International Cyber Expo 2025 (Sept. 30–Oct. 1, Olympia London) again proved why it sits on the short list of must-attend security fixtures: decision-makers, practitioners, and public-sector stakeholders met to discuss and test solutions that aim to improve the resilience of businesses and critical infrastructures. Amid that wider agenda, Plainsea’s contribution was deliberately pointed – make pentesting move at the pace systems change.

The case was made most sharply on Oct. 1, when CSO Boris Goncharov took the Tech Hub Stage for “Quit Staring Into the Abyss of Traditional Pentesting.” Instead of treating common pitfalls as abstractions, he gave them faces: a gallery of “Abyss Entities” that personify traps teams recognize all too well – checklist comfort that lulls leaders, script-driven motion that mimics mastery, noise-heavy bug lists that hide attack paths, unseen surfaces that never get tested, delays that let risk linger, and paperwork mistaken for protection.

“In the abyss, there is no security,” Boris said, as phones went up across the room; slide after slide was photographed, and the feedback afterward was unambiguous: the lens rang true because it mapped to day-to-day reality.

IMG_20251001_171908.jpg

Post-session, the discussion turned immediately to execution: how to wire tests to deployments and configuration changes without overwhelming teams; how to keep humans in control while using AI for prioritization and reporting; and how to maintain clear records of what was tested and when – so progress is visible in the work, not just on paper. Many attendees sought deeper follow-ups at the stand, pressing on integration points, change-driven triggers, and how to shorten the path from finding to fix.

IMG_20250930_170934 (1).jpg

Plainsea’s suggested approach was less a product pitch than a shift in operating model. Rather than an outsourced, point-in-time exercise, the company argued that pentesting should become part of the security rhythm – responsive when systems evolve and predictable where oversight requires cadence. Measured not by report volume, but by how quickly meaningful risk is found, understood, and addressed.

Which raises the larger question: what happens when the Abyss Entities move from metaphor to mandate – when the lullabies, mirages and shadows that surfaced in London become the constraints teams design against? If the industry can name its demons, can it choreograph them –turn panic into pace, doubt into decision? The next step may not be to banish the abyss, but to light it so thoroughly that nothing meaningful can hide there.

Plainsea Recasts Pentesting for a Continuous Era at ICE 2025