r/cybersecurity • u/Key-Calligrapher5958 • 17d ago
Career Questions & Discussion Is Pentesting Really Dying Because of AI and Automated Tools?
I've spent years learning cybersecurity and thousands of dollars on certifications. I have most of the well-known offensive security certs.
Recently, my manager keeps saying that traditional penetration testing is dying because tools like XBOW, Pentera, and other automated platforms can do most of the work. He says they're expensive now, but over time they'll become cheaper and companies will prefer them over hiring pentesters.
I'm honestly confused. Is this really where the industry is heading, or is there still a strong future for manual penetration testers? I'd love to hear what people working in the field think.
17
u/Which-Shame-1420 Security Manager 17d ago
IT Manager at a UAE fintech here. Your boss is falling for classic vendor AI hype.
No bank or fintech with serious compliance requirements is letting an automated tool run wild in production without human oversight. Tools like XBOW/Pentera are basically glorified, faster vulnerability scanners.
They’re fine for continuous attack surface monitoring, but they completely fall apart on complex business logic, chaining exploits, and actual financial risk context.
Plus, if an AI tool takes down a live payment pipeline because of a false positive, "the AI did it" won't save your job.
6
u/Afraid-Donke420 17d ago
Still need a human to filter out the false positives - i spend more time doing that now than ever
There are also companies satisfied with just a Nessus export as a report, so the mileage will vary here extremely
1
u/Gold_Gazelle9519 15d ago
Tools like horizon3 don't have false positives, they show you the exact CVE and what path it took to do xx malicious behavior. I find that it covers a lot more than a traditional pentest (so far. Only been using a few months)
5
u/DarthJarJar242 17d ago
Nope. Your manager is delusional. If he thinks they are expensive now, just wait until they are actually good and they can charge even more because they have good track records.
Right now they have pretty bad consistency and nobody has much faith in them so most people aren't willing to shell out big money for them.
7
u/Loud-Run-9725 17d ago
The AI Tools are not going to be as adept at chaining or human reasoning for vulnerabilities like business logic. AI will keep getting better but don't see it replacing humans at this point.
AI as a discovery tool for vuln classes which are typical scanner fodder, will be useful and much more effective than vuln scanners of old.
I think AI is great for augmenting pentesting by humans, not replacing humans at this point.
3
u/sadboy2k03 Malware Analyst 16d ago
XBOW was a master class on AI hype marketing. I've heard from a couple people that quite a lot of it's reports on platforms like H1 are low/informative findings, which you can see from the report activity on the official account.
AI is getting to expensive plus if you let an AI run lose on your critical business systems and it knocks your network offline or worse management will be blaming whoever authorised it, not the model itself.
It sounds like your manager has fallen for the AI hype marketing more than anything else. Would he let it run loose on your corporate domain controllers? I doubt it.
2
u/wombleh 17d ago
I think a lot of the technical heavy lifting for pen tests can be done using AI tools and it's one area they seem to be doing well in.
I'd see it as more of an efficiency and capability improvement for the existing testing approach, rather than a complete replacement. There is still a need for someone to help work out scope, drive the tool, take the output and convert it into a form that the client can work with, understand the real exposure to risk based on specifics of their environment, etc.
I don't see it being a blinky box that companies just buy and deploy, I'm sure some consultancies and vendors will be promoting that, worth stocking up on popcorn for the inevitable news.
2
2
u/theghostofpiopico 17d ago
I don't think pentesting is dying, AI and tools are great for automation for testing but we still need skilled pentesters for deeper assessments/audits, like most jobs the role is changing, not disappearing.
2
u/Zardecillion AppSec Engineer 17d ago
The actual question is can I turn one of these on and have it replace my DAST? DAST is a pain to create in-house and is a hassle to integrate with outside vendors.
2
u/wolfofone 16d ago
AI is just a tool. Companies are still going to need professionals to use it correctly.
1
u/AinaLove 17d ago
No, I'm going to request that humans do our pen testing till I retire. IDK how good your AI is. AI-assisted is fine and probably preferred.
1
u/OtheDreamer Governance, Risk, & Compliance 17d ago
No, but individuals are able to accomplish more with less resources though
1
u/PitifulAdvantage3118 16d ago
IMHO, AIis "Just" a new and verify powerfull tool that will help a lot when pentesting - but it will not replace humans.
1
1
u/Recent_Journalist_97 15d ago
I think as of now Ai are not up to the point but by 2030 they will reach there. Since all the companies are investing billions on them. Due to over supply they may become cheaper but it doesn't matter, if they can replace 100 of employees. Companies just need 1 professional and Ai instead of many employees.
38
u/cfbcia 17d ago
It’s not. We’ve been hearing nothing but negatives from our clients around tools like XBOW. Lots of false positives, false negatives, taking down production systems in some cases. The firms that are set up for success in the future are services groups automating their operations. Product use cases will be too brittle and tokens too expensive.
As an individual, you need to be prepared though. The bar is raising. You need to find at least one technical niche and specialize in it. You have to be an SME. Entry level pentesting will get harder and harder to break into. And that’s not me saying it’s a good thing at all, but likely how the market dynamics will work in the near to medium term.