Position · Economics
Two in three companies never test.Not because they do not want to.
Johan Almgren · Pentester and founder
Published 2026-08-25 · 6 min read
I did not start Ravnsec because AI is interesting. I started it because the invoice was locking out almost everyone who needed the test.
The number that made me leave
Eurostat asks Europe's companies every year which security measures they actually took. For 2024, 34.6 percent of companies with ten or more employees said they had run some form of security test. Password policies and backups sat above 79 percent. Testing is at the bottom of the list.[02]
Eurostat publishes no size breakdown for testing itself. It does for the neighbouring measure, risk assessment, and there the difference is visible: 75.6 percent among large companies against 29.4 percent among small ones. The same pattern, in all likelihood for the same reason.[02]
What is actually expensive
I built systems before I broke them. The years in document automation taught me what production code looks like when nobody is watching. The exceptions. The shortcuts. The integration that was going to be replaced and never was. Then I changed sides, first at one of the largest consultancies in the Nordics and then at one of its foremost penetration testing firms.
What surprised me was not what we found. It was who we never got to. An engagement is priced in days, and most of those days are spent before anyone tries to get into anything.
That is not an opinion about the industry, it is how the work is defined. NIST describes a test in four phases: planning, discovery, attack and reporting. Two of the four sit before the attack. The mapping is exhaustive, patient and dull, and it is exactly as necessary as it is slow.[01]
The customer pays for judgement. The invoice is dominated by mapping.
What the agent moves
Exhaustive, patient and dull are three properties a machine has and people lose after day three. When the agent takes that part, the engagement shrinks from weeks to days, and the price follows it down.
That is the whole business idea. Not that AI finds things people miss, though it happens. It is that it makes the cheap work cheap, so the expensive work becomes purchasable by more than the largest.
The research here is young and uneven. An independent evaluation of several agent architectures in realistic testing scenarios found that modular agents get markedly better at complex multi-step tasks when given the right support, but also that they fail in recurring patterns. That is roughly as far as anyone can honestly reach today.[05]
What the agent does not move
An agent does not know what is dangerous. It knows what is unusual. The difference between those two is the entire profession, and it cannot be automated away. Every finding in our reports is exploited by hand and proven with steps someone else can follow. What does not hold up is discarded before you see it.
That is why there is a name in the report. Not a tool's name. A person's name.
Why this becomes a question now
NIS2 requires those covered to have procedures for assessing whether their own security measures actually work. In Sweden the directive is implemented through the cybersecurity act. Assessing whether something works is hard to do without testing it, and testing once every three years is hard to call a procedure.[06][04]
The requirement does not move the price. It only moves the number of companies that have to deal with it.
Sources
- [01]SP 800-115, Technical Guide to Information Security Testing and Assessment, avsnitt 5NIST · 2008-09-30
- [02]ICT security in enterprises, Statistics Explained (hämtad 2026-08-25)Eurostat · 2026-08-25
- [03]Awareness of ICT security issues rising in enterprisesEurostat · 2025-02-11
- [04]Cybersäkerhetslag (2025:1506)Sveriges riksdag · 2025-12-11
- [05]From Capabilities to Performance: Evaluating Key Functional Properties of LLM Architectures in Penetration TestingarXiv · 2025-09-16
- [06]Direktiv (EU) 2022/2555 (NIS2), artikel 21.2EUR-Lex · 2022-12-14