Siemba, an offensive security provider, said it was named a Sample Vendor for Penetration Testing as a Service in three 2026 Gartner Hype Cycle reports: security operations, application security and XaaS. The company said the 2026 listings mark its third consecutive year in all three reports, following three reports in 2025 and three in 2024.
Siemba said the security operations report examines technologies and services that support the operational defense of digital assets, including the continued growth of Continuous Threat Exposure Management as a priority for security teams. The application security report looks at how AI transformation, agentic applications and shifting DevSecOps practices are reshaping enterprise application risk. The XaaS report covers how everything as a service is redefining IT as a utility and a platform-driven consumption model, according to the company.
The company said all three reports profile PTaaS as delivering automated and human-led testing through a software-as-a-service platform, covering point-in-time, continuous and change-driven assessments and increasingly incorporating external attack surface discovery. Siemba said the research notes that PTaaS supports Continuous Threat Exposure Management through dynamic scoping, adaptive retesting and faster mobilization of results, and that it enables continuous or change-based validation earlier in the software development life cycle.
Kannan Udayarajan, the company's founder and chief executive, said the third consecutive listing reflected what he described as growing enterprise conviction that continuous, platform-driven offensive security is a strategic imperative. AI-assisted development is expanding the attack surface faster than annual testing cycles can cover, he said.
Siemba said its platform brings together External Attack Surface Mapping, AI-native dynamic application security testing, automated vulnerability assessments and expert-led penetration testing, with coverage of AI attack surfaces including MCP servers, agentic AI workflows and LLM applications. Fixes are retested automatically, with sign-off from certified engineers and audit-ready certificates issued through Verified Closure, the company said. Siemba said the reports can be downloaded from its site. Gartner states in the release that it does not endorse any company, vendor, product or service depicted in its publications.