Ridge Security Named IDC Innovator for Agentic Autonomous Penetration Testing
Ridge Security today announced that it has been named an IDC Innovator in the IDC Innovators: Autonomous Penetration Testing for DevSecOps, 2026 (doc # US54175326, July 2026) report.
As modern applications become increasingly distributed, API-driven, cloud-native, and frequently updated, security teams face a fundamental challenge: traditional penetration testing cannot always keep pace with the speed of modern software development. While periodic assessments remain valuable, they often leave organizations with gaps between testing cycles or generate large volumes of findings without proving whether vulnerabilities can actually be exploited.
Also Read: Infrastructure as Code Governance: Managing Risk in Enterprise Cloud Environments
Agentic autonomous penetration testing addresses this challenge by enabling AI agents to reason, plan, and adapt throughout an assessment. Rather than executing a predefined sequence of tests, agentic systems establish objectives, formulate hypotheses, validate attack paths, and continuously adjust their strategy as new evidence emerges.
Ridge Security’s RidgeGen applies this through a stateful, multi-agent architecture designed to preserve context through an assessment. As agents uncover new information about an application or environment, the platform adapts its testing strategy, pursues deeper attack paths, and validates how multiple weaknesses can be chained into meaningful exploits.
“Agentic AI changes the equation for penetration testing because the technology is no longer limited to executing a fixed catalog,” said Lydia Zhang, President and Co-Founder of Ridge Security. “RidgeGen is designed to reason beyond CVE-based detection. It understands business logic, application workflows, and attack paths to uncover risks that traditional automated tools often miss, significantly reducing false negatives.”
Also Read: Infrastructure as Code vs Configuration Management: What’s the Difference?
The Agentic Advantage – RidgeGen
- Agentic reasoning that enables autonomous decision-making throughout penetration testing
- Stateful, context-aware testing that preserves knowledge gathered during an assessment
- Multi-agent orchestration for discovering, validating, and chaining exploitable risks
- Adaptive testing that changes strategy based on application behavior and newly discovered evidence
- Autonomous exploit validation that distinguishes confirmed exploitable risk from theoretical findings
- Customer-defined objectives, testing boundaries, AI models, and agents for governance and flexibility
The IDC Innovators report profiles seven vendors operating in autonomous penetration testing for DevSecOps.
Unlike traditional automated testing, which executes predefined security checks, agentic systems continuously reason about the environment, determine which attack paths to pursue, and adjust based on what they learn.
“Running more security tests isn’t enough,” said Nick Mo, CEO and Co-Founder of Ridge Security. “The real challenge is understanding what each discovery means and deciding what to investigate next. RidgeGen’s stateful, multi-agent architecture continuously builds on what it learns, making autonomous penetration testing more intelligent, targeted, and effective.”
Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.