Pentesting in transition

„Software does not follow an audit calendar“

Businesses need to evolve IT landscapes in ever-shorter cycles. New applications, updates and AI solutions are constantly changing the attack surface. At the same time, classical pen tests are often tied to fixed test intervals. How can security keep pace with this speed? In our interview, Georg Heise, Expert Offensive Security Consultant at Lufthansa Industry Solutions (LHIND), explains how this can work. His estimation: AI does not replace humans. It shifts the focus.

Norderstedt, October 8, 2026 – Many companies have their systems checked regularly by means of pentests. At the same time, applications, interfaces and digital processes are changing significantly faster than they did just a few years ago. Artificial intelligence opens up new possibilities for supplementing safety tests between classical pentests. But what does this mean for the role of security experts, for regulatory requirements and for securing AI applications themselves?

Mr Heise, what are the concrete benefits of AI in pentesting?

Georg Heise: AI changes the relationship between effort, scope and frequency of testing. AI agents can conduct technical investigations within a shared audit framework, adapt their approach based on the results, and also detect previously unknown vulnerabilities. This provides the ability to use the available resources to investigate more relevant functions, interfaces, and permissions, and to review changes more quickly. However, the extent of this benefit also depends on the quality of the results and the necessary inspection effort. Translating the efficiency gained into a better safety audit is crucial.

"AI changes the relationship between effort, scope and frequency of testing."

Georg Heise
Expert Offensive Security Consultant at Lufthansa Industry Solutions

Is an annual pentest even sufficient today?

Georg Heise: For applications that are constantly being developed further, an annual pentest alone is usually not enough. It provides an important assessment of the condition under review, but no safety evidence for the next 12 months. Software does not follow an audit calendar. Therefore, relevant changes and new threats should trigger additional, targeted reviews. Not every update needs a full pentest; scope and depth must be based on the actual risk.

AI can make mistakes, misclassify results or overlook correlations. How do companies prevent this from leading to false security decisions?

Georg Heise: For this, we need clear test limits, comprehensible test steps and reliable evidence. A reported vulnerability must be technically verifiable, and it must also be possible to identify the areas that have actually been investigated and where limitations or gaps have remained. Not having found a vulnerability is not proof that a system is secure. Experienced pentesters steer the procedure, review critical results and specifically investigate the areas in which AI is not reliably advancing. Technical responsibility cannot be delegated to a model.

So artificial intelligence won't replace the classic pentester?

Georg Heise: Our approach is to strengthen experienced pentesters with AI. AI can also take over parts of the actual technical investigation and is not limited to routine preparatory tasks. Pentesters design the testing strategy, examine complex relationships, question results and classify the technical implications for the company. They remain technically active themselves, especially where automated tests reach their limits. The focus is shifting: we need to do fewer individual steps ourselves, but still be responsible for the quality and meaningfulness of the entire audit.

"Our approach is to strengthen experienced pentesters with AI."

Georg Heise
Expert Offensive Security Consultant at Lufthansa Industry Solutions

In addition to AI Pentesting, AI is gaining ground in all conceivable areas of the company. Shouldn’t companies also test AI systems themselves?

Georg Heise: Yes, and here we have to keep two topics apart: AI as a tool for pen tests and AI systems as the subject of a pen test. In an AI application, we examine the entire system, including data sources, interfaces, permissions, and the actions it is allowed to perform. Manipulated content can be a business risk, especially if it causes an agent to disclose sensitive information or to perform improper actions. We must therefore investigate whether access limits, authorizations and protective measures remain effective even under targeted manipulation. The question is whether the system can be used safely in the intended business process.

What is the significance of regulatory requirements such as DORA or other compliance requirements?

Georg Heise: Regulatory requirements and operational safety must not be mutually exclusive. DORA already uses a risk-based approach for the financial companies concerned; it is therefore not just a matter of adhering to fixed audit deadlines. AI-based testing can complement such a program, but it must be appropriate to the respective requirements in terms of scope, quality and demonstrability. They do not automatically replace prescribed test procedures. It is crucial that the audits lead to concrete improvements and that the correction of detected weaknesses is verified in a comprehensible manner.

What do you think the future of pentesting will look like?

Georg Heise: I expect pentesting to be more involved in the life cycle of applications. In-depth assessments are supplemented by targeted assessments, for example following relevant changes or new threats. AI will play a greater role in both comprehensive and complementary tests. Efficiency gains can allow more relevant areas to be examined more frequently without making any change a full assessment. It is crucial that we identify risks earlier, support their resolution and review the effectiveness of the measures.

About Lufthansa Industry Solutions

Lufthansa Industry Solutions is a service provider for IT consulting and system integration. This Lufthansa subsidiary helps its clients with the digital transformation of their companies. Its customer base includes companies both within and outside the Lufthansa Group, as well as more than 300 companies in various lines of business. The company is based in Norderstedt and employs more than 3,000 members of staff at several branch offices in Germany, Albania, Switzerland and the USA.