{"id":9939,"date":"2026-10-07T08:25:00","date_gmt":"2026-10-07T08:25:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9939"},"modified":"2026-10-07T08:25:00","modified_gmt":"2026-10-07T08:25:00","slug":"ai-is-turning-offensive-security-into-a-continuous-necessity","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9939","title":{"rendered":"AI is turning offensive security into a continuous necessity"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column \">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">The rise of AI has CISOs facing even more vulnerabilities than ever, resulting in increasingly difficult decisions around what fixes to prioritize.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhen I was a CIO, the hardest part of my job was deciding what not to do,\u201d Snehal Antani, CEO of pentesting platform Horizon3.ai, tells CSO. \u201cAnd if I chose not to fix a vulnerability because I didn\u2019t have the resources or I didn\u2019t think it was important, and that\u2019s how I got popped later, I was going to have a really bad day, right?\u201d<\/p>\n<p class=\"wp-block-paragraph\">And the fear among IT leaders is that those bad days may become more frequent as the growing onslaught of discovered vulnerabilities also gives attackers more flaws to exploit.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhat we are facing now is that AI allows adversaries to scale, run continuous operations, and increases the skill level of what were previously lower-skilled adversaries by using models to make them higher-skilled,\u201d Rich Mogull, chief analyst at the Cloud Security Alliance (CSA) and CEO of Securosis, tells CSO. \u201cWe have a higher rate of change. They have a higher rate of attack.\u201d<\/p>\n<p class=\"wp-block-paragraph\">As a result, CISOs are having to rethink vulnerability management, a necessary strategic shift that is also putting offensive security operations at the center of their programs.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhen I was the chief security and risk officer for Microsoft\u2019s cloud, I mean, hell, we invented Patch Tuesday, right?\u201d <a href=\"https:\/\/www.csoonline.com\/article\/568125\/cso-hall-of-fame-honorees.html\">CSO Hall of Famer<\/a> Edna Conway told attendees at this year\u2019s CSO Awards and Conference in May. \u201cThat concept doesn\u2019t apply anymore. It\u2019s real-time anomaly detection using offensive cybersecurity.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Or, as Horizon3.ai\u2019s Antani puts it: \u201cThe burden of prioritization and deciding what not to do has never been more difficult. And the only way to do that properly is to prove exploitability in production systems using penetration testing and offensive security capabilities.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Offensive security methods, such as pen testing, red teaming, and attack path validation, enable CISOs to test which weaknesses can lead to meaningful compromise.<\/p>\n<p class=\"wp-block-paragraph\">That\u2019s why Conway, Antani, and other security leaders and experts are advising CISOs to level up their <a href=\"https:\/\/www.csoonline.com\/article\/4101929\/offensive-security-takes-center-stage-in-the-ai-era.html\">offensive security strategies<\/a> in an effort to simulate real-world cyber incidents to find the vulnerabilities that can lead to serious system compromises before their adversaries do.<\/p>\n<h2 class=\"wp-block-heading\">Prioritizing fixes requires more frequent pen testing<\/h2>\n<p class=\"wp-block-paragraph\">Most organizations have historically conducted compliance-based penetration tests once a year, or in some circumstances slightly more often. But now, in the AI era, threat actors can exploit vulnerabilities that cause serious problems within hours and minutes, making some form of ongoing penetration testing and monitoring necessary.<\/p>\n<p class=\"wp-block-paragraph\">\u201cYou have to patch that quickly because somebody else using an AI system could find the same vulnerability, like, within hours now,\u201d Nick Winter, SVP of frontier lab security at Gray Swan, tells CSO. \u201cIf you\u2019re an offensive security professional, you need to be deploying these in loops, in an automated, ongoing, always-on fashion so that you\u2019re always finding vulnerabilities very quickly so that then they can also get patched or mitigated very quickly on AI timelines.\u201d<\/p>\n<p class=\"wp-block-paragraph\">What these automated loops can deliver is rapid prioritization, helping CISOs to wade through the tsunami of vulnerability reports generated by frontier models such as Claude Mythos to quickly identify which deserve priority patching.<\/p>\n<p class=\"wp-block-paragraph\">Experts say one of the most urgent priorities in offensive operations is to understand how weaknesses can combine, or how vulnerabilities can be chained.<\/p>\n<p class=\"wp-block-paragraph\">\u201cMaybe there\u2019s a vulnerability that on its own is relatively minor in terms of exploit,\u201d Dan Rapp, chief AI and data officer at Proofpoint, tells CSO. \u201cBut maybe if I chain it with two or three other minor vulnerabilities, all of a sudden, I\u2019ve enabled lateral movement in a way that I wasn\u2019t able to do before.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Some of the more advanced AI frontier models could take this more complex form of security testing to new, \u201cartistic\u201d levels, according to Rapp. \u201cOne of the areas that we\u2019re beginning to look at is how might we use these most capable, without-guardrails-type of models, to simulate what threat actors are doing,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">For all these reasons, defenders think that the compliance-oriented once-a-year pentesting, although still a valuable and in-depth tool in the offensive security toolbox, should be supplemented by continuous monitoring and more frequent testing.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe\u2019re moving more and more to what I believe will be just continuous monitoring all the time, with basically pen testing ourselves all the time, because attackers are probing all the time,\u201d Diana Kelley, CISO of Noma Security, tells CSO.<\/p>\n<h2 class=\"wp-block-heading\">Old-fashioned expertise and the training pipeline still matter<\/h2>\n<p class=\"wp-block-paragraph\">Traditional red teaming has always gone beyond scanning code. Red teamers pick locks, sneak into buildings, and devise elaborate deceptive emails and complex deceptive operations that sometimes involve fake personas <a href=\"https:\/\/www.csoonline.com\/article\/3808813\/tricking-the-bad-guys-realism-and-robustness-are-crucial-to-deception-operations.html\">and even fake offices<\/a> and storefronts.<\/p>\n<p class=\"wp-block-paragraph\">CSA\u2019s Mogull, who now tests every piece of code he writes with AI, still sees a role for human pen testers. \u201cI have a lot of friends who are pen testers and red teamers. They\u2019ll still come in, but now they\u2019re bringing the bigger guns, the big game experience,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">Gray Swan\u2019s Winter agrees that even with continuous monitoring and pen testing, the kind of periodic measures that traditionally make up offensive security can bring a level of depth and digital evidence that instant and automated tests can\u2019t provide. Implementing more autonomous measures because of the accelerated pace of AI \u201cisn\u2019t to say that SOC 2 compliance, your annual pen test that might go a little deeper, aren\u2019t useful because you do have to probe those systems at depth and also kind of prove it,\u201d Winter says.<\/p>\n<p class=\"wp-block-paragraph\">Noma Security\u2019s Kelley emphasizes that even if AI monitoring and pen testing can outperform traditional methods, it\u2019s crucial that cybersecurity programs retain human personnel who have the <a href=\"https:\/\/www.csoonline.com\/article\/571483\/10-essential-skills-and-traits-of-ethical-hackers.html\">foundational offensive security skills<\/a> to guide the automated processes that might overshadow the old modes of testing.<\/p>\n<p class=\"wp-block-paragraph\">\u201cEven though they don\u2019t have to do all of the work manually, understanding the techniques and the first principles and the foundations of what makes an exploit path, how to manage these tools, how to control these tools is going to be a really important and useful skill,\u201d Kelley says.<\/p>\n<p class=\"wp-block-paragraph\">Preserving that expertise also requires developing the next generation of offensive security professionals. Mogull worries that automating entry-level work could eliminate the experience junior practitioners need to become senior experts.<\/p>\n<p class=\"wp-block-paragraph\">\u201cYou can still hire lower-level people, you train them on the AI tooling, but then you also have them do some manual validation, not punitively, but to keep their skills up,\u201d Mogull says. \u201cAnd so that they have kind of some of those security fundamentals in there.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Proofpoint\u2019s Rapp agrees that the industry still needs cyber professionals steeped in old-school offensive operations and that organizations should probably steer clear of their own DIY methods.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIn terms of concocting and running red team exercises yourself, the AI model capabilities are getting to the point where it is pretty simple to do a lot of stuff that used to require a relatively high degree of specialization,\u201d Rapp says. \u201cBut for something like cybersecurity, I don\u2019t think I\u2019d recommend that just yet.\u201d<\/p>\n<h2 class=\"wp-block-heading\">How CISOs can navigate the new offensive security environment<\/h2>\n<p class=\"wp-block-paragraph\">For organizations without an established offensive security operation, Horizon3.ai\u2019s Antani argues that building one in-house, even with AI agents, is the wrong move.<\/p>\n<p class=\"wp-block-paragraph\">\u201cSo, the reality is that most organizations don\u2019t have an internal red team at all,\u201d he says. \u201cIt\u2019s a fallacy to think that CISOs can build their own offensive capability with the limited talent that they have in-house and AI agents. Don\u2019t try to build it yourself. It\u2019s extremely hard and expensive.\u201d<\/p>\n<p class=\"wp-block-paragraph\">For organizations that rely on external firms for offensive operations, Antani advises that CISOs make sure they understand those firms\u2019 AI plans. \u201cIf you\u2019re already working with a penetration testing firm, you want to make sure that you understand their AI hacking roadmap and strategy,\u201d he says. \u201cOr you need to select new technology partners.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Noma Security\u2019s Kelley thinks that how CISOs manage AI-based offensive operations depends on what kind of business their teams support. \u201cGenerally, you see [robust red teams] only at very large companies,\u201d she says. She had them when she worked at IBM and Microsoft, and sees them today in large financial institutions.<\/p>\n<p class=\"wp-block-paragraph\">But \u201cin healthcare, you may see nobody on the red team. They may still be on the once-a-year pen test or, maybe, they\u2019ve got a company that they\u2019re outsourcing to where they\u2019re doing it once a month.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Antani thinks most organizations would be better off concentrating their resources on remediation. He says, \u201cWhere can they invest in automation to accelerate remediation? That\u2019s the part of the problem that the CISO should focus on organically or internally while they find the right trusted outside partner to bring that offensive capability to them.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>The rise of AI has CISOs facing even more vulnerabilities than ever, resulting in increasingly difficult decisions around what fixes to prioritize. \u201cWhen I was a CIO, the hardest part of my job was deciding what not to do,\u201d Snehal Antani, CEO of pentesting platform Horizon3.ai, tells CSO. \u201cAnd if I chose not to fix [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9925,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9939","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9939"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9939"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9939\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9925"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9939"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9939"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9939"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}