Jay Kaplan, CEO and Co-founder of Synack: “Stop buying tools and start buying coverage”

Cybersecurity teams have never had more tools at their disposal, yet many are still operating with blind spots they canโ€™t fully quantify. As attack surfaces expand across cloud, APIs and constantly shifting application environments, traditional approaches to security testing are struggling to keep pace. The result is a growing disconnect between perceived security posture and actual exposure.

For Jay Kaplan, CEO and co-founder of Synack, that gap is the product of an outdated model colliding with a radically different threat landscape. Drawing on nearly a decade in cybersecurity roles across the U.S. Department of Defense and the National Security Agency, Kaplan argues that annual penetration tests and limited-scope assessments are no longer fit for purpose in an era where attackers โ€“ now increasingly powered by AI โ€“ can probe systems continuously and at scale.

In this interview, Kaplan outlines why coverage, not tooling, has become the defining metric for security programmes, how AI is reshaping both attack and defence economics, and why the future of pentesting lies in combining continuous, agentic AI-driven testing with human expertise to deliver a real-time view of exploitable risk.

Synackโ€™s research with Omdia found that 95% of organisations rank pentesting as a top priority, yet on average theyโ€™re only testing 32% of their global attack surface. Whatโ€™s behind that disconnect?

The disconnect is structural. Annual pentests, narrow scopes, and a small bench of testers were fine when environments changed quarterly. Today, code ships daily, cloud assets spin up by the hour, and APIs proliferate faster than anyone can inventory them. Security teams arenโ€™t deprioritising pentesting. Theyโ€™re stuck in a model that canโ€™t scale to where the surface has gone. The 32% figure isnโ€™t a coverage problem they chose. Itโ€™s a coverage problem theyโ€™ve inherited.

With frontier models, attackers can map an environment and iterate on exploits at machine speed. What does that mean for untested assets?

Untested assets used to be a calculated risk. Now theyโ€™re an open door. Frontier models compress reconnaissance from days to hours, and they donโ€™t get tired or move on. An asset that hasnโ€™t been tested isnโ€™t just outside your visibility, itโ€™s actively being mapped by something that will iterate on every exposed surface until it finds a path. The economics of attack have flipped. What used to require a skilled adversary now runs at the cost of compute. If you havenโ€™t tested it, assume an attacker already has.

Why is the annual pentest no longer a defensible model in 2026?

The annual pentest was built around a different threat landscape. Today, the mean time from CVE disclosure to active exploitation is a matter of hours, while code deploys multiply your attack surface every week. An annual snapshot tells you what was true 10 months ago, against an adversary that doesnโ€™t wait for your audit cycle. Boards still treat the annual test as proof of posture, but itโ€™s a reporting artefact, not a control. The defensible model in 2026 is continuous validation against current exploit techniques, on the assets that actually matter. Anything less and youโ€™re underwriting last yearโ€™s risk.

How should CISOs invest their time and money to close that gap?

Stop buying tools and start buying coverage. Most CISOs already own more security software than they can operate. The next dollar shouldnโ€™t go into another scanner producing findings nobody validates. It should go into knowing whatโ€™s actually exploitable across the assets that would hurt the business most. That means consolidating spend on platforms that combine continuous AI-driven testing with vetted human researchers, redirecting senior talent away from triage and onto the problems machines canโ€™t solve, and tying every investment back to a business outcome the board can see. Coverage is the metric that matters now.

What does the right balance of AI-driven testing and human validation actually look like in practice, and where do you draw the line?

AI handles breadth, speed, and the chained reasoning attackers are already running against you. Humans handle creativity, business logic, and the novel attack paths that AI agents havenโ€™t been trained on. The line is exploitability versus invention. Agentic AI is good enough now to map attack surface, validate known exploit chains, and confirm what actually fires in your environment. That work should be continuous. Senior researchers should focus on what machines still canโ€™t see: business-logic abuse, multi-step authorisation flaws, and the creative chains that turn a low-impact finding into a breach.

There are a lot of options for AI pentesting out there. What should buyers look for to close the coverage gap?

Most โ€œAI pentestingโ€ solutions on the market today are just basic wrappers sitting on top of publicly available LLMs. Buyers should be sceptical of anything that produces findings without proving exploitability. Ask if the platform can confirm whether a vulnerability actually fires in your environment. Ask if there are vetted human researchers in the loop for the findings AI canโ€™t reason about. And ask if the model runs continuously, or is it a one-off engagement dressed up as automation. If the answer to any of those is no, youโ€™re not closing the gap.

For a CISO who knows their coverage is too low but doesnโ€™t know where to start, what first move would you recommend? 

Pick the system that, if compromised tomorrow, would put you on the front page. Map every asset connected to it, internal and external. Then test it as if an attacker already has a foothold, not as if youโ€™re checking a compliance box. That single exercise tells you more about your real exposure than a full audit cycle. From there, build outward by business impact, not by org chart. The coverage problem feels overwhelming because most teams try to solve it everywhere at once. Start with what would actually hurt, and let that drive the programme.

What do you see as the next evolution for pentesting?

The next evolution of pentesting will be a continuous activity, not just a calendar event. โ€œTestedโ€ starts meaning a live, validated read on whatโ€™s exploitable today. For that to happen, agentic AI must handle the breadth at machine speed, vetted human researchers handle the depth, and the output is a single source of truth on real risk that the board can act on. The next five years will separate organisations that treat security as a continuous business function from those still buying it as an annual service. The first group will be measurably harder to breach.

Avatar photo
Ricardo Oliveira

Ricardo Oliveira is a Senior Director at TechFinitive, where he frequently collaborates with TechFinitive's editorial team to write and produce content. He's based in Sydney, Australia.