The annual penetration test has a quiet problem: it's a snapshot of an environment that never stops moving. By the time the report is bound and delivered, a new service has shipped, a forgotten cloud bucket is open, and last quarter's edge has drifted. Continuous Adversarial Security (CAS) is our answer, an always-on adversarial loop that runs against your environment the way an attacker would, except it works for you.
Detection is necessary, but it's reactive
MDR, XDR, EDR, and SIEM are necessary layers, but they're fundamentally reactive: they observe an attack that's already underway. The data on attacker tempo makes that gap hard to ignore.
- 63 → 5 days. Mandiant's measured average time-to-exploit for newly disclosed vulnerabilities collapsed from 63 days (2018–2019) to just five days in 2023. Attackers now move fast enough to beat routine patching cycles.
- #1 vector. Exploits, both zero-day and n-day, were the top initial infection vector in Mandiant incident-response engagements for four straight years (2020–2023). Compromise increasingly starts at an unassessed weakness, not a phished user.
- $4.99M average breach. The 2026 IBM/Ponemon report puts the global average cost of a data breach at a record USD $4.99 million, up 12% year over year, alongside a 56% increase in AI-driven attacks.
The 2026 Verizon DBIR goes further: software-vulnerability exploitation has overtaken stolen credentials as the leading way attackers get in, and nation-state actors are already using large language models for reconnaissance, vulnerability research, and scripting. The defensive question flips from will my tooling catch the intrusion? to who finds my exploitable weaknesses first: my security partner, or the adversary?
An adversarial cycle, not a one-time test
CAS replaces the once-a-year assessment with a continuous six-phase loop, run against your environment on an ongoing basis:
- Recon — continuous asset and attack-surface discovery, including shadow IT and drift from the prior cycle.
- Discover — vulnerability and weakness identification surfaced as it changes, not once a year.
- Validate — manual confirmation of every finding before it reaches your team, eliminating false positives up front.
- Exploit — controlled exploitation to prove real-world impact, only where explicitly scoped and authorized.
- Report — prioritized findings tied to business impact, not only CVSS scores.
- Retest — verification that remediations actually closed the gap, feeding the next cycle.
Because the loop never stops, the value compounds. We track what changes between cycles and verify fixes instead of handing you a static report that's stale the day a new service ships.
Real operators, not autonomous agents
Every engagement is led by a named Fletch Labs operator who stays your point of contact across cycles and carries forward the accumulated knowledge of your environment. Tooling assists; people decide. We don't point an autonomous AI agent at your network and let it run. That's both a safety property and a quality property: validated findings, zero noise, and judgment applied where automation can't be trusted.
Scope that fits your tolerance
Not every organization wants fully autonomous exploitation against production. Scope is configured up front and adjustable at renewal:
- Autonomous mode — recon through exploitation runs continuously without per-action sign-off; results delivered as found. Best for maximum coverage with minimum friction.
- Gated mode — recon, discovery, and validation run continuously, but exploitation requires a go/no-go check-in before anything touches production.
- Coordinated mode — the full loop runs on a scheduled cadence agreed with your team, closer to a formal, pre-approved penetration test repeated on a regular cycle.
Delivered as a flat-rate subscription billed monthly, one rate covering a single primary environment under standard scope, no per-host or per-user math.
The takeaway
Detection tooling catches intrusions in progress; CAS aims to make sure there's nothing exploitable left for the intrusion to start from. In a year where AI is compressing attacker timelines and breach costs hit a record, the highest-leverage defensive move is the one an attacker would make: assess your own environment, continuously, before someone else does.
Sources: Verizon 2026 DBIR · IBM & Ponemon, Cost of a Data Breach 2026 · Mandiant, Time-to-Exploit Trends 2023 · Microsoft Threat Intelligence & OpenAI, Staying Ahead of Threat Actors in the Age of AI