'Defenders must keep pace with attacker scale'
How Offensys automates the cyber arms race: "We use AI to address one of its consequences: an accelerating threat landscape."
Published on October 17, 2026

Offensys
Bart, co-founder of Media52 and Professor of Journalism oversees IO+, events, and Laio. A journalist at heart, he keeps writing as many stories as possible.
Ahead of the AI Pitch Competition finals on 12 November at the Evoluon in Eindhoven, IO+ continues its deep-dive series profiling the eight finalists and one wildcard. In this fourth instalment, Cor Verhoeven, co-founder at Offensys, discusses why periodic penetration tests are obsolete, how AI can translate live threat intelligence into executable attack paths, and why autonomous security validation is vital for critical infrastructure.
The structural mathematics of cybersecurity have long favoured adversaries: an attacker only needs to find a single misconfiguration, while defenders must secure every perimeter. With generative models and autonomous agents accelerating the speed at which vulnerabilities are identified and weaponised, that asymmetry is widening rapidly. Relying on an annual penetration test or periodic manual red-teaming exercise is no longer sufficient when threats evolve by the hour.
Based at the Jheronimus Academy of Data Science (JADS) in 's-Hertogenbosch, Dutch cybersecurity startup Offensys is addressing this imbalance by moving security validation from occasional manual assessments to continuous, automated purple teaming. Below, co-founder Cor Verhoeven explains how their platform uses AI to simulate realistic attacks and why European data sovereignty is central to enterprise defence.
Translating threat intelligence into autonomous purple teaming
"Offensys is foremost a cybersecurity company," Verhoeven emphasises. "AI is an important layer in our platform and is helping us build the foundation for autonomous security validation."
Rather than treating AI as a marketing buzzword, the platform integrates it into practical defensive engineering: "Our platform automates threat-driven security validation and continuous purple teaming. It combines a large library of attack techniques and playbooks with knowledge of a customer's specific environment to simulate realistic attack paths and identify where defensive controls can be improved."
The next architectural leap moves beyond static playbooks toward autonomous execution: "We use AI to translate threat intelligence into executable security validation playbooks. The next step is an autonomous AI co-pilot within the platform that can select, prioritise, execute, and interpret the right simulations based on the customer's environment and current threats. This will significantly reduce the dependency on human operators for continuously validating security controls."
"The differentiation is therefore not simply 'using AI for cybersecurity,'" says Verhoeven, "but combining AI with a structured understanding of real-world attack techniques, defensive controls, and the customer's environment."
Scaling validation safely across diverse enterprise estates
Attackers benefit naturally from software scale—a zero-day or phishing sequence tested in one environment can be executed against thousands of enterprises in minutes. Defences must match that agility.
"The techniques used by attackers are inherently scalable," Verhoeven explains. "Our library of attack techniques and playbooks is designed to be applicable across different organisations, while the platform adapts the validation to each customer's specific environment. Once the relevant agents and infrastructure are in place, new attack simulations can be executed without requiring a large amount of manual effort from security teams."
However, executing simulated adversary operations inside production environments requires strict boundaries: "The main challenge is scaling safely and reliably across very different enterprise environments. Every organisation has a different infrastructure, security architecture, and risk profile. For AI specifically, the challenge is making AI useful without turning it into a black box. Security teams need to understand why a recommendation was made and remain in control of what is executed."
Explainability over black-box decision-making
In defensive operations, trust hinges on transparency. An automated agent that takes unpredictable actions on live IT networks poses unacceptable operational hazards.
"For us, explainability is non-negotiable," Verhoeven asserts. "Our goal is to make organisations better equipped to keep up with an accelerating threat landscape, while maintaining appropriate human oversight and control over how AI is used. If an AI system recommends a particular security validation scenario, it should be possible to understand the reasoning and the underlying evidence."
He views the offensive-defensive balance as an ethical imperative: "AI is already accelerating the threat landscape by making it easier to automate and scale parts of cyberattacks. We believe the defensive side needs to evolve at the same pace. We see AI not only as a technology that can create new risks, but also as an important tool to restore the balance between attackers and defenders."

Protecting critical infrastructure beyond checkbox compliance
The societal stakes of failing cyber resilience are growing, with vital societal services increasingly caught in the crosshairs. "Cyberattacks increasingly affect organisations that society depends on, from financial institutions to energy and other critical infrastructure," Verhoeven notes. "Improving the ability of organisations to continuously test and strengthen their defences can therefore have a broader societal impact. As the threat landscape accelerates, organisations need to move from periodically testing their defences towards continuously validating them."
