# FSE Pentest Agent

> Security as a permanent state

- **Year:** 2026
- **URL:** https://fse-group.de/en/unsere-arbeit/fse-pentest-agent

With its own penetration test agent, FSE created a solution that checks applications for vulnerabilities automatically and continuously – daily instead of twice a year. The result: 85% time saved, better response times and more security in operations.

Security is no longer an add-on. With NIS2 it becomes a strategic obligation – especially for companies close to critical infrastructure like FSE. At the same time requirements grow while resources stay limited. Classic measures such as half-yearly penetration tests are no longer enough.

Our answer: the FSE Pentest Agent – a solution that works automatically, continuously and independently. Today applications are tested for vulnerabilities weekly – not occasionally but permanently.

The agent identifies risks, prioritises them and delivers concrete recommended actions. The results are structured, traceable and immediately usable – without manual review cycles, without extra burden.

The effect: 85% time saved on our side, a drastically higher test frequency, noticeably faster responses to new risks.

The agent is not a response to customer requirements but an expression of our own security standards. Built in-house, integrated into existing systems, secured to the strictest standards.

### System landscape & integrations

  Security layer

  Oversight

  Pentest
  Agent
  continuous scanning

  Value
  Permanent detection
  instead of 1&#215; per year
  Vulnerabilities visible immediately

  LLMs
  AI-assisted analysis

  Monitoring
  DataDog

  Chaos Monkey
  Destructive actions

  Trigger
  PRs, MRs, Jira

  Code base
  GitLab, GitHub

  Human
  Supervisor
  Approval & oversight

### FSE Pentest Agent – live demo

Simulation: the Pentest Agent scans app.fse-group.de and finds an SQL injection in the /api/search endpoint (CVSS 9.8). It retrieves the source code from GitLab, tasks the backend dev agent with implementing a prepared statement and automatically creates a merge request (!1147). The QA agent runs regression tests (all 23 passed). The Pentest Agent then verifies that the original attack path no longer works.

It shows that security is not a cost factor when you think about it systemically – for our customers a noticeable gain in trust and a reliable basis for further development.

**Tags:** #AIinSecurity #ContinuousTesting #CyberSecurity #NIS2Compliance #Pentesting
