---
title: "What 345 Days of Untested Exposure Looks Like at a Bank"
url: https://daily.dev/posts/what-345-days-of-untested-exposure-looks-like-at-a-bank-0o5yqzlxd
source_url: https://www.bleepingcomputer.com/news/security/what-345-days-of-untested-exposure-looks-like-at-a-bank
type: article
source: "BleepingComputer"
published: 2026-06-03T14:04:24.366Z
updated: 2026-06-03T14:04:44.706Z
tags: ["security", "fintech"]
reading_time: 6
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# What 345 Days of Untested Exposure Looks Like at a Bank

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 6 min read · 0 upvotes · 0 comments

## Summary

Annual penetration tests leave roughly 345 days of unvalidated exposure at financial institutions. Using a real case study from a regional bank, Sprocket Security illustrates how a third-party mortgage portal exposed an unauthenticated API endpoint that leaked staff records and allowed fraudulent loan submissions across all tenants on the shared platform. The finding required active human testing — not automated scanning — and would have been missed by a point-in-time annual assessment. Regulatory frameworks like PCI DSS 4.0, FFIEC, and NYDFS already imply testing should respond to infrastructure changes, not annual schedules. The argument is that continuous testing tied to attack surface changes is the structural fix, not simply testing more frequently.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/what-345-days-of-untested-exposure-looks-like-at-a-bank>

## Similar posts on daily.dev

- [95% of Security Teams Blindsided by Vulnerabilities Between Tests](https://daily.dev/posts/95-of-security-teams-blindsided-by-vulnerabilities-between-tests-zok2oizdf) · IT Security Guru · 0 upvotes · 0 comments
- [How Continuous Scanning Differs from Periodic Pentesting?](https://daily.dev/posts/how-continuous-scanning-differs-from-periodic-pentesting--sp6z2s9ou) · Security Boulevard · 0 upvotes · 0 comments
- [Analysis of one billion CISA KEV remediation records exposes limits of human-scale security](https://daily.dev/posts/analysis-of-one-billion-cisa-kev-remediation-records-exposes-limits-of-human-scale-security-80ptnefpn) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#fintech](https://daily.dev/tags/fintech)

[View this post on daily.dev](https://daily.dev/posts/what-345-days-of-untested-exposure-looks-like-at-a-bank-0o5yqzlxd)