He underscores that Offensys operates strictly within defined boundaries: "Our focus is on controlled security validation in authorised environments. We build the platform specifically for organisations to test their own infrastructure and improve their defensive capabilities."
Real-world enterprise validation before AI expansion
Commercialising deep cybersecurity technology requires resisting superficial trends.
"One of our biggest challenges has been turning a technically complex cybersecurity capability into a product that creates clear and measurable value for enterprise security teams," Verhoeven recalls. "We have addressed this by spending a significant amount of time with potential customers and security professionals, validating the problem, use cases, and product direction before scaling the company."
"We see enormous potential in AI, but we deliberately do not want to add AI simply because it is currently a major trend. We want to apply it where it genuinely improves the effectiveness of security teams: building a strong cybersecurity foundation first and then using AI to make security validation more intelligent, accessible, and scalable."
DORA and NIS2: Driving demand for continuous proof
As European regulatory frameworks like NIS2 and the Digital Operational Resilience Act (DORA) take full effect, enterprise security teams face strict legal requirements to prove operational resilience through structured testing. "Security is at the core of our platform. We don't build security validation simply to satisfy a regulatory checkbox; we build it to help organisations continuously understand whether their defences actually work," Verhoeven points out. "At the same time, we see regulation as an important driver for our customers."
"DORA, for example, requires financial entities to establish and maintain a comprehensive digital operational resilience testing programme and to identify and address weaknesses and gaps through testing," he explains. "We help organisations continuously validate their security controls against realistic threats and create evidence of what has been tested, what was found, and how weaknesses were addressed. This allows security teams not only to improve their cyber resilience, but also to demonstrate that they are actively managing and testing it."
On the data governance side, Offensys applies strict data segregation, dedicated customer environments, and local data storage, while monitoring compliance with the EU AI Act's risk management and human-oversight mandates.
The JADS ecosystem and the demand for European sovereignty
Operating out of JADS in 's-Hertogenbosch gives Offensys access to a vibrant academic and entrepreneurial intersection. "Being located at JADS is particularly valuable because we are building at the intersection of cybersecurity and AI," Verhoeven says. "Being surrounded by students, researchers, startups, and other technology companies creates opportunities to exchange knowledge, attract talent, and collaborate on new ideas."
Crucially, Verhoeven identifies European strategic autonomy as a major differentiator: "For Offensys, European data sovereignty is an important opportunity. We aim to become a key sovereign security validation solution for modern security teams—something that is still relatively rare in the cybersecurity market. Being able to offer customers strong control over where their data and infrastructure reside is increasingly important, particularly in regulated industries."
Levelling the playing field in the cyber arms race
Weighing in on the AI for Good versus AI for Disaster debate, Verhoeven sees the technology as a double-edged sword that demands defensive parity. "In cybersecurity, attackers are typically among the first to adopt new technologies because they directly benefit from automation and scale," Verhoeven explains. "AI is accelerating an arms race that has always existed between attackers and defenders, but it is accelerating it dramatically. Attackers can use AI to discover vulnerabilities, develop attack techniques, and scale their operations faster than ever. That makes it even more critical for defenders to adopt the same innovations."
"The traditional model of relying on human experts to periodically test an organisation's defences simply cannot keep up with the speed and scale of modern threats. AI can help shift security validation towards something continuous and increasingly autonomous: helping defenders stay ahead rather than constantly catching up."
Framing the challenge at the AI Pitch Competition
Looking toward the pitch showdown at the Evoluon on 12 November, Verhoeven argues that the ultimate criterion shouldn't be AI vanity metrics, but problem definition. "For us, the most important question behind this competition is not how much AI a company can put into its product, but what happens when AI changes the problem itself," Verhoeven concludes. "Cybersecurity is a clear example. We are already seeing AI systems discover vulnerabilities, exploit systems, and automate complex tasks quickly. The question is: who makes sure the defensive side can keep up?"
"We are not building AI for the sake of AI. We use AI to address one of its consequences: an accelerating threat landscape. That is the story we want to bring to the AI Pitch Competition."
Erasmus Enterprise, BOM, and IO+ organise the AI Pitch Competition, supported by the Province of North Brabant. The finals take place during AI Summit Brainport on 12 November at the Evoluon in Eindhoven.
