Horizon3 has now published the thought leadership paper I authored: AI-Powered Penetration Testing: How Autonomous Offensive Security Works. It’s out as a SANS white paper, sponsored by Horizon3.ai.
The paper looks at how AI is changing offensive security. It moves penetration testing away from isolated, point-in-time assessments and toward a continuous operational capability. That shift is exactly the direction I’ve been pushing in my own work.
A few of the threads it pulls on:
- From point-in-time to continuous. Autonomous offensive security lets you validate exposure constantly, not once a year. You find what’s actually reachable and exploitable right now, and you re-check it as the environment changes.
- AI in the loop, not humans out of it. The interesting work is in combining automation’s coverage and speed with human judgement and creativity. It’s the same hybrid model we run for continuous penetration testing at River Security.
- Offense informs defense. The point of testing autonomously and continuously is to feed better, prioritized signal back to the defenders, mapping findings to real attacker behaviour instead of a static checklist.
This connects directly to the way I teach and the way we operate: validate continuously, prioritize what’s exploitable, and let offense drive stronger defense.
You can read the full paper here.