Offensive Security Investments Surge as AI Threats Increase
Research from Omdia, led by Theresa Lanowitz, indicates a growing investment in offensive cybersecurity practices due to the increasing speed and sophistication of AI-driven attacks. Organizations are seeking to expand their use of AI for penetration testing, red teaming, and vulnerability assessments, but with significant concerns about the potential for AI agents to become ‘rogue’ and the associated costs. The research highlights a 99% investment in software supply chain security, but only 44% are building Software Bills of Materials (SBOMs) at the time of build. This creates a significant vulnerability as AI-generated code and third-party software increasingly enter the supply chain. The report emphasizes the need for innovation in software supply chain security and the importance of executive-level involvement in addressing these challenges.
Omdia’s Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for penetration testing, red teaming, and other practices. So far, agentic AI has proven more effective for cyberattacks than cyber defense, but that may be changing. Theresa Lanowitz, principal analyst at Omdia, spoke with Dark Reading’s senior news director, Rob Wright, at the News Desk at Black Hat USA 2026 about new research regarding shifting enterprise investments in offensive cybersecurity practices, such as penetration testing, vulnerability assessments, and red teaming, amid growing concerns about AI-driven threats. Lanowitz explained how organizations are looking to increase spending on offensive cybersecurity practices to keep pace with the increasing speed with which threat actors are weaponizing new vulnerabilities and launching attacks. One way to address the AI-enhanced speed of adversaries is to use AI on defense as well, though she highlighted some of the risks for organizations. "You want to limit the blast radius of what that agent is actually able to do," Lanowitz said, referencing some of the recent attacks by rogue AI models. For all of our Dark Reading News Desk videos, please check out our YouTube channel, and our curated video articles. Dark Reading News Desk With Theresa Lanowitz: Full Transcript Dark Reading’s Rob Wright: Hello and welcome to the Dark Reading News Desk at Black Hat USA 2026 in Las Vegas. I'm Rob Wright with Dark Reading, and I'm here with Theresa Lanowitz of Omdia. Theresa, thank you for joining. Theresa Lanowitz: Thank you so much, Rob. I'm really excited to be here with you. DR’s Rob Wright: I'm excited to dig into this research here. You're doing ... you did research on offensive cybersecurity. Theresa Lanowitz: Yes, the title of it officially is "Offensive Security Strategies: Granting the Same AI Advantages to the Defender." DR’s Rob Wright: I love it because there's a bit of an imbalance, right? Theresa Lanowitz: Right, right. DR’s Rob Wright: So, how can AI be used for offensive cybersecurity in a, I guess, safe, responsible way? Is it possible? Theresa Lanowitz: Well, that's the question, right? The safe, responsible way, building trust, and that's really, I think, where we are right now. We're at that inflection point, and so from the research that we just conducted, what we found out is there were three big key areas. The first is AI is certainly fueling the need for offensive security strategies. However, there are some concerns there, and that goes to the point of trust and responsibility that you just made. The second is that those traditional cybersecurity practices that we've been using in offensive security — they're no longer working. If you think of your traditional pen testing, your traditional red teaming, vulnerability assessment, social engineering testing, those are no longer working. And then third, there’s a spending increase in offensive security, so organizations are saying yes, we're going to spend more on offensive security because we know we need it because everything is moving faster, because of AI. The attacks are moving faster, the attackers are moving faster, the vulnerabilities are being exploited. That’s moving faster as well. Speed is now the biggest concern, and so along with that, this idea of continuous visibility comes into play. But if we take that first question that you asked about using agents responsibly, using AI responsibly inside of offensive security, so people said yes, "We want to use agentic AI, but we have some concerns about those agents," and those are very legitimate concerns. People said, "Well, you know, there's this resource consumption, utilization, and potentially high cost." And so, if you look at it from an industry perspective, that's where the industry can really step up and innovate. And granted, we’ve seen a lot of innovation in the past three months specifically. DR’s Rob Wright: Tremendous. Theresa Lanowitz: I think there's this idea of saying, "Yeah, we want to use these agents, and the way people really want to use those agents,” they want to say, “We want to have continuous monitoring of our attack surface across all vectors.” And when you think about it, this is where that responsibility comes into play again. Because AI is now embedded in everything; it's embedded in our