How Strike measures offensive security results

Strike measures offensive security through continuous hybrid validation: AI-led agents execute attacks the moment your attack surface changes, and certified human pentesters validate every finding. This page defines each number we publish — how it is calculated, the period and scope it covers, and when it was last updated — so the results are verifiable, not marketing.
Our numbers, defined
We publish three headline figures. Here is exactly what each one measures, how we arrive at it, and the scope it covers — so you can weigh the evidence, not just the claim.
From a finding to a defensible dollar figure
Strike does not stop at a severity label. Every validated finding is priced with the FAIR/ALE model — an industry standard for risk quantification — anchored in public breach-cost benchmarks such as IBM's Cost of a Data Breach, not arbitrary numbers. No black boxes.
Correlated attack chains that end in the same data or system are consolidated — de-correlated — so exposure is never double-counted. Every figure is reported as a range (conservative / base / aggressive) and we lead with the base case, not the ceiling: a defensible number beats an inflated one. Monetary figures are modeled estimates based on public benchmarks and the scope tested — not a guarantee, accounting valuation or legal advice.
Continuous hybrid validation, step by step
Strike runs an always-on cycle instead of a once-a-year project. AI-led agents work at machine speed; certified human pentesters bring judgment, business-logic depth and proof of exploitability. Every result is evidence you can hand to an auditor.
Strike's testing aligns with recognized industry frameworks — including the OWASP Testing Guide and MASVS, PTES, the NIST SP 800-115 methodology and MITRE ATT&CK — used as reference standards. The same evidence supports SOC 2, ISO 27001 and PCI DSS programs: Strike supports these penetration-testing requirements and never certifies or guarantees compliance.
Questions about how we measure results
What does “risk mitigated” mean?
It is the aggregate expected annual loss of the vulnerabilities Strike found and helped customers remediate — quantified with the FAIR/ALE model and anchored in public breach-cost benchmarks, then consolidated so correlated chains are not double-counted. Strike reports it as a conservative floor: US$4.5B+.
How is 97% precision calculated?
Precision is the share of reported findings confirmed as real after certified-human validation. Because a human reproduces every issue before it reaches you, Strike keeps false positives under 3%.
What counts as a “critical” vulnerability?
The highest-impact tier — typically CVSS 9.0–10.0 — such as remote code execution, authentication bypass or sensitive-data exposure. Strike has reported 6,000+ of them across engagements to date.
Does AI replace the human pentester?
No. AI-led agents provide speed and breadth; certified pentesters provide judgment, business-logic depth and proof of exploitability. That combination is what keeps precision high.
Can these results support a SOC 2, ISO 27001 or PCI DSS audit?
Yes. Strike delivers continuous, audit-ready evidence that supports those programs. Strike supports the penetration-testing requirements; it does not certify or guarantee compliance — that is granted by accredited third parties.
Trusted by security teams that lead
Human expertise.
AI power.
Superior security.
Whether you’re scaling fast, closing enterprise deals, or just tired of noisy reports, we’ll help you build a security stack that moves faster than your threats.






