> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> AI is turning offensive security into a continuous necessity

[SOURCE] CSO Online [DATE: 07/10/2026 08:25] [LANGUAGE: EN]
AI is turning offensive security into a continuous necessity
The rise of AI has CISOs facing even more vulnerabilities than ever, resulting in increasingly difficult decisions around what fixes to prioritize. “When I was a CIO, the hardest part of my job was deciding what not to do,” Snehal Antani, CEO of pentesting platform Horizon3.ai, tells CSO. “And if I chose not to fix a vulnerability because I didn’t have the resources or I didn’t think it was important, and that’s how I got popped later, I was going to have a really bad day, right?” And the fear among IT leaders is that those bad days may become more frequent as the growing onslaught of discovered vulnerabilities also gives attackers more flaws to exploit. “What we are facing now is that AI allows adversaries to scale, run continuous operations, and increases the skill level of what were previously lower-skilled adversaries by using models to make them higher-skilled,” Rich Mogull, chief analyst at the Cloud Security Alliance (CSA) and CEO of Securosis, tells CSO. “We have a higher rate of change. They have a higher rate of attack.” As a result, CISOs are having to rethink vulnerability management, a necessary strategic shift that is also putting offensive security operations at the center of their programs. “When I was the chief security and risk officer for Microsoft’s cloud, I mean, hell, we invented Patch Tuesday, right?” CSO Hall of Famer Edna Conway told attendees at this year’s CSO Awards and Conference in May. “That concept doesn’t apply anymore. It’s real-time anomaly detection using offensive cybersecurity.” Or, as Horizon3.ai’s Antani puts it: “The burden of prioritization and deciding what not to do has never been more difficult. And the only way to do that properly is to prove exploitability in production systems using penetration testing and offensive security capabilities.” Offensive security methods, such as pen testing, red teaming, and attack path validation, enable CISOs to test which weaknesses can lead to meaningful compromise. That’s why Conway, Antani, and other security leaders and experts are advising CISOs to level up their offensive security strategies in an effort to simulate real-world cyber incidents to find the vulnerabilities that can lead to serious system compromises before their adversaries do. Prioritizing fixes requires more frequent pen testing Most organizations have historically conducted compliance-based penetration tests once a year, or in some circumstances slightly more often. But now, in the AI era, threat actors can exploit vulnerabilities that cause serious problems within hours and minutes, making some form of ongoing penetration testing and monitoring necessary. “You have to patch that quickly because somebody else using an AI system could find the same vulnerability, like, within hours now,” Nick Winter, SVP of frontier lab security at Gray Swan, tells CSO. “If you’re an offensive security professional, you need to be deploying these in loops, in an automated, ongoing, always-on fashion so that you’re always finding vulnerabilities very quickly so that then they can also get patched or mitigated very quickly on AI timelines.” What these automated loops can deliver is rapid prioritization, helping CISOs to wade through the tsunami of vulnerability reports generated by frontier models such as Claude Mythos to quickly identify which deserve priority patching. Experts say one of the most urgent priorities in offensive operations is to understand how weaknesses can combine, or how vulnerabilities can be chained. “Maybe there’s a vulnerability that on its own is relatively minor in terms of exploit,” Dan Rapp, chief AI and data officer at Proofpoint, tells CSO. “But maybe if I chain it with two or three other minor vulnerabilities, all of a sudden, I’ve enabled lateral movement in a way that I wasn’t able to do before.” Some of the more advanced AI frontier models could take this more complex form of security testing to new, “artistic” levels, according to Rapp. “One of the areas that we’re beginning to look at is how might we use these most capable, without-guardrails-type of models, to simulate what threat actors are doing,” he says. For all these reasons, defenders think that the compliance-oriented once-a-year pentesting, although still a valuable and in-depth tool in the offensive security toolbox, should be supplemented by continuous monitoring and more frequent testing. “We’re moving more and more to what I believe will be just continuous monitoring all the time, with basically pen testing ourselves all the time, because attackers are probing all the time,” Diana Kelley, CISO of Noma Security, tells CSO. Old-fashioned expertise and the training pipeline still matter Traditional red teaming has always gone beyond scanning code. Red teamers pick locks, sneak into buildings, and devise elaborate deceptive emails and complex deceptive operations that sometimes involve fake personas and even fake offices and storefronts. CSA’s Mogull, who now tests every piece of code he writes with AI, still sees a role for human pen testers. “I have a lot of friends who are pen testers and red teamers. They’ll still come in, but now they’re bringing the bigger guns, the big game experience,” he says. Gray Swan’s Winter agrees that even with continuous monitoring and pen testing, the kind of periodic measures that traditionally make up offensive security can bring a level of depth and digital evidence that instant and automated tests can’t provide. Implementing more autonomous measures because of the accelerated pace of AI “isn’t to say that SOC 2 compliance, your annual pen test that might go a little deeper, aren’t useful because you do have to probe those systems at depth and also kind of prove it,” Winter says. Noma Security’s Kelley emphasizes that even if AI monitoring and pen testing can outperform traditional methods, it’s crucial that cybersecurity programs retain human personnel who have the foundational offensive security skills to guide the automated processes that might overshadow the old modes of testing. “Even though they don’t have to do all of the work manually, understanding the techniques and the first principles and the foundations of what makes an exploit path, how to manage these tools, how to control these tools is going to be a really important and useful skill,” Kelley says. Preserving that expertise also requires developing the next generation of offensive security professionals. Mogull worries that automating entry-level work could eliminate the experience junior practitioners need to become senior experts. “You can still hire lower-level people, you train them on the AI tooling, but then you also have them do some manual validation, not punitively, but to keep their skills up,” Mogull says. “And so that they have kind of some of those security fundamentals in there.” Proofpoint’s Rapp agrees that the industry still needs cyber professionals steeped in old-school offensive operations and that organizations should probably steer clear of their own DIY methods. “In terms of concocting and running red team exercises yourself, the AI model capabilities are getting to the point where it is pretty simple to do a lot of stuff that used to require a relatively high degree of specialization,” Rapp says. “But for something like cybersecurity, I don’t think I’d recommend that just yet.” How CISOs can navigate the new offensive security environment For organizations without an established offensive security operation, Horizon3.ai’s Antani argues that building one in-house, even with AI agents, is the wrong move. “So, the reality is that most organizations don’t have an internal red team at all,” he says. “It’s a fallacy to think that CISOs can build their own offensive capability with the limited talent that they have in-house and AI agents. Don’t try to build it yourself. It’s extremely hard and expensive.” For organizations that rely on external firms for offensive operations, Antani advises that CISOs make sure they understand those firms’ AI plans. “If you’re already working with a penetration testing firm, you want to make sure that you understand their AI hacking roadmap and strategy,” he says. “Or you need to select new technology partners.” Noma Security’s Kelley thinks that how CISOs manage AI-based offensive operations depends on what kind of business their teams support. “Generally, you see [robust red teams] only at very large companies,” she says. She had them when she worked at IBM and Microsoft, and sees them today in large financial institutions. But “in healthcare, you may see nobody on the red team. They may still be on the once-a-year pen test or, maybe, they’ve got a company that they’re outsourcing to where they’re doing it once a month.” Antani thinks most organizations would be better off concentrating their resources on remediation. He says, “Where can they invest in automation to accelerate remediation? That’s the part of the problem that the CISO should focus on organically or internally while they find the right trusted outside partner to bring that offensive capability to them.”
[messages.read_original_source] →