CENSUS
Continuous Assessment: Adversarial Exposure Testing Across A Changing Estate
- tiger team
- continuous engagements
- platform
- golden eagle
- continuous assessment
- adversarial testing
Traditional penetration testing only proves security on the day it runs. CENSUS Continuous Assessment combines the Golden Eagle platform with Tiger Team operators to deliver ongoing adversarial testing, mapping attack paths as your estate changes.
Continuous Assessment: Adversarial Exposure Testing Across A Changing Estate
Most organisations know what their security posture looked like on the day of their last assessment. Far fewer can say what it looks like today.
That gap is a consequence of how security assurance has traditionally been delivered. Assessments are scheduled against environments that do not remain static. Infrastructure changes, identities accumulate, controls drift and new attack paths emerge between one assessment and the next.
CENSUS Continuous Assessment combines Golden Eagle, our adversarial testing platform, with Tiger Team operations. Golden Eagle extends testing across the estate, automates attack-path execution and centralises evidence and reporting. Tiger Team operators set the strategy, scope and direction of each campaign.

Point-in-time Proof Expires
A penetration test proves what was reachable on the day it ran. It does not prove what becomes exposed after the next deployment, credential leak or control change.
Verizon's 2026 Data Breach Investigations Report found that vulnerability exploitation accounted for around 31% of breaches, overtaking credential abuse as the leading initial access vector. Median remediation time for known exploited vulnerabilities also increased from 32 to 43 days.
The practical problem is the interval between exposure and remediation. Annual or semi-annual testing cannot provide current evidence across a window measured in weeks.
Security evidence needs to be refreshed as the environment changes.
Geography Limits Coverage
Distributed environments create a second constraint.
Branch networks, remote sites and operational facilities are often tested according to travel and mobilisation schedules rather than risk. Coverage becomes uneven, particularly across large or geographically distributed estates.
A remote site may be assessed less frequently than headquarters simply because reaching it requires another deployment of personnel. The attacker does not make the same distinction. A weakness in a branch office, operational facility or wireless network can become an entry point into the wider organisation.
Resident access nodes allow internal testing to extend across those locations without deploying a testing team each time. Tiger Team operators can then direct campaigns across the estate through a common operating model.
Product and Operations
Continuous Assessment is built around two complementary components.

Golden Eagle Platform
Golden Eagle scales campaign execution and centralises evidence, findings and reporting. It maps the environment, executes attack scenarios and records the resulting attack paths and supporting evidence.
Tiger Team Operations
CENSUS operators define objectives, tune campaign scope, enforce exclusions and interpret results in the context of the environment being tested.
The two operate as a continuous loop:
MAP → EXPLOIT → ADAPT
The platform maps the estate as it changes, tests what an attacker can reach and uses the resulting evidence to inform subsequent scenarios.
Reconnaissance data, captured credentials, tokens and user secrets obtained during one scenario can feed the next. Campaign depth therefore builds over time rather than resetting with each engagement.
Automation maintains the testing cadence. Tiger Team operators retain responsibility for strategy, scope and judgement.
How Golden Eagle Works

Resident Access and Execution
Internal testing is conducted through access nodes deployed inside the client environment.
Physical devices are the primary deployment model, with software containers available where appropriate. Nodes can be connected to Ethernet segments or positioned within wireless coverage to provide controlled testing access without requiring a dedicated testing workstation at every location.
Existing network access controls remain part of the assessment. If a node can obtain access where policy says it should not, that exposure can itself become a finding.
The nodes include protections such as disk encryption, secure boot and remote wipe. Communication with the backend is outbound only, and task data and configuration are retained for the duration required rather than using the nodes as long-term data stores.
Deployments can use several nodes at each site and relocate them where required to extend coverage across larger environments.
Execution and Compounding Evidence
Backend workers provide the compute required for external, web, cloud, assume breach and social engineering scenarios. Internal scenarios are executed through the access nodes.
Campaign results are retained and reused as evidence.
Reconnaissance output, credentials, tokens, user secrets and proven attack paths from one scenario can influence what is tested next. This allows later activity to build on access already established rather than repeatedly starting from the same baseline.
Findings, attack paths and reports are managed through the Golden Eagle platform and can be tracked through remediation and retesting.
AI-assisted Execution
Golden Eagle uses AI to accelerate selected reconnaissance, analysis and campaign tasks.
Targeted models can run locally on access nodes, keeping suitable processing inside the client environment. More compute-intensive workloads can run on the backend using locally deployed open-weight models or approved commercial models.
The rules of engagement define where AI can assist, which models are permitted and where operator approval is required. Scope controls, request limits and task-specific failsafes remain enforced during execution.
AI supports the campaign. It does not determine its objectives or scope.
Human-led Campaign Control
Tiger Team operators remain responsible for campaign direction.
They define objectives, adjust scope, enforce exclusions and decide how evidence from one scenario should affect the next. Systems and networks that must not be touched can be explicitly excluded.
This is particularly important when automated testing is operating across production environments. The platform provides repeatability and scale, while the operator retains control over risk and campaign intent.
Assume Breach scenarios follow the same model. They are executed through Golden Eagle under human supervision, either from CENSUS operators or, where appropriate, the client's own security specialists.
Detection and Response Validation
Continuous Assessment also provides a repeatable signal to defensive teams.
Campaign activity measures whether the SOC detects the activity associated with a proven attack path and how quickly it responds. This tests control effectiveness under realistic adversarial activity, rather than simply confirming that a control exists.
Proven attack paths and estate context is also used to automatically generate immersive table-top exercises. The same evidence used during offensive testing therefore becomes input for defensive rehearsal and response validation.
Deployment Models
Golden Eagle can be deployed according to the operational and data-handling requirements of the organisation.
The full solution can operate entirely on client premises, including the platform backend.
Hybrid deployments can place access nodes inside the client environment while running backend components in regional cloud infrastructure.
CENSUS-hosted deployments are also available for scoped engagements, including deployments using confidential computing on supported cloud platforms.
This allows organisations to start with a limited footprint and extend coverage as requirements mature, without requiring the same architecture for every engagement.
What Continuous Assessment Changes
For security leaders, testing can extend across distributed sites without repeatedly mobilising personnel. Campaign direction remains centralised while evidence is refreshed as the estate changes.
For technical teams, findings include proven attack paths and supporting evidence. Results from one scenario can inform deeper testing in those that follow.
For SOC teams, campaign activity provides a repeatable way to validate whether detection and response controls identify real attack behaviour.
For governance and compliance teams, testing operates within defined scope, exclusions and rules of engagement. Deployment can also be selected according to data residency, sovereignty and operational requirements.
Golden Eagle was built by the same engineers who run CENSUS Tiger Team engagements. It translates that tradecraft into repeatable adversarial testing across more locations and at a higher cadence, while Tiger Team operators retain control of the campaign.
Start with an External Assessment
Map the internet-facing estate, prove which exposures are reachable, then extend the campaign into selected sites through a scoped Golden Eagle deployment.
To discuss Continuous Assessment for your environment, contact us at [email protected].