AI 9 July 2026 5 min read I Was Asked to Consult a Consultancy on AI Cyber Strategy. Here’s What They Got Wrong. By Old Forge Technologies 89 reads Contents I was recently approached by a top-tier expert network. Their client - a major management consultancy - was conducting a study on the future of penetration testing, market demand dynamics, and the structural impact of AI on cybersecurity. They wanted an hour of my time to map out the future of the industry. Naturally, I prepared. I pulled together notes on the economics of the SMB market, the regulatory lag of the EU AI Act, and how AI is about to structurally disrupt managed service providers (MSPs). I jumped on the Zoom call, delivered my opening frame as a technologist and strategist rather than a hands-on operator, and… the call ended 60 seconds later. It turns out, despite their sweeping macro-economic agenda, what the consultancy *actually* wanted was to watch a penetration tester run Kali Linux payloads and talk about specific exploit chains. They had fundamentally misaligned their own brief; asking for a strategist, but looking for an operator. But I’m not one to let good research go to waste. So, for the management consultants who missed out, and for everyone else navigating the rapidly shifting cybersecurity landscape, here are the structural market shifts you *should* be paying attention to. ### 1. Demand Evolution: The Death of the "Point-in-Time" Pentest The clearest structural shift in the market right now is the move away from thinking of a pentest as a single point-in-time event, and toward treating it as an ongoing, continuous process. This evolution from human-led, periodic testing to AI-led, continuous testing is not evenly distributed: * **Regulated enterprises** (finance, healthcare, critical infrastructure) are moving fastest toward continuous testing, largely because regulations like DORA are pulling them there. * **Large tech-native companies** are adopting continuous, AI-assisted testing because their rapid release cadences demand it. * **Mid-market and SMBs** are the segment where the "periodic" model is still dominant (testing once a year). This lagging adoption in the SMB space creates a massive gap in readiness, which brings us to the next structural issue. ### 2. The SMB Market is a "Nested" Liability Bomb When we talk about cyber risk, the enterprise space is just the tip of the iceberg. Over 99% of businesses in the US, UK, and EU are SMBs. They suffer nearly half of all cyberattacks, but the vast majority lack the budget to buy direct from premium security vendors. Because of this, SMB security is currently a *financial* choice, not a *quality* choice. SMBs rely entirely on outsourced IT via Managed Service Providers (MSPs). Those MSPs often lack in-house security expertise, so they white-label services from a Managed Security Service Provider (MSSP), who might be licensing a tool from yet another vendor. This creates a nested supply chain of liability that is completely unregulated. Frameworks like Cyber Essentials are great prerequisites, but they do absolutely nothing to regulate downstream "white-labeling." As we saw with the Kaseya and SolarWinds breaches, hackers no longer need to attack 1,000 SMBs individually. They just need to breach one "whale" (an MSP or RMM provider) to gain highly privileged, downstream access to crypto-lock thousands of businesses at once. The legislation is moving at a snail's pace compared to the breakneck speed of these supply-chain threats. ### 3. AI is the Ultimate "Middleman Killer" Everyone focuses on how AI helps hackers write malware faster, or helps defenders analyze logs quicker. But AI’s biggest impact on the cybersecurity market will be structural disruption: it is going to cut out the middlemen. Right now, a standard MSP has to outsource security to a Managed SOC (Security Operations Center) simply because they cannot afford the human capital required to filter the sheer volume of alert noise. AI changes the economics of this entirely. AI models are exceptionally good at ingesting and triaging massive data volumes. By replacing the entry-level Managed SOC, AI will give standard MSPs the capability to offer enterprise-grade security directly, capturing higher margins. Alternatively, by drastically lowering the cost of capability, AI-powered security solutions might soon allow SMBs to bypass MSPs entirely and manage their own adaptive security posture. ### 4. The "Botnet with a Brain" and the Regulatory Blind Spot Historically, we catch botnets because they are "dumb." They have to constantly phone home to a Command and Control (C2) server for instructions. That creates network noise, which defenders can detect. That era is ending. With open-weights models (like Llama) now small enough to run locally, a compromised endpoint can carry its own autonomous reasoning engine. A "botnet with a brain" doesn't need to phone home. It can analyze the local environment, decide what to encrypt, and read the infected user's Slack messages to generate hyper-contextualized internal spear-phishing messages to spread laterally; all completely in the dark. This breaks the traditional C2 detection model. Worse, it’s a massive regulatory blind spot. Frameworks like the EU AI Act are built for the "Model-as-a-Service" era, assuming there is a corporate provider hosting an API that can be audited or regulated. You cannot regulate or audit a malicious, jailbroken fork of an open-source model running as malware directly on a compromised laptop. The compliance frameworks being debated today literally have no mechanism to govern this frontier. ### The Takeaway The future of cybersecurity isn't just about faster exploits; it's about shifting economics, unregulated supply chains, and autonomous threats that break our existing detection models. If you want to talk about packet injections, hire a pentester. I am happy to assist with the project and vet you the right team. But if you want to talk about how these structural shifts are going to disrupt your market over the next three years, let’s talk.