Listen to this Post
Introduction: Why Traditional Security Is No Longer Enough
The cybersecurity landscape has changed dramatically over the past few years. Financial technology companies are rapidly adopting cloud-native infrastructure, containerized applications, APIs, artificial intelligence, and automation to remain competitive. While these innovations accelerate business growth, they also introduce new attack surfaces that evolve almost daily. A penetration test performed once every few months is no longer enough to guarantee that production environments remain secure.
Recognizing this challenge, Critical Cloud and Tarian Labs have formed a strategic partnership to introduce Continuous Runtime Security Validation, a new security assurance service designed specifically for organizations across the UK and Ireland. Instead of treating security assessments as isolated events, the service creates an ongoing validation cycle that continuously verifies whether security controls remain effective as infrastructure, applications, and AI systems change.
This collaboration represents a shift from periodic compliance exercises toward continuous operational security assurance—an approach that aligns with the realities of modern cloud computing.
Critical Cloud and Tarian Labs Join Forces
The newly announced partnership combines two complementary areas of expertise.
Critical Cloud contributes its Managed Runtime Assurance operational model, which focuses on maintaining the health, security, compliance, and resilience of production environments. Rather than simply deploying monitoring tools, the company continuously manages cloud operations while ensuring systems remain secure throughout their lifecycle.
Meanwhile, Tarian Labs brings extensive offensive security experience developed through projects involving government agencies, defense organizations, and critical national infrastructure. Their expertise includes penetration testing, cloud assessments, API security evaluations, web application testing, and infrastructure security reviews.
Together, the companies offer fintech organizations a comprehensive security validation service that extends well beyond traditional penetration testing.
Moving Beyond One-Time Security Reports
One of the biggest limitations of conventional penetration testing is that it captures security posture at only a single moment in time.
Organizations typically receive a lengthy report listing discovered vulnerabilities. After remediation, many companies wait months before conducting another assessment. During that period, cloud environments evolve, developers release new code, APIs change, infrastructure scales automatically, and AI systems receive updates—all of which can introduce fresh security risks.
Continuous Runtime Security Validation replaces this outdated workflow with a continuous improvement cycle.
Instead of generating static reports, security findings immediately enter an operational workflow where vulnerabilities are remediated, independently retested, validated, and documented with evidence confirming successful resolution.
This transforms penetration testing into an ongoing operational process rather than an annual compliance exercise.
How the Observe, Detect, Validate Methodology Works
The foundation of the new service is a structured framework called Observe, Detect, Validate.
Each stage performs a distinct role in strengthening production security.
Observe
Critical Cloud continuously monitors production environments using its Datadog-powered managed platform.
This monitoring provides visibility into:
Cloud infrastructure
Runtime applications
AI workloads
Operational performance
Security events
Compliance status
Instead of waiting for scheduled audits, organizations receive continuous insight into production systems.
Detect
Tarian Labs independently evaluates security controls through offensive security testing.
Its assessments include:
Penetration testing
Cloud security reviews
Infrastructure assessments
Web application testing
API security testing
Configuration validation
This offensive approach simulates the techniques real attackers would use to identify weaknesses before cybercriminals exploit them.
Validate
Once vulnerabilities are identified, remediation begins immediately.
Critical Cloud works with customers to resolve identified issues before Tarian Labs independently performs follow-up testing.
Only after vulnerabilities have been successfully verified as fixed are they considered closed.
This produces evidence-based assurance rather than assumptions that remediation was successful.
A Clear Separation of Responsibilities
An important feature of the partnership is its governance model.
Maintaining independence between testing and remediation helps preserve objectivity throughout the validation process.
Under the agreement:
Tarian Labs owns testing methodologies.
Tarian Labs determines vulnerability severity.
Tarian Labs performs independent retesting.
Critical Cloud manages operational improvements.
Critical Cloud oversees remediation.
Critical Cloud handles runtime operations and monitoring.
This separation ensures customers receive unbiased validation while still benefiting from integrated operational support.
Designed for Highly Regulated Industries
The service is particularly valuable for fintech companies operating under increasingly demanding regulatory frameworks.
Financial institutions face ongoing compliance obligations covering:
Operational resilience
Cloud governance
Third-party risk management
Data protection
Incident response
Continuous monitoring
Rather than producing compliance documentation based on outdated assessments, Continuous Runtime Security Validation enables organizations to demonstrate that production controls continue functioning correctly over time.
This evidence-based approach provides stronger assurance for auditors, regulators, and executive leadership.
Leadership Emphasizes Continuous Assurance
James Smith, CEO of Critical Cloud, highlighted a key weakness affecting many security programs today.
According to Smith, detecting threats without validating whether security controls actually work provides hope instead of genuine assurance. As organizations adopt increasingly complex technologies—including AI—continuous validation becomes essential rather than optional.
Kevin Hanford, Co-Founder and CEO of Tarian Labs, echoed a similar perspective.
He explained that penetration testing should serve as the starting point for continuous improvement rather than marking the end of a security engagement. By integrating testing, remediation, and independent verification, organizations gain confidence that identified risks have truly been eliminated.
Availability Across the UK and Ireland
Continuous Runtime Security Validation is immediately available to fintech organizations throughout the UK and Ireland.
The partnership also plans several future initiatives, including:
A packaged joint security offering
Fintech-focused cybersecurity events across Wales
Live demonstration environments
Full Observe, Detect, Validate workflow showcases
Practical remediation demonstrations
Evidence-based validation presentations
These initiatives aim to educate organizations on adopting continuous security assurance practices.
Industry Certifications Strengthen Trust
Both organizations possess credentials that reinforce confidence in the partnership.
Critical Cloud maintains:
ISO 27001 certification
Cyber Essentials Plus certification
Powered by Datadog Accreditation
Datadog Advanced Partner status
Meanwhile, Tarian Labs delivers security engagements through CREST-registered practitioners, with final approval provided at the National Cyber Security Centre (NCSC) recognized CHECK Team Leader (CSTL-INF) level.
These certifications demonstrate adherence to internationally recognized security and operational standards.
Why Continuous Validation Matters in the AI Era
Artificial intelligence is rapidly becoming embedded within enterprise infrastructure.
AI assistants, machine learning models, automated decision engines, and generative AI applications frequently receive updates, new integrations, and expanded permissions.
Unlike traditional software, AI systems can evolve quickly through retraining, configuration changes, API updates, and new data sources.
This creates a dynamic environment where yesterday’s security assessment may no longer accurately reflect today’s production risks.
Continuous Runtime Security Validation addresses this challenge by ensuring security controls remain effective even as AI workloads evolve alongside cloud infrastructure.
Deep Analysis
The partnership reflects a broader cybersecurity trend: organizations are moving away from reactive security toward continuous verification. Traditional penetration testing has long been considered a best practice, but its value diminishes quickly in environments where code is deployed multiple times a day and infrastructure changes automatically. Continuous validation bridges this gap by combining offensive testing with operational monitoring and rapid remediation.
The integration of Datadog into the service is particularly significant because runtime telemetry provides the contextual data needed to validate whether security controls are functioning under real-world conditions. Instead of relying solely on vulnerability scanners, organizations gain operational intelligence that helps prioritize risks based on actual production behavior.
Financial institutions are increasingly embracing DevSecOps principles, and this offering aligns well with those methodologies. Security is no longer confined to annual audits; it becomes an integral part of the software development and deployment lifecycle.
