perimeter, the web application, the wireless network. The pen test scope rarely includes the production cloud environment, the production data warehouse, the production SaaS configuration. The pen test scope becomes the part of the environment the attacker is least likely to bother with. The attacker goes for the cloud account, the SaaS admin, the supply chain. The pen test does not exercise any of those.

3. The report. The pen test report runs to 50 to 200 pages. The report documents every finding. The findings get a severity. The severity gets a fix priority. The fix priority gets an owner. The owner does not fix it. The next pen test runs. The same finding shows up. The cycle continues.

What works in 2026

Three approaches, in priority order.

1. Continuous red team. The continuous red team is not a one off exercise. The continuous red team runs every week, exercises the same scope the real attacker would exercise, and reports the findings as the continuous red team finds them. The continuous red team is what the modern security operations need, and the continuous red team is what the modern security operations can afford. Vendors like Bishop Fox, Coalfire, and the various open source equivalents (Atomic Red Team, Caldera) make the continuous red team a realistic option for the enterprise that could not afford it five years ago.

2. Purple team exercises. The purple team exercise counts as the joint exercise between the red team and the blue team, with the goal of testing the detection and the response, not the goal of finding new vulnerabilities. The purple team exercise sits as the exercise that improves the blue team’s performance, and the purple team exercise sits as the exercise the security operations team should be running every month. The purple team exercise is cheaper than the red team exercise, the purple team exercise produces more value for the detection engineering, and the purple team exercise becomes the exercise the security operations team can run in house.

3. Targeted penetration tests for high risk changes. The major architecture change (the new cloud migration, the new authentication system, the new third party integration) gets the targeted penetration test. The targeted penetration test serves as the test that exercises the change before the change ships, and the targeted penetration test sits as the test that catches the issue the change introduced. The targeted penetration test is more expensive per test than the annual test, and the targeted penetration test is more useful per dollar than the annual test.

What to do this quarter

Cancel the annual penetration test. The annual penetration test serves as the test that is not finding the issues the attacker is going to exploit, and the annual penetration test runs as the test that is not improving the security posture. The cancel serves as the budget move, and the budget move is what funds the continuous red team, the purple team exercises, and the targeted penetration tests the security operations team needs.

Start one of the three approaches above. Pick the one the security team has the operational capacity to run, and the one the security team is going to learn from. The first approach is going to teach the security team what the continuous security testing looks like, and the first approach is going to be the proof of concept for the rest of the security testing the security team is going to run.

The Red Team Bluff: Why Your Annual Pen Test Is a - inline
Key points from The Red Team Bluff: Why Your Annual Pen Test Is a

The bottom line

The patterns the post covers have been showing up in production for long enough that the patterns have names, the failures, the mitigations, the gaps. The work the security team and the engineering team and the operations team are quietly doing today sits as the work that decides whether the practice the post names sits as a tool the team uses or a liability the team is paying for.

Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading