ObsidioMESA

Why Annual Penetration Tests Don't Prove Operational Resilience

Nader Salem· Obsidio MESA ·June 18, 2026
Why Annual Penetration Tests Don't Prove Operational Resilience

One of the most common responses I hear when discussing resilience validation with security leaders is some version of this:

"We already run penetration tests. Doesn't that cover it?"

It's a reasonable question.

Penetration testing is an established part of any mature security programme. It's conducted by qualified specialists, generates detailed reports, and often forms part of the evidence presented to boards and regulators.

The issue isn't that penetration testing lacks value. It does the job it was designed to do very well.

The issue is that it was designed to answer a specific question. Operational resilience requires an answer to a different one.

What Penetration Testing Is Designed to Do

A penetration test is built around one core question:

Can an attacker gain unauthorised access to our systems?

The objective is to find vulnerabilities, misconfigurations, and weaknesses before someone else does. A well-run penetration test gives security teams something concrete to act on and provides meaningful assurance that defences have been evaluated by a credible external party.

For that purpose, penetration testing remains one of the most valuable tools available. I'm not arguing otherwise.

But operational resilience is asking something different.

The Question Penetration Tests Don't Answer

Operational resilience is a broad discipline. It covers business continuity, recovery procedures, third-party dependencies, crisis management, people, and processes, not just technology controls. DDoS resilience is one important dimension of it, not the entirety.

What these disciplines have in common is a focus on outcomes: not how an incident starts, but what happens once it does.

Can critical services keep running when systems come under sustained pressure? How do teams coordinate when conditions move beyond normal operating parameters? Where are the dependencies that only become visible when infrastructure is genuinely stressed?

These questions require a different kind of testing. One that evaluates operational performance under realistic conditions rather than whether a determined attacker can find a way in.

For DDoS resilience specifically, that often means validating how services behave when exposed to distributed traffic patterns that more closely resemble real-world conditions. Not simply whether protection exists, but whether it performs as expected when infrastructure is genuinely under pressure.

An organisation can perform well on every penetration test and still have significant gaps in its ability to maintain service availability during a sustained disruption. One result doesn't tell you much about the other.

Why the Distinction Matters Now

When pen testing is treated as a periodic exercise rather than part of a continuous assurance programme, it can become a confidence signal that doesn't fully reflect operational reality. The infrastructure it tested may have changed significantly since the last engagement. New services, new dependencies, new integrations.

More importantly, the evidence it produces answers a different question than the one boards and regulators are increasingly asking.

The conversation has shifted. Most senior stakeholders now accept that incidents are inevitable. The question they're asking isn't whether an attack can occur. It's how effectively the organisation continues operating when one does.

That requires evidence of operational performance under pressure, not just evidence that vulnerabilities have been assessed.

Increasingly, organisations are looking beyond traditional security assessments and exploring ways to validate resilience using realistic simulations that generate evidence suitable for board, audit, and regulatory review.

Where This Is Heading

The organisations I've spoken to that are furthest ahead in this area aren't replacing penetration testing. They're building on it.

They continue to evaluate attack surfaces and vulnerabilities, but they also validate service continuity, response coordination, and operational performance under conditions that more closely resemble real disruption. The result is a more complete picture of risk.

As operational resilience continues to move up the board agenda, I expect more organisations to supplement traditional security testing with resilience validation exercises designed to demonstrate how critical services perform under realistic conditions.

Penetration testing tells you whether you can be breached.

Resilience validation tells you whether you can keep operating if you are.

Both questions matter. Treating one as a substitute for the other leaves a gap that tends to surface at exactly the wrong moment.

Nader Salem is the regional partner for Obsidio in the Middle East and Southeast Asia.

← Back to Insights

Ready to see what your defences look like under real pressure?

A demonstration takes less than an hour. You will see exactly how Obsidio runs a realistic DDoS simulation against your infrastructure, what the output looks like, and how it maps to your regulatory obligations.