The offensive security market is splitting in two, and this week showed both halves.
On one side, venture money is betting that AI agents will do the attacking. Amsterdam’s Hadrian raised a $40M Series B co-led by Forgepoint Capital International and SmartFin, taking it to $65M total, for agentic pentesting and continuous exposure validation (TechGig). On the other side, services firms are buying humans who already know how to break things.
On Oct 8, Truesec, the Stockholm-based managed security and incident response firm, announced it acquired Binary Security, an Oslo shop founded in 2019 that does penetration testing, application security and security engineering. Terms: Undisclosed. Truesec says it has more than 440 cybersecurity specialists (Truesec).
Small deal. Clear signal.
The loop is the product. Truesec’s own framing gives it away: find weaknesses before attackers do, detect around the clock, respond when it matters. That’s the full loop. Offense finds the gap. The SOC watches it. IR cleans up when the gap gets used. Until recently those were three different vendors, three contracts and three reports that never talked to each other.
Put them under one roof and something useful happens. The pentest finding becomes a detection rule. The IR post-mortem becomes the next test plan. The SOC knows which exposures are real because its own red team proved them. That feedback loop is the moat. It’s much harder to copy than a tool.
Why buy now. AI is compressing the cheap end of offensive work. Automated scanning and agentic testing will eat routine external pentests, and that’s fine. What it doesn’t eat yet is the senior application tester who reads business logic, chains three medium bugs into an account takeover, and then explains it to the dev team in their own sprint. Binary Security sells exactly that kind of work: secure development, application security, an attacker’s perspective on modern software.
So the services play is to own the expensive, judgment-heavy layer and wire it into recurring MDR revenue. Pentests are lumpy project money. MDR is a subscription. Attaching the first to the second is how a services firm turns one-off engagements into renewals.
The tension with the AI-native crowd. Hadrian and its peers pitch continuous, machine-speed validation. Services firms pitch human depth plus a 24/7 SOC. Both are right about different buyers. A large enterprise with a mature team will buy the platform and run it in-house. A mid-size Nordic manufacturer without a red team wants someone to call. Truesec is betting the second group is big and loyal.
The likely end state is both. MDR providers will run agentic testing tools under the hood and sell the human layer on top. AI-native vendors will partner with MDRs for distribution, because someone still has to answer the phone at 3 a.m.
What buyers should ask. If your MDR also tests you, does the testing team report independently, or does it grade its own SOC’s homework? How fast does a pentest finding become a live detection, in days, not quarters? Is the offensive work continuous or still an annual project with a PDF at the end?
The read. Regional consolidation in services rarely makes the trade press. It should. In Europe especially, local language, local regulation and local trust still matter, and firms like Truesec are using M&A to cover the whole region and the whole loop. The AI offensive startups are raising real money to automate attacking. The services firms are answering with a simple argument: finding the hole is only a third of the job.
