Image credit: Pexels

From automated penetration testing and AI-driven threat detection to bot mitigation and governance, cybersecurity companies are transforming enterprise defense against sophisticated attacks.

Artificial intelligence is no longer simply changing the way businesses operate; it is also transforming how they defend themselves. As cyber threats become more sophisticated, organizations are adopting AI-powered cybersecurity tools to improve threat detection, strengthen governance, and reduce the burden on security teams. Despite the efficiency that AI-powered tools bring, industry leaders stress that technology alone is not enough. Human oversight, strong governance, and a security-first culture remain essential.

Automating Penetration Testing Without Removing Human Oversight

One of the biggest challenges for penetration testers is the amount of time spent documenting vulnerabilities. PentestPad was created to solve that problem by automating much of the penetration-testing lifecycle, from project scoping to final reporting, while ensuring that every AI-generated action requires human approval.

Luka Sikic explained, “Reporting during the penetration testing process takes around 30 to 40% of your actual work. So those security professionals really take a lot of their time to document all of the findings to describe them better.”

Despite relying on AI, the platform keeps security professionals firmly in control.

“Before it executes any of the commands that penetration testers would use, you as a human in the loop, have to approve this command. So it would run multiple commands, gather all of the outputs, and then really decide.” 

Sikic also warned that AI-generated security findings require careful verification.

“We receive a large number of security reports, but after we analyze them, we see that there’s no risk. And this is actually some sort of hallucination by an AI model or whatever was used in the background.”

Detecting AI-Powered Attacks at Their Source

While PentestPad focuses on offensive security, Cyngular Security is applying AI to improve threat detection. As attackers increasingly use agentic AI to automate phishing campaigns and exploits, conventional security operations centers (SOCs) are struggling to keep pace.

Amit Weigman said, “Today, attackers are using AI to automate a lot of these processes, and not just AI, but agentic AI. This means that they can do tasks in parallel, more in-depth and more accurately simultaneously. And this ultimately lowers the bar for them to initiate and to induce these attacks.”

Rather than relying on pre-filtered alerts, Cyngular analyzes raw telemetry directly from endpoints and firewalls.

“What we do at Singular is we take the AI, and we really move it down to the very core level of detection. So the AI is not based on these human-defined rules or criteria or data. The AI is exposed to the raw telemetry—the raw data—and the analysis is being done really without having the human intervention in the loop that could potentially harm the detection.” 

Weigman also advised organizations to introduce AI gradually.

“Test it in small environments. Take a few of your trusted SOC analysts, have them build a mini SOC operations, implement AI solutions that you think are going to do justice to your stack, to your needs, and test it in a small environment. See how it functions, see where the failure points are, and then incrementally increase the involvement of AI in all the various fields in your SOC.”

Building a Security Culture Before Embracing AI

Not every cybersecurity leader believes AI should be the primary focus. OrbitalFire CEO Reg Harnish argues that technology delivers value only when backed by a strong organizational culture.

“Just like any other security tool, AI introduces its own risks, because it’s just software. It’s like antivirus; antivirus is really only between 40% and 60% effective. The bigger problem is that it gives organizations and humans a real false sense of security,” Harnish said.

He urged businesses to prioritize long-term commitment instead of chasing new technologies.

“I think they should prioritize their commitment. The analogy I use almost every day is it’s kind of like personal fitness or a gym membership; you can have every fancy weight training gadget you want in the gym, but if you don’t go, it’s useless.”

Harnish also noted that AI has changed the economics of cybercrime, particularly for small and medium-sized businesses.

“If you can grab $20,000 out of a payroll account from a 50-person company, that’s a good day, because it’s only going to cost $8,000 to do that. It’s completely changed the economics, and that’s why we went from fewer than 10 cases over five years to working on three incidents simultaneously in a single week in 2025.

Governing AI Around Sensitive Data

For ReSource Pro, AI governance is central to protecting sensitive insurance data handled across more than 60,000 client processes. The company has established strict safeguards that require human oversight of AI-driven decisions and ensure client information is never used to train external models.

Laura Brown observed, “The velocity of change has really elevated the risks to being more complex and challenging. It’s all changing, not just annually, but every three months, it’s a new landscape.”

 She emphasized that experts must remain responsible for critical decisions.

“Human in the loop is huge. We’re never going to fully rely on an AI tool to make decisions, to take actions. We always have to rely on the experts to interpret that, validate it, and make the ultimate decision.”

Brown also highlighted the company’s strict vendor requirements.

“We have a strict policy against [vendors training on client data], so we make sure that any AI tools that we’re licensing with are not sending that information to any of their other stakeholders, or storing that or using that to improve and train their agents and workflows.”

Making Bots Pay the Price

Friendly Captcha is tackling another growing challenge: AI-powered bots that can mimic legitimate users. Instead of relying on traditional CAPTCHAs, the company uses cryptographic proof-of-work challenges that shift the cost from users to attackers.

Jonas Dams said, “AI made it more accessible for attackers to build up strategies and to find vulnerabilities of applications or websites faster, and also to build up better tactics to somehow try to hide and mimic real users.”

He explained how the system increases the computational cost of automated attacks.

“We’re sending a cryptographic puzzle to your browser engine and the browser needs to calculate the puzzle and therefore invest compute power. We kind of demand resources from the attacker. And by identifying attack patterns, we dynamically scale the difficulty of the puzzle; the harder the attacker tries to enter, the more costly it gets to get the challenge solved.”

Dams added that organizations should define their own AI governance policies.

“Scraping prevention and training prevention are priority number one. I want a Google bot on my platform; I want to be listed at Google. But I don’t want ChatGPT. So the question is how to define governance for your platform: decide what you want to allow and what not. It’s not that one solution fits all anymore. Everybody has their individual demand for protection.”

AI as a Force Multiplier

For these cybersecurity companies, AI is not a replacement for human expertise but a force multiplier when used responsibly. Whether automating penetration testing, strengthening threat detection, governing sensitive data, reinforcing security culture, or preventing automated abuse, these tools demonstrate how organizations can adapt to an increasingly complex threat landscape. As cybercriminals continue to evolve, businesses that combine AI with clear governance, skilled professionals, and thoughtful implementation are likely to be best equipped for the challenges ahead.