A penetration test is a photograph. It captures your security posture at one instant — the day the testers were in, against the systems that were in scope, using the techniques that were current that week. It is genuinely useful. It is also out of date the moment it's filed.
The problem isn't the test. It's the spacing between tests. Most regulated enterprises run an annual VAPT. The well-resourced ones, or those under RBI's mandate, run quarterly. Either way, the calendar creates a known, predictable, exploitable gap — and the math of that gap is not an opinion. It's arithmetic.
Run the numbers yourself
Pick how often you test. Watch what it leaves open. The monitored window is small; the unmonitored stretch is the largest chunk of the year an attacker has the building to themselves.
Even a perfectly executed quarterly programme leaves a 91-day window. That matters because of a second number from the incident-response data: in an under-tested environment, an attacker typically goes from first foothold to Domain Administrator in 30 to 90 days. The blind window isn't a theoretical risk. It's longer than the time the adversary needs to win.
The math nobody runs in the budget meeting
Scale this across a real estate. A mid-sized bank might operate 40-plus internet-facing applications. Quarterly testing across all of them is up to 160 scoped engagements a year. At ₹5–50 lakh and two-to-six weeks each, the programme is financially and operationally unsustainable at human scale — so something quietly gives. Scope shrinks. Frequency slips. The window widens again, in the places no one is looking.
What 363 days actually buys an attacker
The reason the gap is so dangerous is that the adversary doesn't spend it idle. Dwell time is a methodical progression: reconnaissance, lateral movement, privilege escalation, persistence, and exfiltration — all tuned to stay under the alerting threshold.
So the picture compounds. An attacker who slips in the day after your annual test completes stays undetected for an industry-average 194 days, then takes a further 60 to contain — and your next scheduled look is still months away. By the time you photograph the scene again, they've already left with what they came for.
The model has to change, not the effort
None of this means security teams aren't trying. The testing gap is a failure of economics and talent supply, not of will. India alone has over a million unfilled cybersecurity roles; you cannot hire enough people to manually test a large estate continuously. The annual cycle was a reasonable answer to a slower-moving threat. Against AI-accelerated adversaries who weaponise vulnerabilities in days, it is structurally inadequate.
The fix isn't testing harder on the same calendar. It's removing the calendar — shrinking the unmonitored window from months to hours, so a vulnerability that appears on a Tuesday is found and reported before an attacker can build a path through it.
Close the window to under 24 hours.
Arxiis is an autonomous AI penetration-testing platform that runs a coordinated crew of specialist agents through a full engagement in hours, not weeks — continuously, not annually. Every finding is CVSS-scored, MITRE ATT&CK-tagged, and auto-mapped to RBI CSF, CERT-In and nine more frameworks. It runs entirely on your own infrastructure. Nothing leaves the perimeter.