SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
BreachLock launches Breach360 autonomous pen testing

BreachLock launches Breach360 autonomous pen testing

Wed, 26th Aug 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

BreachLock has launched Breach360, an autonomous penetration testing product that forms part of its unified security testing platform.

Breach360 is designed to test internal and external web and network environments. Customers can set scope controls and approve sensitive actions during an engagement. The product combines autonomous testing with BreachLock's existing Attack Surface Management and Penetration Testing as a Service tools in a single workflow.

The launch comes as security teams face growing pressure to distinguish genuine threats from large volumes of alerts and vulnerability reports. BreachLock is positioning the product as a way to show whether an exposure can actually be exploited, rather than simply flagging weaknesses.

The system draws on intelligence from more than 40,000 penetration testing engagements. It is also designed to keep human oversight over automated activity, including approvals for exploitation and lateral movement, along with guardrails and kill switches.

Single workflow

With Breach360, customers can discover exposed assets, test whether attack paths are viable and review mitigation priorities without switching between separate tools. BreachLock argues that consolidation is becoming more important as Chief Information Security Officers seek to reduce complexity across web applications and network infrastructure.

The product includes attack-path visibility, validation aligned with MITRE ATT&CK techniques, proof of exploitability and reporting aimed at both technical teams and executives. Customers can also request a review of findings and recommendations from a certified BreachLock penetration tester.

That model reflects a broader debate in cybersecurity over how far automation should go in offensive testing. While autonomous tools promise faster, more frequent testing, many organisations remain cautious about allowing software to probe live production systems without clear safeguards and direct human approval.

Breach360 is intended to address that concern by keeping users in control of engagement parameters throughout the testing process. BreachLock presents the human-in-the-loop model as a core part of the product rather than an optional add-on.

A company comment linked that approach to discussions with security leaders during the product's development.

"In the more than fifty CISO conversations that shaped Breach360's vision, one thing became clear: the industry is ready to embrace autonomous pen testing, but not at the expense of control," said Seemant Sehgal, Founder and CEO of BreachLock.

"Human-in-the-loop kept coming up as a non-negotiable. The other consistent theme was fatigue with vendor sprawl. CISOs want consolidation across their attack surface, spanning both network and web. Breach360 is our answer to that. Breach360 is the only autonomous pen testing solution that covers internal and external attack surfaces across web and network, with human-in-the-loop built into our DNA from day one," Sehgal said.

Market pressure

Autonomous penetration testing has emerged as one of the most closely watched segments in cybersecurity, as vendors seek to apply artificial intelligence to tasks that have traditionally relied heavily on human testers. For buyers, the appeal lies in the promise of more continuous validation of defences, especially as organisations add cloud services, internet-facing applications and distributed infrastructure.

At the same time, buyers have tended to distinguish between vulnerability scanning, attack surface mapping and full penetration testing. Tools that identify an issue do not always prove it can be chained into a meaningful attack path, and remediation teams often struggle to decide which findings require immediate attention.

BreachLock is trying to position Breach360 in that gap. By combining attack surface discovery, exploit validation and optional expert review, the company is presenting the product as a bridge between automated scanning and conventional consultant-led testing.

The wider platform is used by more than 1,200 organisations worldwide, according to BreachLock. In a market crowded with point products for vulnerability management, external attack surface monitoring and red teaming, platform-based approaches have become a recurring theme as suppliers look to expand their role in security operations.

Control model

A notable part of Breach360's design is its emphasis on customer approval for higher-risk actions. According to BreachLock, organisations can define the scope of each engagement, approve exploitation steps and limit lateral movement during tests. The aim is to reduce the risk of disruption in production environments while preserving enough realism to show whether controls work in practice.

The option to add certified human review may also appeal to buyers that want an audit trail or independent verification before findings are passed to internal teams. In regulated sectors, that additional layer could help security leaders reconcile automation with governance requirements and internal oversight processes.

Breach360 is available immediately through BreachLock's unified platform. Customers can use it across both application and infrastructure environments, with findings delivered in technical and executive formats and prioritised according to attacker logic rather than vulnerability scores alone.