CyberSecurity SEE

NetSPI and Synack Collaborate on Continuous Security Testing

NetSPI and Synack Collaborate on Continuous Security Testing

Artificial Intelligence & Machine Learning,
Governance & Risk Management,
Next-Generation Technologies & Secure Development

Merger Pairs Expert Testers, Crowdsourced Researchers and Autonomous Technology

NetSPI and Synack Collaborate on Continuous Security Testing
Aaron Shilts, CEO, NetSPI (Image: NetSPI)

In a significant move within the cybersecurity landscape, offensive security vendors NetSPI and Synack have announced plans to merge, resulting in a formidable entity valued at $200 million and comprising a workforce of 800 professionals, all specializing in penetration testing and continuous security validation. This merger highlights a growing trend towards integrating diverse cybersecurity strategies and technologies to enhance security effectiveness in a rapidly evolving threat landscape.

The merger is poised to give Minneapolis-based NetSPI access to nearly 2,000 crowdsourced penetration testers from Silicon Valley-based Synack. These individuals possess the capability to identify vulnerabilities that autonomous systems often overlook. Aaron Shilts, CEO of NetSPI, has emphasized that a multifaceted approach to continuous testing is crucial; it incorporates not just human expertise for in-depth investigations but also crowdsourced researchers for more frequent assessments.

Shilts explained, “CISOs today are incredibly interested in the ability to perform true continuous always-on testing in the world of artificial intelligence-driven application development. The CISO community needs an answer to that. They need to test continuously, and they also need to leverage autonomous testing capabilities to be able to do it at a reasonable price point.” This perspective underscores the growing urgency within organizations to adopt proactive security measures in the face of increasingly sophisticated cyber threats.

Founded in 2001, NetSPI currently employs 591 individuals and has been majority-owned by KKR since October 2022, following a $410 million growth investment by the private equity firm. On the other hand, Synack, established in 2013, employs 242 professionals and has raised nearly $108 million, with its latest funding round—the $52 million Series D—being led by B Capital Group and C5 Capital in 2020. Following the merger, the new entity will still be majority-owned by KKR, indicating a strong backing for their strategic vision.

How Workers, Crowdsourcing and Autonomous Tools Work Together

In the competitive realm of cybersecurity, human experts have the unique ability to conduct in-depth investigations and diagnose complex vulnerabilities. Meanwhile, crowdsourced researchers augment this human capacity, facilitating more frequent and cost-effective testing. Autonomous technology, capable of operating continuously and at a larger scale, adds yet another layer of sophistication to the security testing process. Shilts expressed that combining these three elements into a continually operating testing methodology was a key factor in making Synack an appealing partner.

“Our continuous testing will be a mix of the traditional NetSPI expert human deep-dive test, the autonomous technology that we’re building, and the crowdsourced researchers, all orchestrated to deliver this always-on testing methodology,” Shilts detailed. This holistic approach represents a significant evolution in how organizations can safeguard their assets against cyber threats.

Furthermore, NetSPI has developed a benchmarking suite specifically for Synack, focusing on various criteria such as false-positive rates, the identification of difficult critical vulnerabilities, and the practical usefulness of findings. Shilts remarked that Synack surpassed their expectations, with its technology uncovering vulnerabilities that usually mandate expert testing, while producing fewer false alerts than other approaches. “It benchmarked higher than we thought it would,” he added.

The merger holds particular significance for government clients, as Synack maintains a successful practice serving various federal agencies, something NetSPI lacked prior to the merger. Consequently, the newly formed company can now expand its services to encompass hardware, Internet of Things (IoT), and physical device testing for government customers—critical areas where security failures can incur severe implications.

Shilts clarified, “More is not always better in the offensive security space. The right vulnerabilities that matter to our customers are the ones that they want to hear about.” This statement highlights the importance of targeted threat identification over sheer volume, a crucial consideration in effective cybersecurity practices.

What Types of Testing Make Sense in Different Situations

While Synack operates on a crowdsourced model, CEO Jay Kaplan has acknowledged its limitations. He pointed out that testing various environments— such as networks, on-premises systems, hardware, IoT, operational technology, and mainframes—often requires dedicated resources. This gap is where NetSPI’s capabilities can fill in, thus broadening the range of testing engagements Synack can support and not merely increase its test numbers.

Kaplan articulated the need for organizations to adopt a comprehensive strategy for continuous testing of their attack surfaces. He stated, “They want to know all the time, if an adversary was attacking them, what are they going to find as things change across those environments?” This approach is essential for keeping pace with dynamic cybersecurity threats.

As businesses adapt to the complexities of modern infrastructure, understanding potential adversarial discoveries becomes paramount. While Synack’s freelancer model enabled continuous testing, the economic implications made comprehensive assessments challenging. The introduction of AI technologies alters this equation, potentially allowing for extensive testing across broader attack surfaces without prohibitive costs, as Kaplan indicated.

Lastly, Kaplan emphasized the importance of integrating AI with human oversight. He stated, “AI should not stand alone. It should sit next to experts.” This is particularly relevant given that AI is prone to errors and can generate misleading results. To ensure that organizations are alerted to genuine vulnerabilities rather than non-critical false positives, a human touch remains indispensable.

Kaplan illustrated the current gaps in AI capabilities, notably in detecting business logic vulnerabilities, which necessitate an understanding of how applications are designed to function. This often requires human testers to contextualize potential misuse scenarios. He envisioned a future model where human analysts provide AI agents with essential context before allowing them to autonomously conduct testing, striking a balance between automation and expert insight.

Overall, the merger between NetSPI and Synack epitomizes a significant shift in offensive security, blending human intelligence, crowdsourced expertise, and advanced technology to offer a more robust defense against the multifaceted challenges posed by cyber threats.

Source link

Exit mobile version