Skip to content

Services/AI for Cyber

AI for Cyber Security

Custom made cyber security offensive and defensive AI.

Enquire about this service
GPU compute cluster used for model training and inference

At the forefront

Since 2023, Agile Information Security has been integrating Artificial Intelligence (AI) into our penetration testing, reverse engineering and vulnerabilily research workflows. As the technology matures, more possibilities are unlocked, and at the moment virtually everything we do is AI-augmented in some way.

By integrating AI into our testing methodology, we can uncover many more vulnerabilities than even a senior penetration tester would in a much shorter amount of time. We can reverse engineer binaries 10 times faster than an experienced reverse engineer can "by hand".

AI-guided, not AI-led

In all of our engagements we do not simply "let the AI loose" on a customer's environment. The AI never leads; an experienced human leads AI agents into specific, scope bound tasks, and their work output is reviewed at all stages.

Strict guardrails are in place to ensure the AI agents do not perform malicious or unauthorised actions. This is enforced by our own custom harnesses, as well as specific instructions given to the agent and kept in their memory context at all times.

Data kept in-house

We do not rely on third party cloud or cloud hosted Large Language Models (LLM). We own our own advanced hardware, kept in house, where we deploy state-of-the-art open source models, as well as our fine tuned versions of them, which have been adapted for our workflows.

By self-hosting our LLM, we ensure no client data is exposed to the cloud. All data is processed in our local LLM and kept securely stored in our computers, protected with strong encryption during transmission and storage.

Customer data is not kept long term; only the necessary to perform the engagement and any follow up the year after.

Leaders, not followers

In addition to fine-tuning our own LLM based on open source models, we also create custom LLM for customers. If, for example, you wish to train a LLM to perform initial triage of cyber security incidents, or to find a specific type of vulnerability, this is something we can do for you and have done in the past for other customers. The model can then be self-hosted or hosted in a cloud environment.

By fine tuning a small open source model for specific task(s), we can make it match or exceed the capabilities of a cloud based state-of-the-art model at a much lower running cost.

Purely manual is still possible

At a customer's request, we can also perform purely manual penetration tests, without relying on internal or external AI capabilities.

Contact us today to find out how we can help you.

Short or long engagements conducted by senior consultants and experts in technical cyber security.