Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Agentic AI in pentesting: what security leaders need to know


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 17031
Topic starter  

TL;DR: Security leaders are testing only 32% of their attack surface on average while 68% remains untested, according to Synack’s Gartner SRM 2026 commentary, which argues that AI-era adversaries now move on a much faster clock than conventional validation cycles. Human oversight remains essential because agentic systems can chain vulnerabilities, but current programmes still struggle to distinguish real adaptive capability from automated scanning and polished reporting.

NHIMG editorial — based on content published by Synack: What I Told Security Leaders at Gartner SRM 2026 Key Takeaways

Questions worth separating out

Q: How should security teams evaluate agentic pentest tools?

A: Evaluate the full workflow, not the model alone.

Q: Why does low pentest coverage create a governance problem, not just a technical one?

A: Because incomplete coverage means leaders are making risk decisions with a false sense of validation.

Q: What do security teams get wrong about AI safety testing?

A: The common mistake is treating AI safety testing as if it were just another security scan.

Practitioner guidance

  • Define validation coverage as a measurable control. Track what percentage of externally reachable assets, privileged paths, and high-value systems are actually exercised in a quarter, then tie that to risk acceptance reporting rather than tool counts.
  • Require adaptive proof in vendor evaluations. Ask every testing vendor to show how the system changes tactics after a failed first attempt, because repeated pattern matching is not the same as agentic reasoning.
  • Prioritise exploitable paths with business context. Use exploitability indicators, asset criticality, and privilege reach to rank findings, instead of relying on raw severity scores that overstate low-context issues.

What's in the full article

Synack's full article covers the operational detail this post intentionally leaves for the source:

  • How the team distinguishes automation, generative AI, and agentic AI in offensive testing workflows
  • The practical breakdown of human plus AI pentesting roles, including what Sara handles versus what researchers handle
  • The Omdia survey context behind the 32% coverage figure and the 55% communication gap
  • The questions leaders should use to pressure-test claims about adaptive attack chaining and validation quality

👉 Read Synack's analysis of machine-speed adversaries and pentest coverage gaps →

Agentic AI in pentesting: what security leaders need to know?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 16618
 

Machine-speed adversaries expose a validation problem, not just a tooling problem. The article is right to frame the issue around coverage because organisations do not have a visibility deficit alone, they have a time-to-validate deficit. Continuous validation matters more than periodic assurance when attack paths can be discovered and chained in hours, not quarters. For identity teams, that means privilege boundaries and trust assumptions need to be tested as living controls, not annual artefacts.

A question worth separating out:

Q: Who is accountable when agentic testing misses a critical path?

A: Accountability sits with the team that defined the scope, accepted the coverage gap, and approved the validation method. Governance frameworks should treat testing scope, review cadence, and evidence thresholds as explicit risk decisions, not informal preferences buried in tool selection.

👉 Read our full editorial: Machine-speed adversaries are widening the pentest coverage gap



   
ReplyQuote
Share: