Attackers automated the patient part
Reconnaissance, pretexting and exploit assembly now run at machine speed. A quarter of malicious breaches last year had AI on the attacker’s side — a 56% jump in a single year.
AI is on both sides of this now. A quarter of malicious breaches last year were AI-enabled, and they cost about a million dollars more than the rest. Here is what AI genuinely changes about testing, what it still can’t do, and how to weigh what it’s worth to you.
Nothing about your obligations changed this year. What changed is the speed on the other side of the fight, and how quickly your own estate moves underneath you.
Reconnaissance, pretexting and exploit assembly now run at machine speed. A quarter of malicious breaches last year had AI on the attacker’s side — a 56% jump in a single year.
Cloud, SaaS and new features ship continuously. A report from last spring describes a system you no longer run.
Scanners produce volume. Without proof that something is genuinely reachable, your team spends its week sorting noise instead of closing risk.
Copilots, assistants and agents are part of your attack surface now, and most testing programs have never once looked at them.
These are the methods that have earned their place in offensive security — described by what each one is worth to you, not by the tooling behind it.
Goal-directed agents map everything you expose and keep mapping it, across a surface far too large to walk by hand.
Not a list of weaknesses but the route that joins them — the way an attacker actually reaches your data.
Your environment re-examined as it changes, so a gap opened by this week’s release doesn’t wait a year to be found.
Thousands of candidate issues narrowed to the few that are real, reachable and worth your engineers’ time.
Your people tested against the AI-assisted pretexting and voice cloning attackers already use — safely, and only with your authorization.
Prompt injection, tool abuse and memory poisoning against the AI features you ship. A different craft from testing a web app.
This is the part of the conversation that usually gets waved away as hype. It is not hype — it is published, peer-reviewed research, and every one of these has working code behind it. We test you against them because your attackers already read the same papers.
Autonomous web-testing research now uses generative models to produce cross-site scripting and SQL injection payloads aimed squarely at getting past a web application firewall. Tested against Azure WAF and OWASP’s ModSecurity rules, 8% of generated samples went straight through. Eight percent sounds survivable until you remember that an attacker needs one.
Conventional cracking depends on a human choosing the right wordlist and writing the right mangling rules. PassGAN learns the distribution of real leaked passwords instead, and generates candidates those rules would never have produced. Its strongest result was not beating the classic tools — it was finding passwords alongside them that they missed entirely.
MalGAN and the work that followed it do not rewrite malware. They pad it with irrelevant, benign-looking features until a classifier stops objecting — driving the true-positive rate of a black-box detector toward zero. Worse for the defender, the generator learns faster than the detector can be retrained, so the gap does not close on its own.
Generative models can compose an attacker’s face with a target’s features until face verification accepts it. More unsettling still is the master-face work: EU-funded research generated a handful of synthetic faces that authenticated against a meaningful share of an entire population, with no knowledge of any individual. If your access control ends at a face, this is your threat model.
Attack-inspired generative models produce an evasion sample in under a hundredth of a second, against more than three hours for the classical optimization methods. They need no gradients, which means they work against ordinary classifiers — random forests, not only neural networks — and they work from the outside. The same property that makes them dangerous makes them useful for testing your own models at scale.
Generative models write the email, clone the voice and produce the video. Every tell your awareness training taught people to watch for — the odd phrasing, the wrong logo, the accent that did not fit — was a symptom of the effort an attacker used to have to spend. That effort is now a few minutes of compute.
Every technique above is published, peer-reviewed research, cited here because it describes what your attackers can already do — not a CyberlySecure product. Sources include GAN-based autonomous penetration testing for web applications (Chowdhary et al., Sensors, 2023), PassGAN, MalGAN and its successors, EU-funded master-face research, and the AdvGAN / GAP / AI-GAN line of adversarial-sample work.
Automation that reports confidently and wrongly doesn’t save your team time, it spends it. That is why everything we find ends with a certified human before it reaches you — and why the report carries their name.
How we work safelyTesting isn’t bought against a wish list, it’s bought against a risk. Here is the comparison in the terms finance actually weighs.
Published industry averages put a professional penetration test between roughly $10,000 and $30,000 in 2026, depending on scope.
The global average reached $4.99M last year, up 12% — and about $6M when AI was part of the attack.
Machine breadth makes year-round coverage affordable: subscription testing is reported to run roughly 30% below traditional engagement pricing.
Not a document. The chance to close a gap on your schedule instead of an attacker’s — and the evidence that you did.
| What you care about | Once a year, by hand | Year-round, AI breadth + human depth |
|---|---|---|
| What changed since the last test | Waits for the next engagement | Re-examined as it ships |
| Breadth across a large estate | Sampled by hand | Machine breadth, human depth |
| What lands on your engineers | A report at the end | Confirmed findings, as they’re found |
| False alarms | Filtered by the tester | Filtered by the tester |
| Evidence for auditors | Signed attestation | Signed attestation, kept current |
| Cost shape | One large bill a year | Spread across the year |
Figures cited: IBM / Ponemon Institute, Cost of a Data Breach Report 2026 · OWASP Top 10 for LLM Applications (2026) and OWASP Top 10 for Agentic Applications · MITRE ATLAS · Cloud Security Alliance AI Controls Matrix · the EU AI Act. Penetration testing price ranges are published industry averages for 2026, not our pricing.
Tell us what you need protected. You’ll talk to a tester, not a sales rep.
Not sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.
Free. No obligation.