State of Pentesting Report 2026
The definitive benchmark for offensive security and remediation performance.
Secure every application with flexible pentesting that combines expert-led testing, autonomous validation, and actionable results
Learn moreIdentify exploitable risk across external networks, internal infrastructure, and cloud environments
Learn moreExtend your offensive security program with specialized assessments, adversarial testing, code review, and program-level support
Learn moreLLM applications generate serious vulnerabilities at 2.7x the rate of any other asset type, a ratio unchanged across two years of pentest data. Meanwhile, automated agents now reach initial access in under seven minutes at the cost of an API call. Discovery is no longer the bottleneck, and the security programs built around that assumption are exposed. Joe Brinkley (Head of Security Research) and Luke Doherty (Head of Customer Engagement) at Cobalt unpack new findings from thousands of AI and LLM application pentests and 450 security leaders.
What you'll learn:
The definitive benchmark for offensive security and remediation performance.
Discover the security challenges of AI adoption and how to address them.
Discover how AI is your highest-risk asset. The organizations closing that gap do six things differently.