Organizations implementing similar models may incorporate automation such as:
Continuous Infrastructure Monitoring
terraform plan terraform apply
Kubernetes Security Validation
kubectl get pods -A kubectl get events kubectl describe pod <pod-name>
Runtime Container Inspection
docker ps docker inspect <container_id>
API Security Testing
curl -X GET https://api.example.com/health
Network Exposure Assessment
nmap -sV target-ip
Cloud Configuration Review
aws securityhub get-findings az security assessment list gcloud security posture list
These commands illustrate the types of operational activities commonly associated with continuous runtime validation. When integrated with independent penetration testing and evidence-based remediation, they provide organizations with a far stronger security posture than periodic assessments alone.
The partnership also reflects a growing market demand for measurable security outcomes. Boards and regulators increasingly expect organizations to demonstrate that vulnerabilities are not merely discovered but are actually remediated and independently verified. This evidence-driven approach supports compliance initiatives while improving resilience against increasingly sophisticated cyber threats.
What Undercode Say:
The announcement represents one of the strongest examples of how cybersecurity services are evolving from static assessments into continuous operational assurance. Modern fintech companies deploy software at a pace that traditional penetration testing simply cannot keep up with. By the time a report is delivered, parts of the production environment may already have changed.
Critical Cloud’s operational expertise complements Tarian Labs’ offensive security capabilities in a way that addresses this gap effectively. The separation of responsibilities is particularly noteworthy because it maintains the independence required for credible security validation while ensuring remediation is handled efficiently.
Another important aspect is the focus on runtime environments rather than development environments alone. Many organizations invest heavily in secure development practices but overlook the reality that production systems continue changing after deployment through configuration updates, scaling events, third-party integrations, and AI model updates.
The inclusion of AI workloads is especially timely. As enterprises increasingly rely on generative AI and machine learning systems, continuous validation will likely become a regulatory expectation rather than simply a best practice.
From a business perspective, continuous validation may also reduce long-term operational costs by identifying weaknesses earlier, shortening remediation cycles, and minimizing the likelihood of costly security incidents.
This model aligns closely with Zero Trust principles, where trust is never assumed and security controls must be continuously verified. It also complements DevSecOps by embedding security into operational workflows rather than treating it as a separate audit function.
The Observe, Detect, Validate methodology provides a practical framework that organizations can understand and integrate into existing cloud operations. Instead of replacing traditional penetration testing, it enhances its value by extending the lifecycle of every finding until verified closure is achieved.
For regulated industries such as banking and fintech, the ability to provide evidence-based assurance could significantly improve relationships with auditors, insurers, regulators, and customers alike.
Looking ahead, similar continuous validation services are likely to expand beyond fintech into healthcare, manufacturing, telecommunications, and government sectors where operational resilience is becoming equally critical.
Overall, this partnership highlights an important industry transition—from proving security once to proving security continuously.
✅ Fact: Critical Cloud and Tarian Labs have officially announced a strategic partnership to deliver Continuous Runtime Security Validation across the UK and Ireland. This is consistent with the information presented in the announcement and reflects a legitimate collaboration focused on production security assurance.
✅ Fact: The service combines Critical Cloud’s Managed Runtime Assurance model with Tarian Labs’ offensive security testing, following an Observe, Detect, Validate methodology. The described separation of testing and remediation responsibilities aligns with recognized security governance practices that preserve assessment independence.
✅ Fact: The certifications mentioned—including ISO 27001, Cyber Essentials Plus, Datadog partnership status, CREST practitioners, and NCSC CHECK Team Leader oversight—are credible industry-recognized qualifications that strengthen confidence in the service’s operational and technical capabilities.
Prediction
(+1) Continuous Runtime Security Validation is likely to become a standard requirement for regulated industries as cloud-native applications, APIs, and AI systems continue to evolve at high speed. Organizations will increasingly favor continuous evidence-based assurance over annual penetration testing alone.
(-1) Companies that continue relying solely on periodic security assessments may experience larger security gaps as infrastructure changes outpace traditional testing schedules, potentially increasing regulatory scrutiny and cyber risk exposure.
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: www.itsecurityguru.org
Extra Source Hub (Possible Sources for article):
https://www.digitaltrends.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




