Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI-capable PTaaS is changing the testing model, are your controls ready?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Frontier AI models are accelerating offensive security faster than most teams can track, according to Synack, with Anthropic’s Mythos Preview reportedly solving expert-level hacking tasks 73% of the time and OpenAI’s cyber-focused models jumping from 27% to 76% on CTF benchmarks in three months. The practical implication is that point-in-time pentesting no longer matches the pace of attack-surface change, and continuous validation becomes the governing model.

NHIMG editorial — based on content published by Synack: What GigaOm and Synack Got Right About AI Pentesting, and what Mythos means for PTaaS

By the numbers:

Questions worth separating out

Q: How should security teams use AI-assisted penetration testing without losing trust in the results?

A: Use AI-assisted testing to widen discovery, then force a human validation step before any output becomes a confirmed finding.

Q: Why do frontier AI models change the way organisations should think about testing cadence?

A: Because the attack surface is now being exercised at machine speed, annual or quarterly testing leaves too much time for exposure to grow stale.

Q: What do organisations get wrong about AI-assisted pentesting?

A: They often assume the model itself is the product, when the real control surface is the surrounding orchestration, evidence handling, and permissions model.

Practitioner guidance

  • Implement continuous validation for high-risk assets Move beyond annual or quarterly pentests for internet-facing systems, sensitive applications, and identity paths.
  • Require human validation before triage closes Use AI to expand coverage, but require a vetted researcher to confirm exploitability, chain plausibility, and business impact before issues reach remediation queues.
  • Tie PTaaS outputs to NHI governance Feed testing results into service account review, secret rotation, and access minimisation workflows so credential-related findings do not sit in a separate remediation stream.

What's in the full article

Synack's full blog post covers the operational detail this analysis intentionally leaves for the source:

  • How the Synack team distinguishes true agentic behaviour from summarisation or pattern-matching in PTaaS tools
  • The specific questions Synack recommends asking vendors when evaluating AI-enabled penetration testing workflows
  • Examples of where human researchers still outperform models in business logic, multi-step abuse, and contextual judgment
  • How Synack positions continuous validation across reconnaissance, chaining, and triage in its platform model

👉 Read Synack's analysis of AI-capable pentesting and continuous validation →

AI-capable PTaaS is changing the testing model, are your controls ready?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

AI-capable pentesting is becoming a continuous control, not a service event. When models can reason through weaknesses and retry paths faster than a human schedule allows, the old audit cadence no longer describes the real risk. PTaaS now sits closer to continuous validation than periodic assurance, which changes how security leaders budget, scope, and measure coverage. Practitioners should treat testing freshness as a governance metric, not a reporting artefact.

A question worth separating out:

Q: How can organisations tell whether their PTaaS programme is keeping up with modern threats?

A: Look for freshness, not just completion. If your latest test report lags behind major code, cloud, or identity changes, the programme is describing an old environment. Strong programmes retest after significant change and connect findings directly to remediation ownership, especially for exposed credentials and privileged paths.

👉 Read our full editorial: AI-capable pentesting is shifting from reports to continuous validation



   
ReplyQuote
Share: