top of page

NetSPI + Synack: What the Combination Says About the Direction of Offensive Security

6 days ago
5 min read

NetSPI and Synack announced plans on September 2, 2026 to merge, bringing together two established - and competing - offensive security providers with somewhat different histories, delivery models and technology strengths. The transaction is expected to close in October, subject to customary conditions. It's unusual to announce a merger versus an acquisition, but there are usually good reasons to do so, as in customer retention.


It is a notable combination, but perhaps less because it represents a sudden change in offensive security than because it reflects several changes already underway.

Across numerous vendor briefings that we have taken over the past year or more, a consistent picture has emerged: penetration testing is becoming more continuous, automated capabilities are improving, and organizations increasingly want to understand which exposures are actually exploitable rather than manage another expanding list of vulnerabilities. The use of agentic AI accelerates this change.


From Penetration Tests to Continuous Validation


Traditional penetration testing is not disappearing. There remain good reasons for point-in-time assessments, including regulatory requirements, specialized testing and major application or infrastructure changes. What is changing is the expectation that periodic testing alone can provide sufficient visibility into environments that change continuously.


A human security analyst conducting security testing at a computer.

Synack describes continuous offensive security as keeping a defined attack surface under ongoing expert-led testing, rather than replacing penetration testing itself. The underlying discipline remains penetration testing but the cadence, coverage and supporting automation are evolving.


NetSPI and Synack both arrive at this market transition from established offensive-security positions. NetSPI provides broad penetration-testing capabilities spanning applications, cloud, networks, AI/ML systems, mainframes, hardware and other environments, along with attack-surface visibility and vulnerability-prioritization capabilities. Synack provides an AI- and human-led penetration testing platform for continuous security validation, combining Sara AI Pentesting with the Synack Red Team. The Synack Platform provides visibility and control across testing activity, validated findings, and remediation efforts. Together, the two create a potentially interesting foundation for a broader continuous offensive-security offering.


Agentic AI Is Changing the Automation Conversation

Ask any security professional and they will tell you that security testing has used automation for years. What is changing with agentic AI is the potential scope of the work delegated to machines.


Traditional vulnerability scanning generally performs predefined discovery and testing at scale. Emerging agentic approaches are intended to go further, using context and iterative decision-making to perform portions of reconnaissance, testing and validation with less direct human direction.


Synack's Sara AI Pentesting is one example of that progression. The company positions Sara AI Pentesting alongside its human researcher community, rather than as a replacement for it. The merger announcement follows the same philosophy. According to the CEO of Synack, Jay Kaplan, "AI is transforming security testing, but it’s still experts who find the vulnerabilities that lead to real breaches.”


There is considerable attention in the market around fully autonomous penetration testing but we should be cautious about assuming that autonomous testing replaces human pentesters anytime soon. On the Cyber Sidekicks podcast, Paul Mote, VP, Solution Architects at Synack, reinforced this belief: "You still have to do pen testing and you have to have humans in that process for most of the regulations, but you have this sprawling attack surface that is just growing exponentially," pointing to the need for "hybrid offensive security." This is where machines increase testing frequency and coverage and humans concentrate on ambiguity, creativity, complex exploitation and business context.


Connecting Exposure to Exploitability

The other important aspect of the NetSPI + Synack merger is the breadth of information that potentially comes together.


NetSPI brings attack-surface visibility, vulnerability prioritization and a broad portfolio of specialized testing services. Synack brings an AI and human penetration testing platform to expand testing coverage, validate real-world exploitability and provide continuous visibility across testing and remediation


Connecting those capabilities could help answer a much more useful set of questions:

  • Is the asset exposed?

  • Is the vulnerability exploitable?

  • What can an attacker reach from it?

  • How important is that path to the business?


That is a substantially different conversation from simply asking whether an organization has critical vulnerabilities. It also aligns closely with where Continuous Threat Exposure Management (CTEM) is headed.


CTEM As Useful Context

CTEM is sometimes treated as a product category, but it is arguably more useful to view it as an operating model. Its value comes from connecting several activities that historically operated independently: understanding the relevant environment, discovering exposures, prioritizing them, validating whether they matter and mobilizing remediation. Offensive security has an increasingly important role in that process because it provides the validation layer.


At the same time, a vulnerability may carry a severe CVSS score and still be difficult or impossible to exploit in a particular environment. Another vulnerability with a lower generic severity rating may sit on a reachable system and provide the first step toward a critical business asset.


This merger demonstrates the broader movement toward continuous offensive security. As automation and agentic capabilities make validation faster and potentially less expensive (though the jury is out on that), organizations should theoretically be able to test a much larger proportion of their exposure landscape rather than reserve deep testing for a relatively small number of high-priority applications.


The Legacy Bits Actually Create Valuable Outcomes

There is another aspect of NetSPI's portfolio that is particularly relevant. Attackers do not necessarily enter through the asset receiving the most security attention. They look for whatever provides a viable path although modern cybersecurity conversations naturally gravitate toward cloud, APIs, AI and other rapidly evolving technologies. Enterprises, however, still have mainframes, internal networks, hardware systems, legacy applications and specialized environments. NetSPI's testing portfolio spans many of these areas, including mainframe and hardware testing. That means exposure management ultimately has to account for both the highly visible Tier 1 application and the less interesting system connected to it.


Therefore one of the most valuable outcomes of increased continuous offensive testing could be broader coverage of the systems organizations historically test less frequently.


The Gist

The strategic rationale for the NetSPI/Synack combination is reasonably clear. Both companies see offensive security moving toward greater testing frequency, broader coverage and tighter integration between AI and human expertise. The combined organization says it intends to apply agentic AI across its platform while maintaining a substantial offensive-security talent base.


We are seeing the market moving from periodic testing toward continuous validation; from vulnerability volume toward exploitability; and from simple automation toward a hybrid model in which AI performs more of the repetitive and scalable work while experienced offensive-security professionals focus on what still requires judgment.


We'll be watching how quickly and effectively the two companies’ businesses come together and how deeply the two platforms integrate. Other remaining questions we'll be looking to answer are:


  • How well will the automatons and humans share testing context?

  • Can findings from attack-surface discovery flow naturally into validation?

  • Can AI materially expand the amount of an enterprise environment that receives meaningful offensive testing without sacrificing quality?

  • Can the combined platform help customers prioritize exploitable attack paths rather than simply produce more findings?


As mentioned above, mergers can be pursued instead of acquisitions to reduce possible customer attrition. The joint press release reinforces this desire and underlines that the combined company "will continue supporting existing customers, partners, and employees throughout the integration, with a sustained focus on service continuity and long-term growth."


Will the "one-plus-one-equals-three" strategy prevail? It will depend on integration, customer retention, regulatory review, and whether the combined company can turn its scale into demonstrably better testing rather than simply broader packaging. We will be watching closely to see how effectively that thesis translates to measurable customer value.



Comments


bottom of page