OPENLANE, a leading digital marketplace for wholesale vehicles, partners with Evolve Security to managed its advanced offensive security program.
In this customer spotlight, Rob, explains the importance of continuous penetration testing and how essential the human-in-the-loop element is to improve signal to noise ratio, identifying high-impact exposures and improving overall resilience.
Transcript
Jason Rowland:
Tell us a little bit about your company and your role.
Rob Tincher:
I am the Application Security Manager at OPENLANE. For those who don't know, OPENLANE is a digital marketplace that handles the end-to-end vehicle sales operations for buyers and sellers.
In my role, my job is to ensure that we implement security into our development operations in a seamless fashion.
Jason Rowland:
How do you think continuous pen testing plays a role in the quick identification and triage of vulnerabilities as patches are released?
Rob Tincher:
As we progress into more AI-validated exploits and AI-targeted attack vectors, what I'm going to see is that continuous pen testing becomes a necessity — it is not going to be a luxury at that point.
You can't go and do a point-in-time assessment; you're already going to be behind by the time that assessment is complete.
Jason Rowland:
One of the things we'll provide to OPENLANE is micro emulations. Talk a little bit about the value of having a continuous pen test operation that can validate your detections inside your SIEM or other defensive technologies.
Rob Tincher:
Being able to chain those events together — being able to see the entire attack chain in operations — provides value not only to myself but to my organization, as we evaluate how particular low- or medium-severity threats can now impact us at a more critical severity.
Jason Rowland:
What made you go with Evolve Security?
Rob Tincher:
We were looking for that human element — that validation piece that automated pen testing was not hitting the mark on.
We had cases where I was reviewing over 50% of the vulnerabilities or exploits that autonomous pen testing was identifying, and ultimately those were false positives. I needed someone in front of those to contextualize, to understand: here are the true threats, here is what data is exposed, here are the attack vectors you need to patch.
Jason Rowland:
We had done testing for you before in a point-in-time manner. How much credibility did that add to your decision-making process for choosing Evolve?
Rob Tincher:
It was a huge decision-maker. Your folks ended up identifying some gaps we had never considered, even with two or three pen testing companies previously.
.webp)



