Businesses Turn to AI-Powered Offensive Security as Threats Escalate
As cyber threats grow more sophisticated, particularly those powered by artificial intelligence, organisations are ramping up investment in offensive security practices such as penetration testing and red teaming. According to Omdia analyst Theresa Lanowitz, speaking with Dark Reading, agentic AI—systems capable of autonomously performing tasks—is emerging as a tool that security teams can use to proactively test their own defences before attackers do.
While this approach offers real potential to strengthen security postures by identifying weaknesses faster and more thoroughly than manual testing alone, it also carries risks. Agentic AI tools used for offensive testing could themselves be misused, misconfigured, or targeted by adversaries, potentially creating new vulnerabilities rather than closing existing ones. The discussion highlights a broader trend: as attackers adopt AI to scale and refine their techniques, defenders are being pushed to adopt similar technologies simply to keep pace.
For small and medium businesses, this shift signals that offensive security testing—once seen as an enterprise-only investment—is becoming more accessible and relevant. However, adopting AI-driven tools requires careful vetting, as the same automation that improves testing efficiency could introduce new risks if not properly managed and overseen by skilled personnel.