Black Hat USA 2025, held August 6–7 at Mandalay Bay in Las Vegas, gathered cybersecurity leaders from across the globe to exchange ideas, test assumptions, and explore the shifting nature of digital risk. Within the Startup Zone – the event’s early-stage technology showcase – Plainsea stood out with a pragmatic message: infrastructure is changing too fast for pentesting to remain a slow, one-off exercise.
The company’s presence tapped into a recurring theme across the conference: the widening gap between how often systems change, and how infrequently they’re tested. As organizations accelerate product releases, adopt new configurations, and introduce new infrastructure – often on a weekly basis – the need to validate those changes in shorter intervals is becoming a critical concern.
Plainsea’s continuous pentesting platform drew sustained interest from teams navigating that exact tension. Over two days of demos and discussions, the company highlighted how internal security teams – even those without deep pentesting experience – are increasingly looking for ways to keep pace without leaning entirely on managed providers.
A central moment came on the first day, with the session “Stop! You’re Doing It Wrong! Here’s How to Pentest Smarter,” delivered by CEO Marko Simeonov on the Startup City Theater stage. Framed around operational bottlenecks in traditional testing models, the talk paired critical commentary with a live demonstration of how pentesting can be embedded into day-to-day workflows without losing rigor.

“We’re not trying to replace experts – we’re just trying to make expertise more accessible,” Simeonov told the audience. “When systems evolve daily, testing has to evolve too. The question is no longer if you should test continuously – it’s how.”
That “how” – across conversations at the booth and on the stage – frequently came back to Plainsea’s focus on real-time guidance and delivery. Attendees showed particular interest in the company’s AI Companion, demoed publicly at the event. The Companion supports internal teams with contextual prompts, reporting assistance, and triage cues – addressing skill gaps without removing human control (with full automation envisioned as part of the company’s long-term roadmap).
This approach aligned with broader discussions at the event about augmenting teams under pressure. Whether driven by regulatory frameworks like PCI DSS and NIS2, or by the operational demands of agile development, many organizations now face expectations to validate change more frequently – without proportionally increasing their testing budgets or staff.

In that context, Plainsea’s appearance reflected a shift in how offensive security is being operationalized. Instead of positioning pentesting as an outsourced deliverable, the company is contributing to a growing model where testing becomes part of the internal security rhythm – triggered by changes, scheduled events, or manual requests, depending on team maturity.
The platform’s ability to support different testing cadences and resource models – without requiring full-time pentesters – quietly echoed a larger industry question: as environments grow more complex, who exactly is responsible for ensuring they remain secure?
Plainsea didn’t claim to have all the answers. But at Black Hat USA 2025, its presence helped frame one possible path forward – one rooted not in disruption, but in design choices that meet real operational needs.
