Guest Blog: Vendor Decision Making Criteria

This is a repost from LinkedIn with approval from the author, Iain Paterson.

(We have applied light formatting to improve the readability of the post in blog form. No text was otherwise changed. You can click the embed above to see Iain's original post on LinkedIn.)

Read Iain's Post Here

Agentic Offensive Security and AI Pentesting have been really loud on LinkedIn lately. I think there's a lot of hype vs fact.

Before becoming the CISO at Well Health, I was the CEO of a boutique penetration testing company, so this topic is near and dear to me.

The noise cuts both ways.

On one hand, what's possible today leveraging AI was science fiction and junk products just a couple of years ago. We've gone from automated fuzzers with a 90% false positive rate to REAL actionable findings. On the other, plenty of claims just don't stack up against what I've seen out here.

Here's how I've been thinking about vendor selection in this noisy market:

  • We tested on our messiest, most sensitive systems, the ones that keep me up at night and hold real patient data, not a clean demo app or sandbox. Anything easier won't show you how a product behaves in a real deployment.
  • We knew exactly what we were buying: White Box or Black Box, AppSec or OffSec, guardrails and how they're implemented, continuous or point-in-time, web or infra (or both). Most vendors focus on one thing; a vendor with omni-capabilities is a huge bonus and one less product to shop for.
  • Autonomous vs. human in the loop. I don't believe in fully autonomous pentesting, especially in sensitive environments. Even companies claiming full autonomy often have a human behind the scenes. The vendor we chose shows us exactly where a human is involved, if at all, which makes them more trustworthy than pretending it's all agents all the time. And yes, the logs are easy to see.
  • We pushed hard on production safety. This is OffSec, not AppSec: these agents take real, intrusive actions against live environments. We asked what the guardrails actually are, what happens when something breaks, who's accountable for a wrong call, and how they validate a vulnerability if a guardrail blocks the attack.
  • We checked whether it fits how we operate. We got stakeholder buy-in and asked hard questions: could we bring our own AI model, our own cloud, our own people into the loop? Did it fit our existing workflows? We also own a pentesting practice, so we wanted our team to use these tools both internally and commercially with our customers.
  • We didn't just believe the POV. POVs are built to impress, and the reports don't always reflect real-world performance. So we went around them and talked to similar-sized customers in our industry about how the product performed in their shop.

This was my criteria for finding a partner delivering real results with true autonomy in this category. A handful of companies have real capability; the rest is hyperbole. We chose Terra Security after applying this criteria. We found strong results and a team that built a solution fitting our complex needs.

Words of Gratitude

On behalf of everyone at Terra Security, we share our deepest gratitude to Iain for his testimonial. We appreciate all of our customers and partners for entrusting us with such a critical part of their security program. We don’t take it for granted.

LabelContinuous is the new pentesting standard.Book a demo to see how you can operationalize
it for your organization with Terra.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Smooth sand dunes bathed in warm light against a dark background.
YouTubeLinkedInXSoundCloud
Terra
SOC 2 Type II CertifiedSOC 2 Type II Certified
Terra cross emblem