From Annual Pen Tests to Continuous Penetration Testing Services: Why CTOs Are Shifting Their VAPT Strategy