RSA Conference: Striking the Balance between Automation and the Human Touch in Penetration Testing
On March 19, 2021, NetSPI Chief Operating Officer (COO) Charles Horton was featured in RSA Conference:
Navigating how to reap the benefits of automation and when to use manual processes is an age-old cybersecurity challenge. How can organizations achieve efficiencies without the support of automated technologies? How can they ensure they’re getting the most thorough coverage without the human touch? In my opinion, it isn’t an either-or. Organizations need both automation and manual strategies to ensure their assets are protected from cyberattacks, and there is much to learn from the penetration testing community.
Pentesting is a great example of the importance of collaboration, not only between humans, but also between humans and machines. Penetration testing can be a balance of automation and manual efforts so that a cybersecurity program pays dividends.
Read the full RSAC article to better understand the benefits (and potential limitations) of using the different approaches alone and learn how to strike balance between automation and manual efforts.
Explore More News
NetSPI Expands Suite of AI-Powered Continuous Pentesting Services as Organizational Attack Surfaces Grow
NetSPI expands suite of Human-Led, AI-Powered Continuous Pentesting Services, including a first-of-its-kind AI Findings Validation service, as well as continuous testing for web applications and internal networks.
AI’s Role in the Next Era of Pentesting
This article discusses how AI can accelerate penetration testing, but without human expertise to validate findings and apply business context, organizations risk confusing faster output with stronger security.
Why Continuous Security Validation is Becoming a Security Imperative
CTO Magazine interviewed NetSPI's Field CISO, Nabil Hannan, for a June 11, 2026, article about how cloud-native architectures, continuous deployment pipelines, APIs, and AI-assisted development have accelerated change across enterprise environments.