Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

NetSPI and Synack merge: what changes for security testing coverage?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20360
Topic starter  

TL;DR: Expert-led offensive testing is increasingly a scale and orchestration problem, with the company arguing that routing, context preservation, and validation matter more than adding agents or headcount, according to Synack. The real security lesson is that coverage only improves when expert judgment survives every handoff and production constraints are tested continuously.

NHIMG editorial — based on content published by Synack: Putting Experts on the Problems Only Experts Can Solve

Questions worth separating out

Q: What breaks when offensive testing loses context between handoffs?

A: When context is lost between handoffs, the next tester or agent starts from a blank page and may repeat work, miss escalation clues, or fail to confirm whether the issue is real.

Q: Why do production testing results differ from benchmark results?

A: Production testing includes expired sessions, rate limits, changing workflows, and authentication failures that benchmarks usually hide.

Q: How should security teams decide when agent-assisted testing needs human escalation?

A: Teams should escalate when the agent is looping, when the result depends on business logic or cross-system state, or when evidence is not strong enough to support a risk claim.

Practitioner guidance

  • Define explicit escalation rules for test handoffs Document when work must move from an agent or junior tester to a specialist, and require the receiving party to inherit evidence, prior attempts, and the reason the escalation happened.
  • Preserve state across production-like test sessions Track authentication state, retries, rate limits, and workflow transitions so assessments do not reset at every boundary and lose the context needed to reach stateful flaws.
  • Move validation earlier in the testing workflow Require reproducibility checks at each handoff, including whether the target is reachable as deployed and whether the impact claim is supported by evidence.

What's in the full analysis

Synack's full blog covers the operational detail this post intentionally leaves for the source:

  • The merger rationale and the specific delivery-model differences between consultant-led testing and agent-assisted coverage
  • The article's examples of how validation should move earlier in the workflow, including how evidence survives each handoff
  • The platform-and-harness discussion behind production testing, including state retention, escalation logic, and scope control
  • The practical implications of combining two offensive security operating models into a single testing system

👉 Read Synack's analysis of the NetSPI merger and expert-led testing scale →

NetSPI and Synack merge: what changes for security testing coverage?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19951
 

Expert scale only matters when the system preserves judgment: the real bottleneck in offensive security is not simply finding more talent, but ensuring expertise survives routing, state changes, and escalation between humans and automation. In practice, that is a governance problem around evidence retention and work handoff, not just a staffing problem. Programmes that lose context between stages create more activity, not better assurance. The practitioner conclusion is that coordination design now sits alongside skill as a security control.

A question worth separating out:

Q: How can organisations tell whether their testing programme is actually validating risk?

A: A programme is validating risk when findings are reproducible, the target is reachable as deployed, and the evidence supports the claimed impact. If those checks happen only at the end, the team is probably measuring volume, not assurance.

👉 Read our full editorial: NetSPI and Synack merge: what it means for expert-led testing scale



   
ReplyQuote
Share: