AI can find vulnerabilities. Humans find ways in
Every South African business is about to receive the same pitch – security testing driven by AI. Continuous instead of annual. Cheaper than whatever you’re paying now.
Two of the three claims are true. The third is the one to check before anything is signed.
Cobalt’s AI and Pentesting Pulse Report 2026, published in June, compared two surveys of security professionals a year apart. In 2025, 29% of organisations relied entirely on AI automation for their testing needs. By 2026, that figure had fallen to 9%.
The same research says why. Some 78% reported that fully automated scanning tools had missed critical vulnerabilities in their environment. It’s not a complaint about too many alerts, which any team can work through, but a report that came back clean when the business was not.
“When a scanner raises a false alarm, a security team loses a week chasing it,” says Marthinus Engelbrecht, group chief executive of NEWORDER. “That is irritating. When a scanner stays silent about something real, the business is told it is safe. It files the report, stops worrying, and never looks at that part of the business again. That silence is the expensive failure, and nobody ever finds out it happened.”
The distinction that decides this purchase is not technical. It is the difference between a list and a route.
A vulnerability is a fact about one system. A way in is a sequence: a low-severity flaw in a supplier portal, a connection between two systems that nobody wrote down, a login that should have been switched off, and a finance system three steps away. Automation is good at the first. Every item on the list can be true, and the report can still miss what mattered, because the danger was never in any item. It was in the order.
Chaining findings into a working attack path is Adversary Path Engineering. It is the same work an attacker does, in the same order. Nobody breaks into a business by exploiting a severity rating.
The head-to-head data agrees, and the detail matters more than the headline. In a hacking contest run by Hack The Box in November 2025, teams using AI and teams working without it were set the same 36 problems. The AI-assisted teams solved them at 3.2 times the rate. That gap is driven by the weaker end of the field. Among the top 5%, it falls to 1.69 times. The top-scoring team finished all 36. The best AI-assisted team stopped at 32.
The less skilled the tester, the more automation helps. The more skilled the tester, the less difference it makes. The market has already moved: 47% now prefer a hybrid model, automation for coverage and qualified operators for judgment.
“Automation is used where automation is genuinely better, which is breadth and repetition,” Engelbrecht says. “Every finding is then confirmed by a qualified operator before it reaches a client. That is Human Validation at Scale, and it is the difference between a report and an assessment.”
The offer is genuinely attractive.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on techcentral.co.za — the content belongs to TechCentral.