Pentesting at the pace of software
Companies and organisations hacked by cybercriminals regularly make the news. A hospital forced to fall back on paper-based procedures for three days because its entire computer system has been paralysed? Something we’d rather not see happen. “Penetration testing” (‘pentesting’ for short) is to cybersecurity what a solid practice match is to any sports team: it shows where the weak spots are by simulating attacks – in a controlled manner and with permission.
Too often, companies treat such pentests as an annual box-ticking exercise. You schedule the pentest, wait weeks or months, receive a report and tick it off for audit or compliance purposes. Meanwhile, your IT environment is constantly changing: new cloud resources, updates, new integrations, new accounts. As if a sports team could make do with a single practice match per year. With innovative starter support from Flanders Innovation & Entrepreneurship (VLAIO), Allseek developed pentesting that delivers results and insights more quickly, but above all continuously. Its success was quickly picked up by larger players in the market, and Allseek now continues to develop its cyber capabilities under the wing of Aikido.
A strong idea no one wants to pay for
Wout Debaenst, co-founder of Allseek: “As an independent ethical hacker, I kept encountering the same pattern: even at the most secure companies, important ‘secrets’ such as passwords were scattered everywhere. For hackers, that’s the starting point of any attack. Once they gain access, they look for which password grants further access. That’s how hackers work their way step by step until they reach the highest privileges within a company’s computer system.
“Together with Miel Verkerken and Arne Feys, we developed a solution to that problem with Allseek. Yet to our great surprise, the companies we spoke to acknowledged the problem but didn’t consider it worth opening their wallets. As long as it wasn’t linked to broader risks or compliance requirements, it wasn’t seen as a strategic priority for many companies, however real the issue was. That surprising feedback forced us to rethink. The problem existed, but lacked sufficient urgency.”
Stepping back and pivoting
“Back to the drawing board,” Wout laughs. “The market forced us to look differently, more broadly and more effectively at security risks. Instead of focusing solely on secrets, we zoomed out: what systems are still exposed online, what vulnerabilities exist and how can we build a platform based on external detection?”
With innovative starters support, llseek was able to make that pivot and develop a platform for external detection of system vulnerabilities. Wout: “Our product-market fit gradually took shape, and we even secured our first paying customers. But communication remained a challenge; our message fit wasn’t quite right yet. Customers kept wondering what exactly we did and where our added value lay. That confusion also made something else clear: what we were building was not an additional feature, but the first building block of a broader security platform.”
USP: continuous
The real breakthrough came when Allseek sharpened its focus. “We started looking at continuous pentesting,” Wout explains. “That’s when we noticed it with customers: yes, this is what they want.” Instead of positioning external threats as the main message, Allseek shifted towards continuous pentesting – with external threats as one component within a broader whole.
“In hindsight, that makes perfect sense,” Wout continues, “when you realise that setting up pentesting for companies could take up to six months. In that case, one test per year, one report per year is the maximum achievable for large enterprises.” What Allseek introduced was not only faster deployment, but above all a continuous process: ongoing testing and adjustment, because “system administrators realise that their set-ups are also constantly evolving.” In other words, a shift from an annual check to an ongoing way of managing risk.
Timing also played a crucial role, Wout admits: “Agentic AI emerged and proved to be an enabler for the industry. Everyone we spoke to immediately understood: yes, this is what we want to see, what we want to try.”
Today, continuous pentesting is no longer a standalone product, but an integrated building block within the broader Aikido security platform.
Jump on the rocket ship?
“Our very first LinkedIn post about this new approach immediately caught the attention of Aikido, the fast-growing cybersecurity company focused on web applications,” Wout explains. “They were exploring the same idea, though with more emphasis on web applications.”
A difficult decision had to be made: continue as a start-up or jump on the rocket ship? Wout: “Because that’s what Aikido was, given how rapidly they were growing.”
Ultimately, Aikido proved to be the logical partner. Not only because of its speed, but because it already had what it takes start-ups years to build: an existing security platform, an international customer base and a strong engineering team.
The cultural fit proved decisive. “That fit was immediate and complete,” Wout stresses. “If I had to sum it up in a few words: autonomy, no bullshit, go fast. That was exactly the culture we wanted.” The collaboration quickly delivered tangible results. “ By integrating our technology into the broader Aikido ecosystem, we were able to build faster and roll out more quickly to existing customers.”
The merger with Aikido’s pentesting team dramatically accelerated development. “In six months, we achieved things that would otherwise have taken years,” Wout says. “From a product perspective, we have completely caught up with our main competitors.”
Solving two problems at once
The product solves two problems simultaneously. Wout: “We reduce the – mandatory – pentesting process for companies to a single day, whereas previously it took months: finding the right partner, scheduling, testing and reporting. But more importantly, security teams no longer receive an annual PDF, but continuous feedback that allows them to adjust immediately.”
“Such a report is otherwise merely a snapshot in time – a PDF that fulfils a requirement, while new vulnerabilities creep into your system throughout the rest of the year. We operate continuously: what changes occur in the application? Our autonomous agents automatically attack those changes and provide instant feedback. These are then verified by special ‘validation agents’ to eliminate false positives. The result is a low error rate.”
Wout: “That is what our fascinating journey has delivered: today, continuous pentesting is no longer a standalone product, but an integrated building block within the broader Aikido security platform.”