HR systems, our accounting systems, our finance systems. It's not just in one area that increases your attack surface, and they also want to be able to use agents to continuously discover assets. And they want to be able to use those agents to be able to prioritize remediation based upon business risk, right? Because if you really think about what the cybersecurity team is really responsible for, it's responsible for outcomes. We're in the outcome business in the security world. DR’s Rob Wright: So, how do you — I mean, that’s a pretty tall order for the AI — how do you control costs? How do you keep that from being like, you know, making your C-suite cry at the numbers of the spend on the tokens. Is there a way to manage that to keep it lower? Will AI get better as it goes along, and maybe you don't have to use it as much? Theresa Lanowitz: I don't think anybody really knows the cost answer at this point. But what we do know from the research that we published is that 88% of organizations say they are willing to spend more on offensive security strategies, but they do want to make sure that they're reducing the risk with that. While they're spending more, the cost comes into play in terms of those agents. They want to make sure that they can keep those agents under control. DR’s Rob Wright: They want to see results. Theresa Lanowitz: Absolutely, they want to see results. And what they want to be able to see — they're spending more, but what they want to have that visibility across the entire IT estate. Theresa Lanowitz: They also want to make sure that whatever they're doing can integrate with existing tooling. They don't want to have to go through this rip and replace. And then they want to make sure that along the way, they are reducing risk. And this is now a board-level issue, and it's a C-level. DR’s Rob Wright: 100%. Yeah, but with everything you’re seeing these days, yeah, how could it not be? There’s a lot of pressure. But I guess if you’re an end-user organization, there’s got to be some concern out there about making an investment, not just making an investment in AI, but actually deploying it because these days you don’t know if you’re going to be hacked by APT28 or GPT 5.4 or whatever. It could be a model or someone’s agent that is in training and decides to step out and do a little freelancing. So, do you think there’s concern on the part of end-user organizations about having something like that happen, either to them or from them, from their own ... Theresa Lanowitz: Yeah, absolutely. I think that is a concern. Like you said, it could go rogue. It could do a little bit of experimentation, and that’s why, from an engineering perspective, you want to make sure that you are building sandboxes. You want to limit the blast radius of what that agent is actually able to do. And we also have some new research out on the software supply chain. DR’s Rob Wright: Oh, boy. Theresa Lanowitz: And the software supply chain — it's a business issue, it's a C-suite issue as well as being a cybersecurity issue. And here's an amazing stat that we found for that research. DR’s Rob Wright: I'm ready. Theresa Lanowitz: 99% of organizations say that they are investing in the software supply chain. DR’s Rob Wright: Really? Theresa Lanowitz: 99%, yeah. To me, that's an amazing stat. DR’s Rob Wright: I mean, I think some of them might be liars, but that’s a good stat, to make an investment like that, right? Theresa Lanowitz: Right. And so if you take that back a little bit, and you say, “OK, 99% say they’re investing in supply chain security,” what I read from that is that the executives are saying, “Yes, this is an issue.” And the practitioners are saying, “Yes, this is an issue.” DR’s Rob Wright: There’s alignment. Theresa Lanowitz: Yes, there’s alignment, and anytime we see the line of business get involved with technology, we see alignment, and we start to see better outcomes. And so this is a really promising area because we’re getting so much software from so many different places, right? Open source software, third-party, and now AI-generated code. And that AI-generated software, is it introducing more vulnerabilities? We don’t know. DR’s Rob Wright: Yeah, yeah. I mean, judging from the pitches I get in my inbox these days, it’s either AI or it’s supply chain. Theresa Lanowitz: And the supply chain issue is really critical right now because of that influx of third-party, including open source and AI-generated code. DR’s Rob Wright: Right. So, many attacks this year where stuff has been infiltrated, and, I mean, there’s been serious, serious blast radius from some of those attacks, too. Theresa Lanowitz: And if that software supply chain is somehow corrupted, it’s somehow infiltrated, as you just said — that has serious repercussions to the business, and that’s a threat. It can take — it’s an intentional threat by some adversary or maybe by some agent that has gone a little bit rogue, and it can take down your business. And one of the other things we found in this software supply chain research, we know the SBOM is really important, the software bill of materials, but only 44% of organizations are building an SBOM at the time of build, and there’s ...
