Setting the Standard for Responsible AI in Offensive Security
Risk Associates, a global information technology consulting firm at the forefront of cybersecurity, risk, compliance, information governance, and strategy, today announced it has achieved accreditation as one of the first organisations globally to be recognised under CREST’s AI-Enabled Penetration Testing Supplement. This landmark inaugural cohort achievement positions the firm as a pioneering leader in next-generation offensive security, demonstrating proven capability to harness artificial intelligence at enterprise scale whilst maintaining the rigorous governance, transparency, and human oversight that characterise responsible AI deployment in cybersecurity.
THE SIGNIFICANCE: A MARKET INFLECTION POINT
The release of CREST’s AI-Enabled Penetration Testing Supplement in July 2026 marked a critical moment for the security industry. Whilst 69% of penetration testing providers already deploy AI in their workflows, most operate without independently verified governance frameworks. CREST’s new accreditation standard addressed this gap fundamentally, establishing the first formal framework for responsible AI integration in offensive security.
Risk Associates’ first-cohort recognition signifies more than a credential. It represents evidence of architectural capability in the age of AI-centric cybersecurity and signals to the global enterprise market that the firm stands among the earliest adopters of standards-based, governance-verified AI integration. For organisations competing on digital resilience, this distinction matters profoundly.
LEADING THE DIGITAL FRONTIER: WHAT THIS ACHIEVEMENT UNLOCKS
The CREST AI-Enabled Penetration Testing Supplement establishes verified governance across the entire AI-assisted offensive security lifecycle, encompassing reconnaissance, enumeration, configuration reviews, threat modelling, and reporting. For Risk Associates, this represents far more than an add-on credential. It is architectural validation that the firm operates at the convergence of artificial intelligence innovation and proven security methodology.
The accreditation amplifies Risk Associates’ existing CREST credentials in Penetration Testing, Vulnerability Assessment, and Threat-Led Red Teaming, extending capability into the AI-centric security operations that forward-thinking enterprises now demand. For clients navigating digital transformation at scale, this achievement unlocks four distinct advantages:
- Speed with rigour underpins the first. AI-assisted threat simulation operates at enterprise velocity, identifying sophisticated attack vectors in weeks rather than months, whilst human experts validate every strategic finding.
- Verified governance forms the second pillar. CREST accreditation proves that AI operates within a framework of transparency, accountability, and oversight. There are no black-box security decisions.
- Compliance confidence comprises the third element. For regulated sectors—financial services, critical infrastructure, healthcare—this accreditation signals that AI-enabled penetration testing meets the governance standards regulators expect.
- Threat intelligence advantage constitutes the fourth. First-cohort status means Risk Associates’ teams are among the earliest to operationalise AI-driven threat reconnaissance and pattern recognition at global scale.
DEFINING THE DIGITAL FRONTIER: MARKET CONTEXT AND STRATEGIC IMPACT
The CREST AI-Enabled Penetration Testing Supplement represents a watershed moment for the security industry. Whilst 69% of penetration testing providers already deploy AI in their workflows, the vast majority operate in an unverified, ungoverned space. CREST’s Annex B standard, launched in July 2026, changed that fundamental equation by establishing the first independently auditable governance framework for responsible AI integration in offensive security.
Risk Associates’ first-cohort status carries profound strategic significance. The firm now ranks among the earliest organisations globally to operate AI-enabled penetration testing within a standards-backed governance framework, positioning it as a thought leader shaping the future of AI-centric cybersecurity. For organisations competing on digital resilience, this credential signals access to next-generation offensive security capability delivered with verified governance and audit compliance. In financial services, critical infrastructure, and healthcare, where compliance and governance are non-negotiable, the accreditation removes a significant barrier to AI adoption, enabling clients to leverage AI-enabled speed and sophistication with confidence.
As AI adoption accelerates across the industry, first-cohort accreditation becomes a rare and defensible differentiator. It stands as evidence that Risk Associates is not experimenting with AI, but leading with responsibility and discipline. This achievement opens genuine pathways to new client engagements, partner opportunities, and market share among enterprises seeking verified leadership in the AI-centric security frontier.
SHAPING THE AI-CENTRIC SECURITY FRONTIER
Risk Associates’ first-cohort achievement is not an endpoint. It is a launchpad. As enterprises worldwide accelerate digital transformation and threat sophistication evolves in real time, the demand for AI-enabled offensive security will only intensify. Risk Associates is positioned to lead that evolution, setting the standards for governance, transparency, and responsible innovation that the industry will follow.
The digital frontier has arrived. Risk Associates is leading it.
About
Risk Associates
Risk Associates is a global information technology consulting firm specialising in cybersecurity, risk, compliance, information governance, and strategy. The company helps organisations worldwide identify and manage cyber risks, strengthen their security posture, and meet regulatory and industry requirements. As a PCI SSC Qualified Security Assessor and Approved Scanning Vendor, and a CREST-accredited provider across Penetration Testing, Vulnerability Assessment, and Threat-Led Red Teaming, Risk Associates brings deep technical expertise to every engagement. The firm’s services span PCI DSS and SWIFT CSP compliance, ISO 27001, threat intelligence, managed security, digital forensics, and security awareness, delivered by a team of highly certified information security professionals.



