Human-Led, AI-Assisted Testing Will Define the Next Generation of Cybersecurity
According to Shaun Peapell, VP Global Threat Services at
Rootshell Security, the industry's focus is beginning to shift from discovery
toward prioritization as AI-assisted testing technologies dramatically increase
the volume of findings available to security teams.
For more than a decade, cybersecurity programs have invested
heavily in improving visibility through vulnerability scanners, attack surface
management platforms, threat intelligence feeds, penetration testing, and
exposure management technologies. Today, AI-assisted testing is accelerating
those capabilities further, enabling organizations to uncover more
vulnerabilities, correlate more data, and identify potential attack paths
faster than ever before.
However, Peapell argues that visibility alone does not
reduce risk.
"AI is helping us discover more vulnerabilities,
correlate more findings, and identify potential attack paths faster than ever
before," said Shaun Peapell, VP Global Threat Services at Rootshell
Security.
"That's a significant advancement for the industry. But
discovering vulnerabilities isn't the same as understanding risk. Security
teams still need to determine what is genuinely exploitable, how attackers
would leverage those weaknesses in practice, and which issues deserve immediate
attention. That's where human expertise remains critical."
As AI-assisted security technologies continue to mature,
Rootshell believes many organizations are approaching a point where visibility
is no longer the primary constraint. Instead, security teams are increasingly
challenged by the volume of information they must assess, contextualize, and
operationalize.
The company describes this as a growing prioritization
challenge.
From an offensive security perspective, organizations
frequently possess large volumes of vulnerability data but struggle to identify
which findings represent realistic attack opportunities. As AI improves
discovery capabilities, the gap between identifying vulnerabilities and
effectively prioritizing them is becoming increasingly apparent.
According to Peapell, successful security programs will
increasingly be measured not by the number of vulnerabilities they identify,
but by their ability to continuously validate risk, prioritize effectively, and
reduce the attacker's window of opportunity.
This shift is contributing to growing demand for continuous
security testing models that provide ongoing validation, exploit-aware
prioritization, and visibility into how risk evolves over time. Unlike
traditional point-in-time assessments, continuous testing enables organizations
to reassess findings as exploitability changes, monitor evolving attack
surfaces, and maintain a more accurate understanding of real-world exposure.
Rootshell believes this evolution is driving the adoption of
what it describes as human-led, AI-assisted security testing.
Rather than replacing security professionals, AI is
increasingly being used to accelerate analysis, correlate findings across
environments, identify attack path relationships, and surface potentially
exploitable conditions at scale. Human expertise remains essential for
validating exploitability, understanding attacker behaviour, assessing business
impact, and translating technical findings into actionable decisions.
"The conversation around AI in cybersecurity often
focuses on automation," Peapell continued. "The reality is that
effective offensive security still relies heavily on experience, creativity,
and contextual understanding. AI can help us process information faster, but
understanding how an attacker would chain vulnerabilities together, move
through an environment, and exploit weaknesses in practice still requires human
judgement."
The company's own experience reinforces the importance of
prioritization. Across organizations using The Rootshell Platform, remediation
performance improved from 44.56% to 74.62% over an eleven-month period,
representing a 67.5% relative increase in resolution rates. According to
Rootshell, this demonstrates the value of combining continuous visibility with
effective prioritization and remediation ownership rather than relying solely
on periodic assessments and static reporting.
As part of this broader evolution, Rootshell continues to
expand the capabilities of Velma, its exploit intelligence technology.
Originally developed to identify vulnerabilities being actively exploited in
the wild, Velma is increasingly supporting finding correlation, attack path
analysis, exposure prioritization, and risk contextualization across modern
environments.
These AI-assisted enhancements are designed to help security
teams identify changing risk conditions faster, reduce manual triage effort,
and focus remediation resources where they will have the greatest impact.
Looking ahead, Rootshell also sees increasing demand for
security intelligence that can integrate more naturally into operational
workflows. As organizations continue exploring AI and large language model
initiatives, the company is investigating future MCP server capabilities that
could allow prioritized exposure intelligence to be securely consumed within
AI-driven decision-making environments.
Tony Allen, Co-Founder of Rootshell Security, believes this
reflects a broader industry transition.
"We're seeing increasing demand from organizations that
want more than another report or dashboard," said Allen. "They want
continuous visibility, exploit-aware prioritization, and confidence that
they're focusing resources on the risks that matter most. AI can accelerate the
journey, but prioritization remains the key to reducing risk."
For Rootshell, the implications are clear. As AI continues
to improve visibility and increase the volume of security intelligence
available to organizations, the differentiator will no longer be who can
discover the most vulnerabilities. It will be who can understand, prioritize,
and act on them most effectively.
About Shaun Peapell ChCSP
Shaun Peapell is VP Global Threat Services at Rootshell
Security, where he leads the delivery and evolution of offensive security
services, including penetration testing, red teaming, purple teaming, social
engineering, and Continuous Testing programs. A highly experienced
cybersecurity practitioner, Shaun specializes in helping organizations
understand and validate real-world cyber risk through adversary-led testing,
exploit intelligence, and continuous security assessment methodologies.
Shaun holds multiple industry-recognized certifications and
accreditations, including CREST Registered Simulated Attack Manager (CRTAM) and
NCSC CHECK Team Leader, and is a regular contributor to industry discussions on
offensive security, threat-led testing, vulnerability prioritization, and the
evolving role of AI within cybersecurity.