Continuous Penetration Testing
Active Focus vs every other way to test
Point-in-time pentests, PTaaS, bug bounty and automated scanning each solve part of the problem. Continuous Penetration Testing is the only model that covers all seven capabilities at once — human depth, always-on and change-driven, across your whole attack surface.
CPT vs other methods, at a glance
Only Continuous Penetration Testing ticks every box. Hover or focus a capability to see what it means.
Why one method is never enough
Every testing model was built to answer a different question. A pentest answers "how deep can an expert go against this scope?" A scanner answers "what known issues can we find everywhere, right now?" Bug bounty answers "what will the crowd stumble onto over time?"
The trouble is that attackers do not respect those boundaries. They watch for change, they hit whatever is exposed, and they do it every day of the year. To match them you need human depth and constant, change-driven coverage of the whole attack surface — which is exactly the gap Continuous Penetration Testing was designed to close.
Where each method wins — and where it stops
Point-in-time pentest
Deep, but only for two weeks a year.
StrengthDeep human testing of an agreed scope; the report auditors expect.
GapBlind for the other ~50 weeks. Anything outside the booked scope — or added after — goes untested.
PTaaS
A better delivery model for the same bursts.
StrengthPlatform, findings and retesting modernise how point-in-time testing is delivered.
GapStill scheduled and scoped in bursts. Not change-driven, and rarely covers assets you did not book in.
Bug Bounty
Broad and always-on — but opportunistic.
StrengthAlways-on human attention across a wide surface; creative, high-impact findings.
GapReward-driven and unpredictable: no guaranteed coverage, thin on business logic, little compliance evidence.
Automated & AI scanning
Tireless, but it cannot think.
StrengthAlways-on and broad — including emerging AI and agentic scanners — excellent at surfacing known issues at scale.
GapEven the best AI tools stop short of business-logic reasoning, chaining and proof of real impact. Noise without a human to validate it.
How CPT covers all seven
River Security delivers Continuous Penetration Testing throughActive Focus — human-led offensive testing on top of continuous Attack Surface Management.
- Human Testers
Real offensive specialists reason about your systems, chain weaknesses and prove impact — the one thing no scanner can do.
- Compliance
Validated findings, reports and retesting that satisfy ISO 27001, NIS2 and DORA — continuously, not as a once-a-year snapshot.
- Always On
Coverage never stops between engagements. Your attack surface is watched year-round, not for two weeks in Q3.
- Always Active
We are probing and attacking at all times, rather than passively waiting for a researcher to feel like looking.
- Change-Driven
A new host, service or feature triggers testing the moment it appears — the window attackers love is the window we close.
- Testing Breadth
The whole external attack surface is in scope, including the unknown, forgotten and shadow-IT assets — not just an agreed list.
- Testing Depth
Business-logic abuse, chained exploits and real-world impact — the depth of a great pentest, applied continuously.
Where does AI fit?
Autonomous AI and agentic pentest tools are improving fast — but today they behave like a smarter scanner, not a testing model in their own right. We treat AI the way our methodology treats every tool: a force-multiplier under human judgement, never a substitute for it.
What AI accelerates
Inside Active Focus, AI speeds up discovery, enrichment, triage and breadth of coverage — surfacing more of your attack surface, faster, so our testers spend their time where it counts.
How we use AIWhat still needs a human
Reasoning about business logic, chaining weaknesses into a real attack path, and proving impact remain human work. That is the "depth" line in the matrix — and where AI-only testing still falls short.
Our MVP methodologyLooking to secure the AI in your own products instead? That is a different question — see AI Testing.
Where our depth comes from
Continuous doesn't mean shallow
The usual objection to "always-on" testing is that it must be thin. Ours is not. Every asset we test is attacked with our composable, recursive MVP (Most Valuable Pentest) methodology — the same expert tradecraft you would get from a top-tier point-in-time engagement, turned into reusable playbooks that improve with every target.
That is how CPT keeps the depth of a great pentest while running continuously and following every change to your attack surface.
Explore the MVP methodology- Discovery-led. Testing follows what we find, recursing into every new asset.
- Business logic. Creative, context-specific attacks scanners cannot reach.
- Proven impact. Findings validated by humans, with demonstrations — not raw scanner output.
- Compliance-ready. Evidence and retesting mapped to ISO 27001, NIS2 and DORA.
Stop choosing between depth and coverage
See how Continuous Penetration Testing would map to your attack surface — or evaluate it on your own environment with a proof of concept.
