
Pen testing works and obviously, remains a critical tool in application validation. However intermittent pen testing is never going to be enough for infrastructure that changes every day. Security teams face an increasing set of challenges. They need support in pen test prep, remediation and readiness… but how can this be provided in an always-on model?
That's the problem we set out to solve internally, before we ever thought about building a product. But we’ve built the product - we call the result Peregrine.
Peregrine is a continuous penetration testing platform. Instead of a snapshot taken once or twice a year, it watches your digital estate around the clock, catching exposures, drifted configurations and vulnerable dependencies as they appear rather than weeks later.
Where it finds something fixable, it can open the pull request and run the retest itself, so evidence for your next audit is already timestamped and waiting.
Peregrine doesn't replace your third-party pen test, and it isn't meant to. What it does is address the risk of costly remediation and re-testing efforts. Instead of finding out what’s been wrong for weeks, and paying for the expensive remediation sprint and the repeat test that follows, using Peregrine, you're closing the gaps continuously. The annual test becomes a confirmation of a system in place, not a source of surprises.
That's what we mean by moving towards this “right and ready first time” model for security. Not one clean scorecard once a year, but a secure setup that's sound by default, every day in between.
We've built our reputation at Marino Software on software, made human: technology that's rigorous underneath, but reliable and responsive for the people who depend on it.
For the critical infrastructure we work on, that reliability isn't a nice-to-have. Availability and responsiveness are critical components of the service. A transport network, a bank, a hospital system doesn't get to be "mostly up." Peregrine is an extension of that same commitment, applied to security rather than uptime.
It's also part of something bigger we believe in: citizen critical services. We build pen testing platforms like Peregrine because the public and the organisations serving them deserve software that's dependable by design, not just software that's fast to ship. Guaranteeing availability, and getting better software into people's hands faster, is our goal.
We've been running Peregrine with a small number of our public and private sector clients (such as Irish Rail and Veracity). The results so far have been unprecedented and are bringing our clients closer to that ‘right and ready first time’ position when it comes to 3rd party pen testing.
We’re now keen to bring the evidence for Peregrine to prospective clients who are focused on meeting an increasingly complex set of cybersecurity and availability challenges.
If continuous pen testing sounds like something your organisation should be exploring, we'd like to hear from you. We're offering free, no-obligation 1:1 consultations to walk through the operational and commercial case for Peregrine, and whether it's a fit for your environment.
More broadly, Marino is working on a number of software validation tools just like Peregrine. We’re looking forward to releasing these - client-first - in the coming months.
Get in touch to arrange a conversation, or find out more at get-peregrine.io.

Have a project in mind, or just starting to think one through? We’re good at both.
Get in touch