The threat landscape has fundamentally changed. Attack surfaces are expanding. Vulnerability disclosures are accelerating. Organizations can no longer rely on annual testing or surface-level assessments. The adversaries aren’t waiting, and neither should security programs. 

NetSPI and Synack announced a definitive agreement to merge, backed by KKR, forming the industry’s leading offensive cybersecurity platform. Together, the companies bring nearly 40 years of combined operating history and more than 13 million hours of premier, real-world offensive testing experience, providing the scale, expertise and capabilities to help organizations address increasingly sophisticated cybersecurity threats. 

Why the “Fully Autonomous” Promise Falls Short 

The most sophisticated vulnerabilities can be incredibly complex and difficult to identify. They live at the intersection of business logic, infrastructure choices, and attacker creativity. These are places where a checklist approach naturally fails. 

A skilled tester walks into an environment with intuition: an understanding of where configurations go wrong, how systems chain together, and what a tool will inevitably miss. That intuition comes from time spent in the trenches across diverse organizations, facing novel attack patterns that no training dataset could possibly capture. 

When an AI system flags a vulnerability, someone must determine if it matters. More critically, someone has to catch what it didn’t flag at all. The gaps that tools systematically overlook. Without that filter, what looks like efficiency becomes noise. And noise in security is how real vulnerabilities hide. 

Speed with Judgement 

Speed matters. Environments change daily. Threats emerge constantly. Continuous validation requires the ability to run assessments without waiting for manual scheduling and only works when the findings are actionable. That requires someone who can separate the signal from the noise. Someone who understands not just what a vulnerability is, but whether it actually matters for that specific organization, that specific architecture, that specific threat landscape. 

The goal has never been to build an autonomous system for its own sake. It’s been answering a single question: What actually puts this organization at risk? And the evidence keeps pointing the same direction: that question requires both AI and expertise, each amplifying the value of the other. 

What We’re Building 

As the industry explores fully autonomous testing approaches, NetSPI and Synack share the conviction that AI is most powerful when combined with expert judgment. By bringing together leading security talent and AI-enabled capabilities, the merger positions the combined company to deliver more sophisticated testing at greater scale. 

The future of pentesting isn’t a choice between human and machine. It’s about deploying the best of both. That’s what we’re bringing to the market.  

We’re excited about this next chapter and the opportunity to deepen our commitment to the organizations that rely on us for security testing. To our customers and partners, thank you for your continued trust. We’re looking forward to delivering expanded capabilities across the full offensive security lifecycle:  

  • One of the industry’s deepest benches of vetted offensive security talent, amplified by agentic AI 
  • Purpose-built AI that accelerates discovery, analysis, and validation of findings 
  • Continuous security testing and validation across the full attack surface 
  • Expanded service offerings with flexible delivery models 
  • Greater operational scale, efficiency, and accelerated innovation. 

For more information, read the full press release.