TL;DR: Rigid two-week pentest scopes and checklist-driven coverage can cut off discovery before investigators understand how an exploit path really forms, while intuition-driven offensive security prioritises footholds, pivot points, and business impact, according to Sprocket Security. The shift matters because it rewards adversary thinking, deeper documentation, and human judgment over finding counts and ticket volume.
NHIMG editorial — based on content published by Sprocket Security: Ahead of the Breach episode on intuition-driven offensive security
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, with 46% confirmed and 26% suspected.
Questions worth separating out
Q: How should security teams measure offensive security programmes beyond finding counts?
A: Measure whether the work changes decisions.
Q: When does fixed pentest scope become a liability?
A: Fixed scope becomes a liability when evidence suggests a connected attack path but the test ends before investigators can follow it.
Q: What do security teams get wrong about AI safety testing?
A: The common mistake is treating AI safety testing as if it were just another security scan.
Practitioner guidance
- Rebuild pentest success metrics around impact Track whether offensive work changes remediation priority, threat models, or executive decisions rather than only counting findings and tickets.
- Allow scope expansion when evidence justifies it Set a clear rule that investigators can widen scope after peer review when a lead suggests a connected access path, cloud dependency, or identity trust boundary.
- Use AI as a research accelerator, not a verdict engine Permit AI to draft PoCs, summarise patch behaviour, and identify hot spots, but require human confirmation before any result is treated as exploitable or material.
What's in the full article
Sprocket Security's full podcast covers the operational detail this post intentionally leaves for the source:
- How Andy Grant structures open-scope offensive work without losing accountability or documentation discipline
- Examples of the internal guardrails used to justify deeper investigation when a lead appears worth following
- The specific ways AI is used to speed up proof-of-concept work, patch analysis, and black-box adversarial thinking
- How the team decides whether a finding is valuable even when no critical vulnerability is uncovered
👉 Read Sprocket Security's discussion on intuition-driven offensive security →
Intuition-driven offensive security: what does it change for teams?
Explore further