That experience fundamentally shifted my mindset: it is much easier to be compliant than secure. Human-led penetration testing remains valuable, but small-scoped, point-in-time assessments cannot match today’s threat velocity. A manual test conducted annually gives you 24 hours of confidence and 364 days of guesswork. In an AI-accelerated environment, the report may be stale before the ink dries.
Has this always been the case? Adversaries have generally been more adept. I agree that it speeds up threat actors capabilities, but threat actors have always been more adept.