CREST Introduces AI-Enabled Penetration Testing Accreditation Module
On July 28, CREST unveiled an innovative accreditation module focused on AI-enabled penetration testing, aimed at ensuring responsible AI usage within cybersecurity service providers. This initiative is part of a broader effort to address the rapid integration of artificial intelligence in the cybersecurity sector, thereby setting a standard for organizations that utilize AI technologies in their operations.
The introduction of this accreditation module integrates seamlessly into CREST’s existing Penetration Testing Accreditation Standard. By doing so, it allows providers employing AI in their daily activities to undergo a thorough independent assessment to validate their practices. Applications for this new accreditation are open to current CREST members looking to enhance their recognition for services involving AI-enabled penetration testing.
This accreditation initiative comes in response to a CREST report released in March, which underscored the increasing reliance on AI among cybersecurity providers. According to the report, a striking 76% of these providers reported a rise in their use of AI over the past year. Furthermore, 69% indicated that they already incorporate AI into their routine service delivery, a clear indicator of the technology’s growing significance in this field. Recognizing this shift, CREST released AI Principles in March and an accompanying AI Charter in June, which has garnered the endorsement of over 100 cybersecurity organizations.
Importantly, the new accreditation module provides independent assurance regarding responsible AI governance, aligning with CREST’s established complaints and disciplinary structures. Unlike voluntary agreements that may lack stringent enforcement mechanisms, this formal accreditation empowers CREST to mandate compliance amongst its members. The standards themselves were crafted by an AI Working Group within CREST and are intended to evolve in tandem with technological advancements and their practical applications.
Nick Benson, the CEO of CREST, emphasized the importance of this new initiative, stating that it effectively fills a significant market void where the rapid adoption of AI has outstripped existing governance frameworks. In the current cybersecurity landscape, there is a growing demand from clients for independent assurances concerning AI-enhanced services. The introduction of this accreditation serves to create a robust, enforceable framework designed to restore confidence in the market.
While no organization has yet received the accreditation at the time of its launch, it is anticipated that the first certified provider will emerge within a month. This certification process offers an invaluable opportunity for cybersecurity professionals looking to evaluate the credibility of penetration testing vendors. It highlights the importance of monitoring which service providers receive this accreditation as organizations increasingly look to invest in AI-enabled security services.
For businesses that have already adopted or are considering the use of AI-driven security solutions, it becomes crucial to assess whether their chosen providers meet the criteria outlined by this new accreditation. By engaging with accredited vendors, organizations can ensure that they are utilizing AI responsibly and in a manner that prioritizes security and ethical governance.
CREST members who are interested in pursuing this accreditation can do so through the organization’s established certification pathways. The new module is designed as an optional extension to the traditional penetration testing credentials, enabling members to enhance their offerings by showcasing their commitment to responsible AI practices.
As the cybersecurity landscape continues to evolve, this accreditation module represents a proactive approach to managing the complexities associated with AI integration. By establishing clear standards and oversight, CREST aims to lead the way in fostering accountability, reassuring clients, and encouraging ethical practices in the adoption of AI technologies across the cybersecurity industry.
This move by CREST not only signifies a commitment to excellence but also reflects a responsive approach to the changing technological environment, one where governance, trust, and responsibility are paramount.
Source: https://www.infosecurity-magazine.com/news/crest-ai-pentesting-accreditation/

