Episode Summary:
In this Anchors Away episode of the AnchorPoint podcast, Host Joe Munsayac sits down with Michel Chamberland, Founder and CEO of IntegSec, to trace his journey from self‑taught software engineer to leading offensive security teams at SpiderLabs and IBM X‑Force Red—and now building a new model for agentic penetration testing.
The discussion dives into how pen testing has evolved from annual, compliance‑driven PCI/SOC 2 exercises to a world where GenAI lets a single developer ship hundreds of thousands of lines of code in weeks, dramatically increasing bug density and forcing security teams to move from once‑a‑year tests to shorter, deeper, more frequent assessments.
Joe and Michel unpack the rise of agentic pen testing—using AI agents and MCP‑style tooling to chain findings, expand coverage, and generate richer reports—while keeping a human expert in the loop to drive creativity, authorization testing, and real‑world risk validation for everything from small SaaS startups to large enterprises.
They also explore the realities of onshore vs offshore pen test talent, why scoping is still one of the most misunderstood parts of a pen test, how AI can now analyze codebases (lines of code, complexity, routes) to inform better scoping.
Michel closes by arguing that the future of pentesting is an arms race where attackers and defenders both use AI, and the winning teams will blend expert human creativity with agentic automation to continuously probe rapidly growing, AI‑generated codebases—without burning out testers or breaking security budgets.
Key Takeaways:
Great pen testers blend creativity, history, and hands‑on learning—bug bounties, CTFs, and real‑world hacking still matter more than check‑box credentials alone.
Annual, compliance‑driven pen tests are becoming obsolete as GenAI explodes code volume, bug density, and release cadence, demanding more frequent, targeted testing.
Agentic pen testing (AI agents + human experts) can already outperform many legacy big‑firm tests, delivering deeper chains of findings, richer reports, and better coverage for both startups and enterprises.
IoT and legacy web apps remain soft targets—from smart pool controllers to abandoned pharma websites—where a single bug (like SQL injection) can still escalate to full enterprise compromise.
Connect, Follow, Learn …
Michel Chamberland
https://www.linkedin.com/in/michelchamberland
IntegSec
https://integsec.com
AnchorPoint Partners
https://www.anchorpointpartners.io/
Host (Joe Munsayac)
https://www.linkedin.com/in/joe-munsayac-120a09103/