Innovaway participated in the SQF 2026. As an event sponsor and ISTQB® Platinum Partner, we shared our expertise in the field of AI-enhanced Quality Assurance.
On June 25, 2026, at the Software Quality Forum (SQF), Daniele Bartolomeo Vaudano illustrated Innovaway's vision on "Assisted Red Teaming," exploring in detail how Artificial Intelligence is revolutionizing Penetration Testing processes.
The Asymmetry of Modern Penetration Testing
Today's IT organizations face a deep asymmetry in cybersecurity. On one hand, attackers have virtually infinite time and leverage aggressive automation with the sole objective of identifying a single flaw in the system. On the other hand, defense teams must manage an extremely vast perimeter under stringent budget and time constraints, despite having the absolute necessity of ensuring total coverage. This disparity inevitably turns security testing into the primary bottleneck during software release phases.
Furthermore, relying exclusively on automated scanners (DAST) to speed up processes creates a false sense of security. The real problem is not a lack of detections, but a massive volume of uncontextualized alerts and errors that clog the systems. This phenomenon leads to so-called 'alert fatigue,' which translates into a massive waste of time for triage and drives Security Teams to burnout. The goal for IT decision-makers must therefore be to create a 'Cognitive Assistant' capable of filtering out this background noise, allowing human intuition to scale.
AI as an Operational Co-Pilot: Efficiency and Value
It is vital to understand that Artificial Intelligence is not a "magic button" capable of hacking systems autonomously; unguided use exposes organizations to the severe risk of hallucinations. Innovaway’s strategic approach is based on "Continuous Consultation"—a collaborative workflow where the analyst provides the AI with the architecture description, receives suggested test roadmaps as input, and precisely validates their effectiveness.
Adopting AI as a co-pilot delivers immediate returns across several areas:
Clear Reporting and Agentic AI: Toward Autonomous Testing
A Penetration Test completely loses its value if the reporting fails to provide clear and actionable information for rapid analysis and resolution by developers. AI supports this technical-to-layman translation by generating formal documentation from notes or dashboards, while also providing secure code snippets for guided and contextualized remediation. This system balances massive AI exploration with human lateral thinking.
Looking to the future, the industry is moving from purely reactive models toward Agentic AI, a paradigm shift that will lead to the autonomous delegation of execution. In our vision of a 'Virtual Test Factory', Multi-Agent architectures simulate distinct roles (Functional Analyst, Test Automation Engineer, Security Expert) to analyze documentation and begin testing based on the functional specifications before the code even exists, achieving a true 'shift-left'. To prevent unpredictable risks of autonomy (such as accidental damage or Scope Creep), we implement strict operational boundaries, Kill Switches, and 'Human-in-the-loop' controls.
Governance and New Skills
Introducing these technological accelerators without a solid methodological framework creates an exponential risk. The integration of ISTQB standards serves as a fundamental pillar: if AI is the tool to maximize efficiency, methodology is the guarantee for effectiveness and control.
In conclusion, the role of the QA Engineer is undergoing an evolutionary leap: by delegating 30% of repetitive operations to AI, professionals will invest 70% of their time in strategy, business logic analysis, and active risk prevention, transforming themselves from simple executors into true 'Quality Strategists.' The direction forward is clear: optimize time, democratize security, and future-proof corporate architectures.