Why penetration testing must move at the speed of attackers
Thu, 20th Aug 2026 (Today)
I have sat through enough post-penetration-test debriefs to recognise the moment when a room suddenly goes quiet. . It is never the finding on page one of the report, the exposed port or the outdated library that everyone half expected. It is usually the third or fourth finding , the one that looks almost routine on its own, until someone in the room says what it connects to. That moment changed how I think about penetration testing.
For years, the industry has asked one question above all others: does the organisation have vulnerabilities? I believe that question is now incomplete. A stolen password might once have been treated primarily as a compromised account. Today, it may be the beginning of a much broader attack path.
Modern stealer malware extracts browser credentials, session tokens and other authentication data straight from a victim's device. Attackers turn that into access, then sell it, reuse it or combine it with other weaknesses to enable account takeover, business email compromise, fraud and deeper intrusion.
The real question therefore is not whether an organisation has vulnerabilities. It is what an attacker could do right now with the access and weaknesses already sitting unnoticed across its environment, and whether the organisation's defenders can identify those paths before an attacker does. . This is the problem, I believe AI is starting to help us solve.
Our threat intelligence team recently traced how far malware threats have evolved. . One malware attack campaign used ACRStealer delivered through abused Google Drive access, riding on a platform employees already trusted. Another relied on ClickFix, a technique that tricks victims into carrying out the malicious step themselves, allowing the attack to slip past defences built to detect an external actor.
Attackers no longer need to make a complex cyber-attack. They need a familiar workflow and a moment of trust.
The malware itself is only half the story. What happens after the theft is where the greater risk lies. A browser credential or session token becomes an entry point. From there an attacker goes looking for other accounts, exposed services or applications that can be reached from that first breach. A privilege weakness that looked relatively minor when viewed in isolation in a report, can turn serious once it is combined with valid access. Access itself becomes the weapon.
Traditional penetration testing can struggle here because of how reports are structured. . A standard report might list an exposed service, a vulnerable application and an over privileged account as three separate findings. An attacker does not see three separate findings. They see one route through.
Experienced human testers have always tried to identify and validate these routes , but doing so manually takes time. AI tools can examine and prioritise far more possible connections than a human team could assess manually within the same period. They can help correlate compromised credentials with exposed assets, model possible privilege-escalation paths and repeatedly check whether changes to an environment have created new attack routes.
But speed and scale are not the whole story. Finding a vulnerability and understanding an attack are different jobs.
An automated system can flag an unusual response or successfully run a testing technique. But it still takes an experienced tester to judge whether the behaviour represents a genuine issue, whether the proposed attack path is realistic and what an attacker could actually gain. Business context matters as much as the technical detail of what is possible . Breaching an isolated system is not the same as compromising an application handling customer data.
A finding that looks severe in isolation might carry limited real impact. Conversely, several moderate findings can combine to create a genuine route toward something sensitive. Automation can reveal possible connections, but human judgment is needed to decide which ones genuinely matter.
This is why I do not believe a penetration tester's job is disappearing. But it is changing shape.
As AI takes on more reconnaissance, repetitive testing and initial analysis, experienced testers can spend their time investigating unusual paths, validating results and on the judgement calls that determine business risk.
That shift needs firm guardrails to be implemented successfully. No organisation should hand an automated system permission to test everything it can reach. Testing still needs a defined scope, authorised targets and clear rules, particularly for anything involved with production or customer data. Every AI generated finding should also be reviewed by a qualified human before it informs a business decision.
That balance matters more with every year as attackers increasingly adopt the same AI automation. A stolen session can be used the moment it is stolen. A compromised credential is no less dangerous because the next scheduled penetration test is six months away.
That gap, between when access is stolen and when a scheduled test might identify it, is the greatest flaw in the traditional testing cycle. Attackers get access today and immediately start probing for ways to expand it.Defenders often only discover the same paths exist when the next scheduled assessment finally arrives.
AI gives organizations of all sizes a real chance to narrow that gap. Organisations can use automation to check for new attack paths continuously as credentials, applications, permissions and exposed assets change. Human testers can then concentrate their judgment on validating the paths most likely to produce meaningful impact.
The evolution of stealer malware is a warning worth taking seriously. Attackers do not need a sophisticated exploit to establish a foothold. A stolen credential, an abused legitimate service or a ClickFix style trick is often enough. From there they look for ways to turn that foothold into something bigger.
I believe the next generation of penetration testing should not be judged by how many vulnerabilities show up in a report. It should be judged by how well a security team can identify, validate and disrupt the attack paths that are actually realistic for their organisation.
AI brings the speed and scale to examine far more possibilities than any human team could assess manually. Experienced testers provide the context and judgment needed to determine which of those possibilities actually matter.
Today, access can turn into an operational foothold within hours. Waiting for the next annual assessment to find out what an attacker could do gets harder to justify by the day. So I believe our industry should ask a more urgent question: if someone gained access to your systems today, what could they actually do with it?