How Strike measures offensive security results

Strike measures offensive security through continuous hybrid validation: AI-led agents execute attacks the moment your attack surface changes, and certified human pentesters validate every finding. This page defines each number we publish — how it is calculated, the period and scope it covers, and when it was last updated — so the results are verifiable, not marketing.

[ METHODOLOGY & EVIDENCE ]

Our numbers, defined

We publish three headline figures. Here is exactly what each one measures, how we arrive at it, and the scope it covers — so you can weigh the evidence, not just the claim.

US$4.5B+
in risk mitigated
What it means
The aggregate estimated financial exposure of the vulnerabilities Strike has found and helped remediate — the potential cost of the breaches those issues could have enabled had they stayed open.
How we arrive at it
Each validated finding is mapped to an estimated impact from the asset it affects and the class of compromise it enables; the figure sums that exposure across issues customers remediated. It is a conservative floor, shown as “4.5B+”.
Scope
Aggregate across Strike engagements to date, reported in USD. Last reviewed July 2026.
97%
precision · under 3% false positives
What it means
Precision is the share of the vulnerabilities Strike reports to a customer that are confirmed as real, exploitable findings — not noise. The inverse, under 3%, is our false-positive rate.
How we arrive at it
Every issue surfaced by AI-led testing is reviewed and reproduced by a certified pentester before it reaches you. Precision is validated-true findings divided by total reported findings.
Scope
Measured across validated Strike engagements to date. Last reviewed July 2026.
6,000+
critical vulnerabilities reported
What it means
The cumulative count of critical-severity vulnerabilities Strike has reported to customers — the highest-impact issues, such as remote code execution, authentication bypass or sensitive-data exposure.
How we arrive at it
Severity is assigned during human validation. “Critical” is the top tier, typically CVSS 9.0–10.0, counted once per distinct confirmed finding.
Scope
Cumulative across Strike engagements to date. Last reviewed July 2026.
[ HOW WE QUANTIFY IMPACT ]

From a finding to a defensible dollar figure

Strike does not stop at a severity label. Every validated finding is priced with the FAIR/ALE model — an industry standard for risk quantification — anchored in public breach-cost benchmarks such as IBM's Cost of a Data Breach, not arbitrary numbers. No black boxes.

SLE
Single Loss Expectancy
What one exploitation would cost, combining up to five impact components: data breach (records × cost per record), regulatory exposure, operational interruption, fraud and integrity, and reputation or churn.
ARO
Annualized Rate of Occurrence
The probability the issue is exploited within 12 months, calibrated by CVSS severity and by exploitability — whether it is pre-authentication, chainable, evades existing controls, and how attractive the target is.
ALE = SLE × ARO
Annual Loss Expectancy
The expected annual loss per finding — the honest basis for both risk and ROI. It is what turns “critical” from a label into a number a CFO can act on.

Correlated attack chains that end in the same data or system are consolidated — de-correlated — so exposure is never double-counted. Every figure is reported as a range (conservative / base / aggressive) and we lead with the base case, not the ceiling: a defensible number beats an inflated one. Monetary figures are modeled estimates based on public benchmarks and the scope tested — not a guarantee, accounting valuation or legal advice.

[ HOW WE TEST ]

Continuous hybrid validation, step by step

Strike runs an always-on cycle instead of a once-a-year project. AI-led agents work at machine speed; certified human pentesters bring judgment, business-logic depth and proof of exploitability. Every result is evidence you can hand to an auditor.

01
Recon & attack-surface mapping
We continuously discover assets, services and changes — the surface an attacker would see — so nothing new goes untested.
02
AI-led attack simulation
Autonomous agents emulate real attacker techniques across web, mobile, API and cloud, at a speed and scale manual testing cannot match.
03
Human validation
Certified pentesters reproduce and confirm every finding, chain business-logic flaws, and discard false positives before anything reaches you.
04
Reporting with evidence
Each confirmed issue ships with severity, reproduction steps and remediation guidance — audit-ready documentation, not a scanner dump.
05
Retest & continuous coverage
Fixes are retested to confirm closure, and testing keeps running as your attack surface changes — shrinking the window between exposure and detection.

Strike's testing aligns with recognized industry frameworks — including the OWASP Testing Guide and MASVS, PTES, the NIST SP 800-115 methodology and MITRE ATT&CK — used as reference standards. The same evidence supports SOC 2, ISO 27001 and PCI DSS programs: Strike supports these penetration-testing requirements and never certifies or guarantees compliance.

