Listen to the article

0:00
0:00

Key Takeaways

🌐 Translate Article

Translating...

📖 Read Along

💬 AI Assistant

🤖
Hi! I'm here to help you understand this article. Ask me anything about the content!

By André Pienaar

This week, two of the most consequential names in offensive cybersecurity — NetSPI and Synack — announced a merger to form what will be the industry’s leading offensive security platform, backed by KKR, C5 Capital and other investors. As a growth investor, C5 has supported Synack’s growth since 2020. This merger is not simply a consolidation story. This deal indicates where effective cyber defence is heading in the age of AI.

The question is: as AI systems become capable of finding and exploiting vulnerabilities on their own, does the human hacker still matter? Some vendors have bet the answer is no, racing to build fully autonomous penetration-testing platforms that promise to replace expert red teams with software solutions alone. The NetSPI-Synack combination is a rebuttal to that thesis — and, I would argue, the correct one.

Nation-state adversaries do not attack in predictable patterns. The most damaging breaches of the past decade — from state-sponsored supply-chain compromises to the exploitation of obscure business logic flaws inside financial institutions — were not found by scanners running down a checklist. They were found by people who understood the vulnerability of the human factor and the contradictory ways in which people, cultures and organisations actually work.

Autonomous tools are exceptionally good at finding everything that is scannable. They are not yet good at finding what is exploitable in the way a determined, well-resourced and battle-hardened adversary would exploit it. In addition, autonomous tools are not yet capable of the operational fusion of cyber, cognitive warfare and kinetics that we have observed across the three major theatres of war in Europe, the Middle East and Africa since 2021. That distinction is the entire game in national security and cybersecurity, where the ultimate attacker is a hostile military force, intelligence service or criminal syndicate with a specific objective.

This is also the thesis C5 backed when we invested in Synack in 2020. Synack’s model pairs a human Red Team — a vetted global community of researchers, many with backgrounds in signals intelligence and offensive security work for governments — with agentic AI that accelerates discovery and validation without replacing the secret sauce of human judgement. NetSPI has built a comparable philosophy from the penetration-testing side of the market. Bringing the two together, with the strength of KKR’s balance sheet behind them, creates an unrivalled platform with the scale to serve the institutions that matter most for security and resilience: critical infrastructure providers and federal government agencies.

Why does this matter for national security specifically? Offensive security validation has quietly become a frontline discipline in the escalating regional wars that are increasingly merging into an all-consuming global conflict. A cybersecurity industry that can only produce autonomous and commoditised testing at scale — without the depth of expert judgement needed to anticipate a sophisticated adversary — leaves the most critical institutions with a false sense of assurance. Scale without judgement and expertise is not resilience; it is a larger vulnerable surface area of misplaced confidence.

There is also a capital allocation insight here for investors in defence and national security. The market has spent two years pricing autonomous-everything narratives at a premium. The underlying assumption is that human expertise is a cost to be engineered away. The NetSPI-Synack combination suggests the more durable model is the opposite: AI acts as a force multiplier for expert judgement, and it is not a substitute for it. That is a distinction worth pricing correctly, because the institutions that get this wrong will be the ones explaining a breach to investors, to a board or to a regulator after the fact.

The combination of Synack and NetSPI is worth following not just as an exciting business story, but as an indicator of how the offensive security market — and by extension, the defence of Western critical infrastructure — chooses to compete against adversaries in the age of AI.


André Pienaar is the Founder and CEO of C5 Capital, a specialist growth equity investment firm focused on energy security.

Share.
Exit mobile version