A global investment firm with 18 locations and a small security engineering team adopted continuous automated penetration testing using NodeZero to replace point-in-time assessments. An early internal pentest found 85 weaknesses that could be chained into 251 real-world impacts including domain compromise, ransomware exposure, and credential theft. After remediation and continuous validation, the team reduced impacts from 251 to 0, compromised credentials from 52 to 0, compromised hosts from 67 to 0, and cracked Active Directory passwords from 40 to 0. The key insight was shifting from counting weaknesses to understanding how attackers chain them together to achieve objectives, enabling a lean team to prioritize remediation by demonstrated business impact rather than theoretical risk.