[ FAQ ]

Questions about how we measure results

What does “risk mitigated” mean?

It is the aggregate expected annual loss of the vulnerabilities Strike found and helped customers remediate — quantified with the FAIR/ALE model and anchored in public breach-cost benchmarks, then consolidated so correlated chains are not double-counted. Strike reports it as a conservative floor: US$4.5B+.

How is 97% precision calculated?

Precision is the share of reported findings confirmed as real after certified-human validation. Because a human reproduces every issue before it reaches you, Strike keeps false positives under 3%.

What counts as a “critical” vulnerability?

The highest-impact tier — typically CVSS 9.0–10.0 — such as remote code execution, authentication bypass or sensitive-data exposure. Strike has reported 6,000+ of them across engagements to date.

Does AI replace the human pentester?

No. AI-led agents provide speed and breadth; certified pentesters provide judgment, business-logic depth and proof of exploitability. That combination is what keeps precision high.

Can these results support a SOC 2, ISO 27001 or PCI DSS audit?

Yes. Strike delivers continuous, audit-ready evidence that supports those programs. Strike supports the penetration-testing requirements; it does not certify or guarantee compliance — that is granted by accredited third parties.

Boost your experience with Hybrid Testing Booster

Continuous Hybrid Testing

Emulated, deep stealth-based attacks executed by creative, unconventional security experts. Find out how real attackers would breach your systems, and stop them before they do.

Testimonial

Trusted by security teams that lead

"Product was great! The team was exceptional when addressing our sense of urgency with regards to an important timeline, and they were able to deliver effectively and finding important vulnerabilities within our systems."

Gartner 4
Gartner review, Head of Engineering, Banking

"Good option for agile testing, especially if GTM timelines are tight. This is especially important when the release train comes with a lot of new products and releases, making it hard to keep the pace in a traditional ad-hoc business model."

Gartner 3
Gartner review, Product Security Leader Cybersecurity, Hardware

“Strike provides continuous pentesting for our critical web and mobile features. Each month they help us validate new functionalities in production, delivering relevant vulnerabilities and strong value for money. We are very satisfied with their innovative and customer-centric approach.”

Gartner 2
Gartner review, Chief Information Security Officer, Retail

"Strike team was fast and provided the exact solution we needed for our use case. We decided to go for Strike because they provide a pen-testing suite that fits the way we work in terms of speed and communication. Highly recommended!"

Gartner review
Gartner 1
Gartner Review, Chief Technical Officer, Banking

"We greatly value our partnership with Strike. Their exceptional penetration testing services and effective communication have significantly enhanced our cybersecurity, ensuring the safety and trust of our customers' financial information."

Ozan Özgür Özyüksel
Information Security Officer, Plum

"The management of communication channels and the centralization of interactions with the team made the experience much more agile and effective. Having everything in one place was a huge advantage and allowed us to complete the pentest within just a few weeks."

Miguel Langone
CTO at Horizon

“Working with Strike is extremely important to us, especially because they deliver quality work over our products in a continuous way, and provide constant follow-up when it comes to managing the already found vulnerabilities. Moreover, they are constantly making improvements in their SaaS platform so we can have the best experience possible. In case we have a problem, they listen and help us. That’s invaluable.”

Ileana Barrionuevo
Sr AppSec Red Team, NaranjaX

“Working with Strike was an excellent experience for us. We were able to create our own pentests and change their scope each month. The Strikers are world-class professionals who provide us with relevant findings quickly and efficiently. Also, automated tools like Phishing Monitor are really interesting for our company, because they help us spot fake domains trying to impersonate PedidosYa.”

Eduardo Gimenez
CISO, Pedidos Ya

“For us at pier, security is the most important aspect, not only on the surface but throughout our entire product. When we reached out to Strike, we were looking for someone that could test & find vulnerabilities across our entire stack. We are very happy that we have found the right partner to achieve that, and we are looking forward to continuing this important work together.”

Andras Hejj
CEO & CTO, Pier

Human expertise.
AI power.
Superior security.

Whether you’re scaling fast, closing enterprise deals, or just tired of noisy reports, we’ll help you build a security stack that moves faster than your threats.

Book a Demo