Kingly Clark

Security

Nobody is trying to hack you

Something is. It doesn’t sleep, it doesn’t get bored, and there are thousands of it.

The attacker stopped being a person

In November 2025, Anthropic disrupted the first documented espionage campaign run by software rather than by people. A state-linked group pointed an agent at roughly thirty organisations: technology companies, banks, chemical manufacturers, government agencies.

The agent did the reconnaissance. It found the vulnerabilities, wrote the exploit code, harvested the credentials, sorted what it took and moved on. Its operators stepped in for perhaps ten to twenty percent of the work, mostly to approve the next move. The rest ran unattended.

That was the proof it could be done. It is now simply how it is done. Roughly one in eight reported AI-related breaches already involves an agent acting without a person directing it.

Every assumption underneath your security programme was written for an attacker who has to sleep, gets bored, and can only be in one place at a time. None of those are true any more.

Your defence runs on human time

Every security programme ever built assumes a person in the loop. Someone reads the alert. Someone decides whether it matters. Someone schedules the fix for the next maintenance window. Each of those steps takes hours or days, and each was perfectly reasonable when the attacker also had to go home at night.

Attack speed against defence speed On a logarithmic time scale: an agent adapts to a failed login and gets in within 31 seconds; one automated toolchain exploits more than 8,000 exposed endpoints in under 10 minutes; defenders are given 15 days to patch a known exploited vulnerability. 2,160× slower Attack 31 seconds an agent reads a failed login, changes approach, and gets in Attack 10 minutes one toolchain exploits more than 8,000 exposed endpoints Defence 15 days the deadline defenders are given to patch a known exploited flaw
Logarithmic scale. Sources: Anthropic threat intelligence, November 2025; observed HexStrike activity, 2025; CISA Binding Operational Directive 22-01.

This is not a staffing problem. You cannot hire enough people to make a fifteen-day process outrun a thirty-one-second one. It is a difference in kind, which is why the industry’s standing answer, another quarterly test and a larger team, closes nothing.

And you just installed a new door

Your organisation is deploying agents right now. Support, engineering, finance, operations. Each one is handed credentials, and it is handed them faster than any person is hired. In most organisations the machine identities already outnumber the human ones, and they are policed by systems built to check whether a person is who they say they are.

Nearly every serious agent compromise so far has the same three ingredients:

  • An agent that can reach private data.
  • An agent that reads content it did not write.
  • An agent that can send something outward.

Every genuinely useful agent has all three. That is what makes it useful, and it is also the whole attack.

Your last penetration test did not look at any of this. It was not asked to.

Three things, in order

We attack you first

You hire us to break in, and we do it the way it is actually going to be done to you. Human judgement sets the objective. Agents do the volume. One tester holds a few ideas at a time and is tired by Thursday. A swarm holds thousands, tries all of them, and is not discouraged by the first four hundred failures.

We come at your network, your applications, your people, and at the agents you have quietly put into production.

We get in, and then we show you the way in

The deliverable is not a list of findings sorted by severity score. It is the route: where we got in, every step we took to escalate, what we could reach by the end, and what it would have cost you had we wanted to stay.

Access points are ranked by what an attacker gains from them, not by what a scanner scores them. Some critical findings cannot be reached in practice. Some medium ones are the entire building.

We leave something behind that fights at the same speed

Then we build the other side of it: defensive software for your organisation, running our own agents against your environment continuously. They attack you the way the incoming ones do, watch what the incoming ones touch, and close what they find.

It is not a dashboard for somebody to check on Monday morning. It runs on the same clock as the attack, because nothing slower is defence.

What we will not tell you

  1. That AI replaces your security team.

    It replaces the part of the job that was always machine work: the volume, the patience, the second and third shift. The judgement stays where it was.

  2. That a scan is a penetration test.

    A scanner finds what has already been catalogued by somebody else. That is the easy half, and it is the half your attacker has automated too.

  3. That the report is for your auditor.

    Compliance is a by-product of doing the work. A document written to pass a review rather than to be acted on has changed nothing about your exposure.

  4. That you are secure.

    Nobody can tell you that honestly. We can tell you what we got into, how long it took us, and precisely what would have stopped us.

All of this will be tested against your organisation eventually. The only question is whether the first people to write it up are working for you.

We accept new clients by referral only. If you have been referred, the person who sent you here will make the introduction.