I supported Picus Security on their State of BAS 2025 summit, a virtual event on redefining attack simulation through AI. The announcement, which lists the speaker lineup, is here: Picus Security Hosts State of BAS 2025 to Redefine Attack Simulation Through AI.
The summit ran across two sessions (October 14 and 16) and brought together practitioners and leaders, including Ron Eddings from Hacker Valley and CISOs from Fortune 500 companies, around one question: what does breach and attack simulation look like now that AI is in the loop?
The themes lined up closely with how I think about offensive security:
- Breaking the patch-overload cycle. Using validation to find the exposures that are actually reachable and exploitable, rather than drowning teams in severity scores.
- Reducing noise and prioritization fatigue for SOC and vulnerability management teams.
- Operationalizing AI-powered BAS and continuous validation across hybrid and cloud environments.
- Talking risk to the board, in business terms and progress over time, not raw technical findings.
This connects directly to the work I have been doing on continuous penetration testing and the offensive SOC: offense should inform defense, you validate continuously rather than once a year, and you map what you find to real attacker behaviour instead of a static checklist. BAS and continuous pentesting are two sides of the same coin, and pulling AI into that loop is where a lot of the interesting work is right now.
For more on my take on the foundations of BAS, see my talks & media page, which links the keynote I gave with Picus.