Skip to content

Leadership1 publisher3 min readPublished

Anthropic's 17-victim case anchors a pentest CEO's argument for retiring the annual pentest

Seemant Sehgal, whose firm sells continuous penetration testing, says AI agents have cut the skill needed to run a full intrusion campaign. His evidence is two August 2025 incidents and one unmeasured claim about speed.

The Board Room · Leadership desk

Photograph accompanying Anthropic's 17-victim case anchors a pentest CEO's argument for retiring the annual pentest
Photo: thecyberwire.com

What happened

  • Seemant Sehgal, founder and CEO of the penetration testing firm BreachLock, wrote that attack complexity has stayed relatively stable while the expertise required to launch an attack has dwindled.
  • He argues no new category of vulnerability has appeared and existing controls most likely still work, while the time to find an unclosed gap has fallen from days to minutes.
  • His recommendation is to validate continuously which findings an attacker could exploit, on the grounds that an annual pentest no longer gives the control and visibility it once did.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • decision The choice a security leader faces this quarter is testing cadence, not a new control category: a once-a-year test samples the environment once every 8,760 hours, and the column's own case rests on exploitation windows of minutes.
  • contradiction The remedy the column prescribes is the product category its author sells, and the speed figure carrying the argument comes with no measurement, so a buyer has to weigh the diagnosis and the prescription separately.
  • constraint If payload variation is generated on demand, blocklists and signature matching lose ground even where the underlying gaps are unchanged. A defender can take only so much comfort from an unchanged control set.
  • exposure Internally deployed assistants put the defender on both sides of the problem, since the same tooling that speeds attackers up becomes a target inside the perimeter that most programs have not inventoried.

The load-bearing evidence in Seemant Sehgal's column is two incidents. In August 2025 Anthropic documented an operator who used an AI coding agent against at least 17 organizations, with the model handling reconnaissance through to setting ransom prices from the stolen financial data [1]. The other is a group called FulcrumSec, which used AI to read what it had already taken so it could negotiate from a position of knowledge [2]. Sehgal says he spent more than two decades on the offensive side of security, first in the CISO's office at one of Europe's largest banks. The past eight years he has spent building offensive security products [9]. He is also founder and CEO of BreachLock, which sells continuous attack surface discovery and penetration testing as a service [8]. The remedy his column recommends is continuous validation of exploitable attack paths in place of an annual pentest [11].

That overlap does not make the argument wrong, but it sets the standard of proof for the parts a buyer cannot check. The claim doing the most work is that the time for an attacker to find the one gap nobody closed and exploit it has gone from days to minutes [7]. Sehgal offers no measurement behind it, and the column puts no price on the tooling used in either case [2].

What is in the record is a narrower and more usable claim. Sehgal is explicit that vibe hacking, the label the industry has settled on [3], has not introduced a new category of vulnerability. The controls that would have stopped these campaigns a year ago are most likely still doing their job, he writes [6]. "The complexity of the attacks has stayed relatively stable, but the expertise required to launch one has dwindled," he wrote [4]. A test run once a year samples the environment once every 8,760 hours [1].

Seventeen victims in one vendor's report is not a population, and a company selling continuous testing has an obvious reason to describe annual testing as spent. Both objections are fair. Neither touches the part of the argument that rests on the defender's own books: most enterprise security programs already have more findings than they can remediate, and discovery was never the bottleneck [12]. Ordering that backlog by what an attacker can actually chain pays off whether or not the attacker has an agent.

Where the mechanism gets specific, it concerns adaptability. A model can rewrite a phishing lure once the first attempt is flagged, adjust an extortion negotiation according to how the victim responds, and generate enough payload variation that blocklists and signature matching struggle to keep pace [10]. Earlier waves of tooling, from exploit kits to phishing-as-a-service to ransomware affiliate programs, were static templates that still needed skill to use [15]. The training consequence Sehgal draws is that lures now read as grammatically clean and contextually relevant, so awareness programs have to move to out-of-band confirmation for sensitive requests [13].

The third recommendation carries the least evidence and the longest tail. Organizations rolling out AI agents and assistants internally are creating a layer of attack surface most security programs have not fully accounted for. Sehgal writes that vibe hacking increasingly involves manipulating the AI tools a defender has deployed [14]. He names that exposure. He does not describe how the manipulation works.

What to watch

  • Whether Anthropic or another vendor publishes victim counts and dwell times for AI-assisted campaigns, replacing the days-to-minutes assertion with a measurement.
  • Whether insurers and auditors begin asking for continuous exploitability evidence in place of an annual pentest report.
  • Whether a documented case turns on manipulation of a victim's own deployed AI assistant.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories