The Rise and Fall of Automated Pentesting: What Infosec Pros Think (2026)

The world of cybersecurity is abuzz with a fascinating debate: the rise and fall of automated pentesting tools. It's a story that highlights the complexities of relying on technology for critical tasks and the ever-evolving nature of security threats.

The Rise and Fall of Automated Pentesting

In a recent report, offensive security firm Cobalt revealed a significant shift in the cybersecurity landscape. Last year, 29% of security professionals were open to fully autonomous pentesting, but that number has plummeted to a mere 9% in the latest survey. What caused this rapid decline in enthusiasm?

According to Cobalt, the issue lies with the tools' inability to detect critical vulnerabilities. A staggering 78% of respondents experienced critical false negatives, meaning the automated scanners failed to identify serious flaws. This is particularly concerning in AI-infused environments, where the tools struggle to keep up with the unique vulnerabilities introduced by AI systems.

"Prompt injection exploits and excessive agency flaws require creative, multi-turn interaction chains and adversarial psychology. These logic flaws are entirely invisible to tools that test using single-shot automated queries." - Cobalt

This quote highlights the need for human intervention and creativity in pentesting, especially when dealing with the complexities of AI-driven systems. It's a reminder that while automation has its place, it cannot replace the critical thinking and adaptability of human experts.

The Impact on Security Professionals

The decline in support for fully automated pentesting is a double-edged sword. On one hand, it's a sign that security professionals are becoming more discerning and demanding real assurance, not just coverage. They're realizing that vendor hype doesn't always translate to effective security measures.

However, the increasing number of vulnerabilities introduced by non-security AI tools is a cause for concern. With 12% of vulnerabilities in traditional environments classified as high or critical, and that number jumping to 32% in AI and LLM environments, security teams are facing a daunting task. The combination of these factors makes a strong case for a hybrid approach to security, where AI handles routine scans, and humans focus on the most critical systems.

The Hybrid Approach

Cobalt's solution, and one that many in the industry seem to be adopting, is a hybrid security model. This approach allows AI to scan most systems automatically, freeing up human resources to focus on the most sensitive and critical areas. It's an efficient division of labor that leverages the strengths of both humans and machines.

However, it's not just Cobalt singing the praises of this approach. Veracode, an application security firm, has also reported that AI-assisted software development is creating an overwhelming number of vulnerabilities, many of which are left unresolved for extended periods. This further emphasizes the need for a balanced approach, where AI assists but doesn't replace human expertise.

A Word of Caution

While the hybrid model seems to be gaining traction, it's not without its critics. CJ Moses, Amazon's security chief, believes AI pentesting tools have increased efficiency by 40%, but he's not ready to hand over the reins entirely. Moses emphasizes the importance of human decision-making, especially when it comes to security, a sentiment that many in the industry share.

"AI is very good at doing things, especially when you have large amounts of data and need that big view. But from a decision-making capability, it isn't something that we're ready to rely on." - CJ Moses, Amazon Security Chief

This quote underscores the need for a cautious approach to AI integration in security. While AI can assist and enhance human capabilities, it's clear that the final decisions and oversight should remain with trained professionals.

Conclusion

The debate around automated pentesting tools highlights the ongoing tension between automation and human expertise in critical fields like cybersecurity. While automation can bring efficiency and scale, it's clear that human insight, creativity, and decision-making are irreplaceable. The future of cybersecurity may very well lie in a harmonious blend of these two elements, a hybrid approach that leverages the strengths of both to create a robust and adaptable security posture.

The Rise and Fall of Automated Pentesting: What Infosec Pros Think (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Twana Towne Ret

Last Updated:

Views: 6040

Rating: 4.3 / 5 (44 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Twana Towne Ret

Birthday: 1994-03-19

Address: Apt. 990 97439 Corwin Motorway, Port Eliseoburgh, NM 99144-2618

Phone: +5958753152963

Job: National Specialist

Hobby: Kayaking, Photography, Skydiving, Embroidery, Leather crafting, Orienteering, Cooking

Introduction: My name is Twana Towne Ret, I am a famous, talented, joyous, perfect, powerful, inquisitive, lovely person who loves writing and wants to share my knowledge and understanding with you.