CBTS Launches AI-Enabled Penetration Testing as a Service to Deliver Continuous, Expert-Validated Exposure Insights
New service combines autonomous penetration testing with security expertise to help organizations validate exploitable
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
CBTS, a leading North American technology services company, today announced the launch of Penetration Testing as a Service (PTaaS), leveraging industry-leading autonomous penetration testing capabilities. The new service helps organizations move beyond point-in-time annual testing with autonomous penetration testing and CBTS security expertise to validate exploitable risk, reveal real attack paths, and prioritize remediation as environments evolve.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260811692961/en/
Annual testing can’t keep up with continuous change
Cloud environments, SaaS applications, connected systems, third-party relationships and AI systems are expanding enterprise attack surfaces faster than traditional testing cycles can track, and the industry’s own breach data backs that up, as vulnerability exploitation now outpaces stolen credentials as attackers’ top way in, with AI narrowing the gap between disclosure and exploitation from months to hours.
“Organizations are moving beyond point-in-time assessments to continuous security validation, and partners like CBTS are helping make that transition practical,” said Tim Mackie, Global Vice President of Worldwide Channels, Horizon3.ai. “By combining the autonomous penetration testing capabilities of NodeZero with CBTS’s security expertise, organizations can continuously validate exploitable risk, prioritize remediation based on evidence, and strengthen their security posture as their environments evolve.”
AI generated findings need human review to ensure accuracy
CBTS built PTaaS on NodeZero to autonomously perform penetration tests across live production environments without disrupting operations. CBTS security experts review the results of each assessment, providing customer-specific context and remediation guidance. Together, they extend penetration testing from a once-a-year checkpoint into an ongoing practice, giving organizations continuous evidence of which risks are actually exploitable as new vulnerabilities, configurations, and identity exposures emerge.
“Environments don’t stand still, so threat identification can’t either,” said Ryan Hamrick, Director, Security Practice, CBTS. “Traditional penetration testing gives organizations a valuable snapshot, but that snapshot can age quickly as new vulnerabilities, configurations, identities and systems are introduced. CBTS PTaaS helps clients continuously verify which risks are actually exploitable in their own environment, understand how attackers could chain them together, and prioritize remediation with confidence.”
How it works
Powered by NodeZero, CBTS PTaaS runs recurring penetration tests across a client’s environment to validate exploitable risk and demonstrate how individual weaknesses can chain together to form real attack paths. CBTS penetration testing and ethical hacking professionals review each assessment to provide expert context, remediation guidance, and customer-specific recommendations. Every finding comes with 100% proof of exploitability.
The service provides clients with:
- Validated exploitability based on testing within the client’s environment, helping security teams focus on the risks attackers can actually exploit.
- Attack path analysis showing how multiple weaknesses could be chained together to compromise critical systems.
- Expert review from CBTS penetration testing and ethical hacking professionals, providing customer-specific context, remediation guidance, and recommendations for reducing validated risk.
- Customized reporting that helps security teams prioritize remediation based on validated exploitability and track progress over time.
- Flexible testing frequency that allows organizations to choose a daily, weekly, monthly, or quarterly cadence based on their risk profile, business needs, and security maturity.
As organizations adopt Continuous Threat Exposure Management (CTEM) programs, security teams need ways to continuously identify, validate, and prioritize the exposures most likely to create business risk. Verizon’s 2026 Data Breach Investigations Report found that a vulnerability’s likelihood of being exploited again drops by roughly half just 30 days after its last observed exploitation, a finding that reinforces why continuous validation and prioritization, not one-time patching, is what reduces risk.
CBTS PTaaS helps organizations put that approach into practice by assessing vulnerabilities alongside configuration issues, identity exposures, and other weaknesses across systems, devices, applications, and networks. By validating which risks are actually exploitable and demonstrating how they can be chained together into real attack paths, the service gives security teams a clearer path from exposure discovery to remediation, helping reduce noise, focus resources, and strengthen their security posture over time.
This is a critical capability when adversarial frontier AI models are dramatically increasing the volume of newly disclosed vulnerabilities. Contextual prioritization helps security teams focus on the exposures that matter most and respond with confidence. To learn more about CBTS Penetration Testing as a Service, visit our blog. For more on the CBTS cybersecurity portfolio, see our new website.
About CBTS
CBTS is a leading technology services company that designs, builds, and operates resilient technology foundations for mid-market and enterprise organizations across North America. Offering expertise in AI, data, applications, platforms, and security, CBTS combines the technical depth of a large integrator with the flexibility and client focus of a specialized partner. Founded in 1994 and headquartered in Cincinnati, Ohio, CBTS and its OnX Canada division serve more than 3,000 clients. CBTS has been named CRN Tech Elite 250 for seven consecutive years and ranks #49 on the CRN Solution Provider 500. Learn more at cbts.com.
About Horizon3.ai
Horizon3, the AI-Native Proactive Security Company behind NodeZero®, shifts the advantage from attackers to defenders by giving organizations the power to fight AI with AI. NodeZero, the World’s Best AI Hacker™, autonomously tests defenses at machine speed, safely uncovers and prioritizes exploitable attack paths, instantly verifies fixes, and drives a continuous hack, fix, verify loop. More than 7,000 organizations, including global defense agencies, Fortune 10 enterprises, multinational banks, and major healthcare providers, trust Horizon3 for security they can prove. Horizon3 was recently named the Fastest Growing Cybersecurity Company in North America by the Deloitte Technology Fast 500 and named one of the Most Innovative companies by Fast Company in 2026. Follow HORIZON3.ai on LinkedIn and X.
Horizon3.ai Media Contact
Stephen Gates
press@horizon3.ai
View source version on businesswire.com: https://www.businesswire.com/news/home/20260811692961/en/
Media gallery