Topic: Implement Agentic AI Pentesting While Managing Risk & Cost
Abstract: Agentic AI is beginning to change how penetration testing is conducted. It can improve testing speed, depth, and coverage, but it also introduces new questions around safety, control, governance, and cost. This session will focus on key practical insights for CISOs evaluating or implementing AI-driven penetration testing.
Key Takeaways:
- What agentic AI is and how it differs from traditional security automation
- How to evaluate agentic AI platforms, capabilities, and vendors
- How to implement AI pentest agents within an enterprise environment
- Key risks, including excessive permissions, unintended actions, data exposure, and lack of oversight
- Safety guardrails, governance, and human-in-the-loop controls
- Managing token usage, infrastructure costs, and overall ROI
Speaker:
Arnab Chattopadhayay, Co-founder & VP of Emerging Research, FireCompass
Bio: Arnab Chattopadhayay is Co-Founder of FireCompass, with over 23 years of experience in leadership roles across IT security at large global organizations, including British Telecom, Tech Mahindra, iViZ (part of Synopsys), MetricStream, Capgemini, and IBM. His expertise lies in providing solutions to complex problems in the area of IT security.
Arnab was one of the key members who worked on BT21CN, one of the largest transformation projects in the telecom world, aimed at the complete transformation of British Telecom’s network to a Next Generation Network (NGN).




