
08.09.2026
Security Validation continuously tests IT security and uncovers real attack paths. Learn how Pentera prioritises risks and complements manual pentests.
Security Validation continuously checks which vulnerabilities in an IT environment can actually be exploited and what attack paths arise from them. This gives companies a more up-to-date picture of their security posture than individual scans or an annual audit.
A traditional penetration test remains important. However, systems, configurations and threats change between two assessments. Automated security validation bridges this temporal gap and helps to prioritise risks according to their actual exploitability.
Timur Yilmaz, Service Owner Security Validation at accompio, explains in an expert interview how the Pentera platform uses controlled attack techniques, why ongoing operations remain unaffected, and how companies can derive concrete measures from the results.
In the video, Timur Yilmaz demonstrates how automated checks can be integrated into existing security processes and why having transparency over one's IT environment is the first step.
How can IT systems be continuously tested from the attacker's perspective? What results does Pentera deliver? And why are manual penetration tests still needed? Timur Yilmaz answers these questions in the full video.
Security Validation refers to the continuous and automated review of IT security. It examines whether existing vulnerabilities are actually exploitable, which systems become reachable and how individual gaps combine to form an attack path.
A vulnerability scan identifies known security flaws and often assesses them using a score. Security Validation complements this information with practical proof. As a result, companies can see which vulnerabilities pose a real risk in their specific environment and which measures should be implemented first.
This places security validation at the intersection between Vulnerability Management, automated pentesting and the validation of already implemented security measures.
IT environments are constantly changing. New applications are introduced, updates are installed, systems are restored and configurations are adjusted. A test successfully completed today therefore says little about what the security posture will look like in three months.
„Individual scans are always just a snapshot.“
Timur Yilmaz, Service Owner Security Validation at accompio
Regular automated tests make changes between two inspection points visible. This makes it possible to trace whether new risks have emerged, whether protective measures are effective and whether fixed vulnerabilities recur. This also supports continuous Vulnerability management.
The Pentera platform is deployed in the IT environment and tests defined systems, network segments and scenarios. It uses controlled attack techniques to verify vulnerabilities and potential paths through the network. The scope and frequency of the tests are determined in advance.
A minor vulnerability on its own often seems insignificant. Combined with further misconfigurations or access rights, however, it can enable a far-reaching attack. Pentera maps such connections as attack paths and shows which steps were actually successful.
According to Timur Yilmaz, the tests are structured in such a way that they do not disrupt operational business and infrastructure. Control mechanisms ensure that the testing does not damage productive systems. Companies can therefore integrate recurring test cycles into their everyday security routines.
Following a test run, technical results, visualised attack paths and management evaluations are available. The reports explain which vulnerabilities were exploited, what potential impacts exist and how the risks can be remediated. This facilitates the Vulnerability prioritisation and creates a common basis for decision-making for IT and management.
Automated security validation does not replace the manual penetration test. Both methods fulfil different tasks and complement each other. Automated tests deliver frequent, comparable results and make changes quickly visible. A manual pentest brings in the creativity and experience of specialised security experts and can examine individual scenarios in greater depth.
Timur Yilmaz compares the interplay to dental care: continuous validation corresponds to daily teeth cleaning, while the manual pentest is like a regular visit to the dentist. Both are needed for a comprehensive view of the security posture. Further typical attack scenarios are described in the article on Offensive Security in the enterprise.
The platform can also be operated with a smaller security team. A managed service can additionally assist with setup, test planning, automation and evaluation. Suitable systems and scenarios are selected together. Subsequently, the tests run at scheduled cycles.
Experts help to contextualise the results, prioritise measures and further develop test procedures. A proof of value can demonstrate in advance how the platform operates in your own environment. For this purpose, a limited area with selected endpoints is tested and evaluated jointly.

Would you like to identify real attack paths and continuously check your security measures? accompio supports you from selecting suitable test scenarios and setting up the Pentera platform to evaluating and prioritising the results.
Before automation comes the stocktake. Businesses should know which systems are in place, which areas are particularly critical and which checks are already taking place. This overview forms the basis for sensible test objectives and a suitable rhythm.
On this basis, it is possible to determine which network segments should be tested first and what results are required for IT managers and management. Small, clearly defined test areas make it easier to get started and build confidence in the process.

Timur Yilmaz is Service Owner Security Validation at accompio. He guides companies through continuous security audits and supports them in turning technical results into concrete measures.
A vulnerability scan lists known security flaws. A manual penetration test investigates a defined target using the experience and creativity of a security team. Security validation carries out recurring automated checks, showing which vulnerabilities can be exploited in the respective environment and what attack paths emerge.
The frequency depends on the risk profile, rate of change and criticality of the systems. Automated tests can run daily, weekly or at individually defined cycles. It is important to identify changes between two audits in a timely manner.
The tests are controlled and executed with a defined scope. According to Timur Yilmaz, the Pentera platform is designed to test during ongoing operations without damaging productive systems or disrupting workflows.
A large internal team is not a prerequisite. The platform presents technical results in an easy-to-understand way. If required, a managed service assists with setup, test planning, evaluation and prioritisation.
The platform documents exploited vulnerabilities, successful attack steps and connected attack paths. In addition, management reports and remediation advice are available. As a result, measures can be prioritised according to the actual risk.
A proof of value enables a limited rollout. For this purpose, selected endpoints or network areas are defined, tested and evaluated together. This allows companies to see how the platform operates in their own environment and what added value the results provide.
