01 Sep 2026 · 4 min read

Artificial intelligence has prompted a question our industry should have asked long ago: what is the moat in pentesting?

For years, my answer was simple: hire the best hackers and customers will come. That answer is not wrong. Technical competence is necessary. Poor work destroys a consultancy's reputation, while technical excellence attracts talent and builds trust. But it may not be enough.

Imagine two consultancies bidding for a penetration test at a regional healthcare provider. The first employs elite researchers with impressive discoveries and conference credentials. The second is less prestigious, but its consultants understand healthcare environments, regulatory constraints, common authentication systems and which recommendations the customer can realistically implement.

Either might win, and either might produce the better test. But they will be different tests. In my experience, the elite team may find technically impressive vulnerabilities that the customer neither cares about nor knows how to fix. By contrast, the second consultancy may deliver simpler but more actionable findings that materially improve the customer's security baseline.

Customers rarely buy "the best pentesters" in the abstract. They buy the people they believe are best suited to their problems. That is the real distinction.

The moat is not simply technical ability. It is the ability to match the right expertise to the right customer and repeatedly deliver findings and advice that fit their environment, maturity and objectives. Over time, this creates valuable knowledge: which problems recur, which recommendations work and where security improvements get stuck.

But customer knowledge lives largely in consultants' heads, while customer trust often attaches to individual relationships. Both can walk out the door.

Founder-led boutiques can conceal this fragility. Founders know every tester, review the work, assign engagements and maintain customer relationships personally. That model becomes harder to sustain as the company grows. Hiring thirty testers is not the same as creating a thirty-person technical culture. Revenue can scale faster than judgement, mentorship and quality control.

The challenge is to preserve what makes exceptional consultants valuable without reducing them to interchangeable operators. Too little structure leaves the business dependent on individuals. Too much suppresses the autonomy and judgement customers are paying for.

AI makes this balance even more important. As vulnerability discovery becomes more automated, findings may become increasingly similar across consultancies. The differentiator will be the accumulated understanding of each customer's architecture, constraints and appetite for change. AI may help capture that context and increase the leverage of exceptional testers, but it cannot create the culture or judgement on its own.

Technical excellence attracts talent. Customer context makes that talent useful. Culture and operating systems allow both to compound.

The moat has always been institutional judgement: knowing which people to put on which problems, understanding what matters to each customer and ensuring that what the organisation learns survives when any individual consultant leaves. AI does not change that answer. By commoditising the findings, it only makes the moat matter more.

Want to build these skills hands-on?

PentesterLab has 700+ real-world labs on web hacking, code review, and vulnerability analysis. Start with a free account.

Photo of Louis Nyffenegger
Louis Nyffenegger
Founder and CEO @PentesterLab