More Than Humanly Possible: Why We Built A

Why cybersecurity needs a new operating model for the AI era

I spent nearly two decades in cybersecurity, six of them at Sygnia responding to breaches across roughly 40 countries and nearly every industry. You learn something specific from that work that you cannot learn anywhere else: you learn exactly how things break. Not in theory. In production, at 3 a.m., while a real adversary is still inside the environment.

So I want to be direct about why we built A, and why we are emerging from stealth now with $37 million from Lightspeed Venture Partners, Cyberstarts, and angel investors including Wiz CEO Assaf Rapaport and Cyera CEO Yotam Segev.

We built A because the entire defensive industry was built for a human adversary. That adversary is no longer human. Machine-driven attacks are easier, faster, and cheaper and almost everything shipped over the last decade assumes an operating model that no longer exists.

The moment everything changed

There was a specific moment when I realized most of what our industry had built was about to become obsolete, not just the tools, but the entire way we defend against a threat. It was when I watched attackers begin to use AI.

This is not an incremental improvement on the attacker side. It is a fundamental revolution of how attackers operate and how defenders need to respond. Frontier models can now find, chain, and exploit weaknesses across an environment at a pace that human teams relying on manual processes cannot match. The barrier to entry collapsed at the same time the ceiling rose.

Here is the part that should keep every security leader awake: capabilities once reserved for nation-state actors are now available to anyone with a laptop and access to a frontier model. That is not hyperbole, it is the new baseline. And it lands on top of years of accumulated vulnerability debt: the exposed paths, unvalidated fixes, and untested assumptions sitting in every environment. Attackers can now find and chain these issues faster than any human team can pay it down. Resilience in this era means confronting that vulnerability debt head-on, continuously, not once a quarter.

The evidence is already on the table. Anthropic's Mythos model autonomously surfaced thousands of previously unknown vulnerabilities across every major operating system and browser. Anthropic's own threat research has documented attackers orchestrating the full kill chain autonomously across all 14 MITRE ATT&CK tactics. The capability that used to be rare and expensive is now ambient and cheap. And this is only the first chapter of the book — the adversary's capabilities compound from here, and so must ours.

The old model was already dead

For years, we built security the same way: checklist-based, measured against frameworks assembled over time, hunting for vulnerabilities and misconfigurations one at a time. That approach rested on assumptions. Weaponized AI broke these.

The old vulnerability-management clock ran in months. A flaw was born, someone eventually found it, the vendor was notified, a CVE was issued, a patch shipped and then everyone raced to deploy it before it was too late. That entire lifecycle was measured in weeks and months. Today, the time for an attacker to find a weakness and generate a working exploit can be measured in hours. You were never going to out-patch that gap. Patching faster is not a strategy against an adversary that moves this fast; it is a treadmill.

Traditional prioritization ranks the criticality of each vulnerability or misconfiguration in isolation. But an isolated severity score tells you almost nothing about real risk, because attackers do not exploit issues one at a time, they chain them. Without the context of how weaknesses connect, you cannot understand what is actually critical in your environment. This is exactly what AI does well, and it gets better as its context grows. The unit of risk is no longer the individual vulnerability. It is the exploitable path.

Even in well-run organizations, the distance from finding to validated fix was always too long between triage, hand-offs between security, engineering, and QA, then someone remembering to re-test. That lag was survivable when the attacker also moved at human speed. Against an AI-driven adversary, it is an open door.

None of this is a failure of effort or talent. Security teams are doing the work. They have attack surface management, dynamic application testing, breach-and-attack simulation, manual pentests, bug bounties, posture tools, vulnerability scanners, vulnerability management, and manual remediation workflows tying it all together. They have spent millions. And they are still exposed because every one of those tools and services was built for a legacy adversary who is no longer relevant.

You cannot out-hire an asymmetry like this. You cannot out-process it. The structure of the work has to change.

What we built instead

A is a continuous offensive security and remediation platform built for the age of weaponized AI. It is not a better scanner. It is not just "AI pentesting", it's a new way of how we are building our defenses against weaponized-AI. Instead of a slow, noisy checklist based approach, we are transitioning to offense based security where the core is actual exploitability and fixing what matters.

A does what an AI-armed attacker would do to your environment, continuously and safely, and closes the gap before a real one can. Same reasoning. Same cross-vector chaining. Same speed. Run from your side of the table instead of theirs.

Concretely, A runs the full offensive lifecycle as one closed loop:

  • Find. Continuously discover what changed and where exposure lives across your environment.
  • Prove. Validate real exploitability with evidence, not a CVSS score, not a theoretical hotspot.
  • Chain. Build the cross-vector attack paths an adversary would actually use across your entire environment from web to AI from your network to your infrastructure.
  • Remediate. Drive fixes at the source and across compensating controls, with ticket-ready records.
  • Validate. Re-test until closure is proven, not assumed.

This matters most where the old model is blindest. AI-armed attackers increasingly find zero-days before researchers ever catalog them, which means waiting for a CVE is waiting too long. A reasons the way red teamers and pentesters do, probing for exploitable weaknesses in your environment before they are publicly known, so you are not defending only against yesterday's disclosed vulnerabilities.

Unlike periodic pentests and manual risk assessments that flag abstract risk hotspots, A continuously identifies cross-domain attack paths and validates exploitability, demonstrating how AI-enabled threat actors will chain weaknesses to exploit the business, then helping remediate before they do.

And it gets sharper every campaign. A holds opt-in persistent memory of your environment and your prior findings. Your attack surface is unique; your offensive security should be too.

Why the name is just "A"

People ask about the name. For me it represents going back to first principles, to the attacker's perspective, which is the root of what cybersecurity was always supposed to be.It also stands for the team we are building: the A team, the best of the best, the people I want in the room when the problem is this hard. And being first in the alphabet doesn't hurt either :)

Where we go from here

We are already working with large organizations across finance, healthcare, critical infrastructure, and technology, places where even a moment of failure is not an option, and where teams are under real pressure to validate and close attack paths faster than manual testing cycles allow.

We built A with a team that has spent its careers on the offensive side, veterans of Check Point, Hunters, Sygnia, and Unit 8200, precisely because this problem demands people who know exactly how things break. This is not a research project. It is a production platform, and we have the capital and the conviction to deliver on the roadmap ahead.

The board question has changed. It is no longer "did last quarter's pentest go fine?" It is "are we resilient against weaponized AI, right now?" Answering that on demand requires a different kind of capability than the one our industry built for the last era.

It requires being more than humanly possible. That is the bar adversaries already cleared. It is the bar we built A to meet and the reason we are just getting started.

Share this article
About the author
Yossi Torati is the co-founder and CEO of A, an offensive security and remediation platform that helps organizations defend against weaponized AI by discovering and remediating attack paths before adversaries can exploit them. Before founding A Security, Torati spent six years at Bynet and another six years at Sygnia, where he managed complex cyber incidents across nearly 40 countries and worked with major corporations and cryptocurrency exchanges facing high-stakes attacks.