ADVERSARY ATLAS
Navigating the Offensive Security Market
The Penetration testing market has drastically changed in the last year. It has fractured into six structurally different subcategories of providers. The Adversary Atlas maps all six, the organizations defining them, and the consolidation now erasing the lines between them. It is written by Mark Carney and Jason Rowland, operators with a combined 45 years in the space, who have deep industry knowledge across every category.

GET THE ATLAS
Download now
Why this report exists
Annual testing was built for a slower adversary
In 2025, an average of 131 CVEs were published every day, a 24% increase year over year. Attack surfaces now change around the clock with new code, new cloud assets, and new AI-enabled features. A test that runs once a year cannot keep pace with an attacker that doesn't sleep.
That gap is now the market. Every vendor in this space, from crowdsourced bug bounty to autonomous AI agents, is placing a different bet on how to close it. Most market research either treats "penetration testing" as one static category or is vendor marketing presented as analysis. The Adversary Atlas takes a different approach. It is a plain-spoken map of the whole field, with the trade-offs stated.
That gap is now the market. Every vendor in this space, from crowdsourced bug bounty to autonomous AI agents, is placing a different bet on how to close it. Most market research either treats "penetration testing" as one static category or is vendor marketing presented as analysis. The Adversary Atlas takes a different approach. It is a plain-spoken map of the whole field, with the trade-offs stated.



The Market at a Glance
Six categories. One map. The names are inside.
Continuous Penetration Testing, AI-Native, Crowdsourcing, Software-Centric, Research-Driven, and Professional Services. The organizing question is not "what do they test?", because nearly everyone tests everything now. The question is who or what does the finding, and who is accountable for the judgment.
The map shows how each model works and where it falls short. The full report names the 22 organizations defining these categories, what changed this year, and what to watch before Volume 2.
The map shows how each model works and where it falls short. The full report names the 22 organizations defining these categories, what changed this year, and what to watch before Volume 2.

Built for the people making the call
CISOs and security leaders who are building or rebuilding a testing program for the next budget year.
Procurement and vendor-management teams who are comparing proposals that use the same words to describe different work.
Engineering and platform leaders who are deciding where testing fits in the release pipeline.
Boards, investors, and operators who are tracking a market that repriced itself in under two years.

Inside the Atlas
What you'll walk away with
Three forces reshaping the market
Consolidation, a new wave of AI capital, and the return of human validation as a premium. What each one means for your next vendor decision.
Deep-dive profiles of all six categories
Each category is profiled with the same eight-part structure: how it works, where it fits, how it's priced, and where the hidden costs sit. That makes it possible to compare vendors that describe very different work in the same language.
24 buyer's diligence questions
Four questions per category that separate a real capability from a slide. You can bring them straight into your next RFP or renewal.
The Buyer's Decision Framework
Start from the constraint that actually binds your program, not from the category you were pitched. Covers four constraints, recommended vendor mixes for three buyer types, and the most common forms of wasted offensive spend.
Five shifts to watch
Where the market is heading, what's getting cheaper, what stays expensive, and how to stop paying premium rates for commodity coverage.
Categories and vendors to watch
Where we expect the greatest structural impact before Volume 2, and which players are most exposed to acquisition.

