AutomationAI & Technology

The future of penetration testing is not AI versus humans

By Geoff Jones, Partner at Cyberis Reply

Across the cybersecurity industry, organisations are looking at how large language models and other AI technologies can improve threat detection, automate repetitive tasks and increase the efficiency of security operations. Penetration testing is no exception. AI-powered tools have the ability to analyse large codebases, review configurations, identify patterns and generate recommendations in a fraction of the time of traditional approaches. 

As these capabilities continue to mature, it will be natural for organisations to talk about how the role of the security consultant might change. Some have suggested that AI will eventually replace many of the activities traditionally performed by penetration testers and security assessors. But although AI is becoming a valuable addition to the security testing toolkit, this perspective totally misunderstands what is needed for effective security testing.  

The real opportunity of AI in penetration testing doesn’t lie in replacing human expertise, it is in combining the best of AI-driven efficiency with the judgement, creativity and contextual understanding that experienced consultants provide. 

This is an important distinction. The cybersecurity industry is able to get efficiency gains through AI but delivering meaningful security outcomes is much more challenging. 

The benefits and limitations of automation 

The appeal of using AI in security testing is clear. Security teams are assessing complex and growing environments, along with supporting faster development cycles. In addition, they have pressures around budgets, skills shortages and compliance obligations. All of this makes using AI to reduce manual effort and accelerate analysis attractive. 

AI can provide significant benefits during some of the stages of a security assessment. It can help consultants process large volumes of information, identify potential areas of concern, summarise technical findings and support research activities. Tasks that may previously have needed hours of manual effort can often be completed quickly, allowing consultants to spend more time focusing on investigation and analysis rather than administration. 

However, there is an important difference between accelerating security testing and conducting security testing. Penetration testing is not just a technical exercise for identifying vulnerabilities. At its core, it is an assessment of risk that has to have an understanding of how technologies, business processes and human behaviour interact within a specific organisational context. While AI can certainly help with gathering and analysing information, it does not have the broader understanding needed to determine what that information means for a particular organisation. 

Context is critical 

One of the greatest strengths of an experienced penetration tester is the ability to evaluate technical findings in context. A vulnerability’s significance depends on a range of factors including the organisation’s threat profile, sensitivity of the affected systems, effectiveness of existing controls and potential business impact. 

AI models are capable of identifying patterns and generating plausible explanations based on the data they have been trained on. What they cannot reliably do is understand the nuances that make one risk a priority while another may be relatively insignificant. Security professionals routinely make these judgements by combining technical knowledge with experience, business understanding and an appreciation of how real-world attackers operate. 

This contextual awareness is vitally important when communicating findings to clients. Organisations rarely benefit the most from a list of every possible weakness within an environment. They need clear guidance on which issues present genuine risk, what the likely consequences are and where remediation efforts should be prioritised. Providing that level of advice has to have professional judgement, not just isolated technical analysis. 

Creativity is one of cybersecurity’s most valuable skills 

The role creativity plays in security testing is something that is often overlooked in discussions about AI. Effective penetration testing involves far more than running tools or following established methodologies. Experienced consultants are constantly adapting as new information emerges. They investigate unexpected behaviours and identify relationships between seemingly unrelated findings. 

Many significant vulnerabilities will be discovered because a tester recognised that something did not look quite right and decided to investigate further, not because an automated tool identified them. This ability to think laterally, form hypotheses and pursue unconventional attack paths is one of the defining characteristics of skilled security professionals. 

Cybercriminals are continuously adapting their techniques, combining known weaknesses in new ways and exploiting unforeseen opportunities. This means security testing needs creativity and adaptability, which is still difficult to replicate through automation alone. 

Maintaining accountability  

As organisations incorporate AI into security processes, questions of accountability become important. Security assessments influence investment decisions, compliance programmes, remediation priorities and board-level risk discussions. The findings generated during a penetration test will often have operational and strategic consequences. 

Organisations need confidence that conclusions are accurate, evidence-based and properly contextualised. Although AI can help to generate insights, it can’t take responsibility for the quality of the insights or the decisions that follow them. Accountability ultimately has to rest with the security professionals carrying out the assessment and the organisations delivering the advice. 

This is why security consultancies have to adopt a consultant-led approach to AI. Instead of allowing AI to operate autonomously, it should be used to augment the capabilities of their teams. This means consultants are still responsible for validating findings, challenging assumptions, applying context and ensuring that recommendations are appropriate for the client’s environment. In this model, AI acts as a powerful assistant and not as a replacement for human expertise. 

A collaborative future 

The debate around AI in cybersecurity is often framed as making a choice between human expertise and automation. In reality, the future is likely to involve Humans and AI working together. AI is exceptionally effective at processing information at scale, reducing repetitive tasks and improving operational efficiency. Human consultants bring essential contextual understanding, critical thinking, creativity and accountability. 

These capabilities are complementary and the organisations that gain the greatest benefit from AI will be those that use AI to augment the expertise of skilled professionals, so they can focus their efforts where they create the greatest value. 

Undoubtably AI will continue to reshape cybersecurity but human consultants will remain essential. Organisations need to look at how they can use AI to enhance human expertise while retaining the judgement and oversight that effective security testing requires. This is what will define the future of penetration testing. 

Related Articles

Back to top button