Trending Topics

How Hadrian’s Nova is making always-on offense a security baseline
The annual penetration test is an artefact of a slower threat era. Attackers now probe continuously, chaining weaknesses across exposed systems long before a quarterly assessment lands in a PDF. Hadrian’s Nova launch is built around that uncomfortable truth: agentic pentesting is becoming a baseline for modern offensive security.
The pressure is not theoretical.
In our May 2026 interview with Jay Kaplan, CEO and Co-founder of Synack, he notes that 95% of organisations rank pentesting as a top priority, yet test only 32% of their global attack surface. That gap explains why continuous penetration testing is gaining urgency.
Hadrian announced Nova on 24 March 2026 as an extension of its external exposure management platform. The company says Nova delivers on-demand, AI-driven pentests without the scheduling delays and operational disruption associated with traditional human-led engagements.
Why agentic pentesting changes the offensive security model
The difference is autonomy.
Nova uses specialised hacker agents to explore attack paths, chain vulnerabilities, escalate access across real assets and validate findings with evidence. Hadrian also keeps humans in the loop, with expert review before results are delivered. That is critical because agentic pentesting is only useful if it reduces noise, not if it floods teams with speculative findings. Hadrian claims its platform eliminates 99.5% of false positives and reduces time to resolution by up to 80%.
This is not a replacement for elite red teams.
It is a way to replicate parts of their methodology continuously: reconnaissance, contextual prioritisation, adaptive attack chaining and vulnerability validation. As our Zscaler interview argued, businesses now need to “test in the same manner” they operate.
Nova sits between EASM, BAS and traditional pentesting. BAS tools simulate attacks; red teams prove what is exploitable; agentic pentesting tries to make that proof repeatable. Competitors such as Pentera, Horizon3.ai and AttackIQ are chasing similar validation budgets, but Hadrian’s angle is depth across the external attack surface.
For CISOs, the takeaway is practical: use agentic pentesting to prioritise remediation, support audit evidence and shorten MTTR. It will not remove the need for human creativity, but it raises the floor. Once testing becomes continuous, annual pentesting starts to look less like assurance and more like nostalgia.
