Humans in the loop

Automation does the miles. Humans make the calls.

Incenter automates relentlessly. But a machine can’t judge which risk matters most to your business, know when it’s making something up, or safely test a system that must never go down. That’s where our operators come in. Here’s exactly why, and where.

The model

The loop that makes the engine smarter.

Every engagement makes the engine smarter. That’s the whole model, and here’s how it runs.

Operators generate tradecraft: the chained flaw, the careful OT test, the attack no signature covers. That tradecraft is encoded into the engine as new automated tests, and the engine scales it to every customer, continuously, at a pace no team could match.

It runs the other way too. The engine’s findings sharpen the operators: it does the miles, and hands them the cases that genuinely take a human, the judgment calls and the systems that must not be touched.

It’s the same loop whichever cadence you run: always-on across whatever you put in scope, or a single point-in-time run as PTaaS.

Brings in an operatorEvery manual break → a new automated testAUTOMATIONContinuous · at scale · every surfaceruns 24/7, never tiresOPERATORSJudgment · creativity · carethink like the attacker

Runs autonomously today

  • Discovery across your external attack surface, continuously
  • Exploit validation of known vulnerability classes
  • Re-testing every fix, automatically
  • Catching drift between changes: new hosts, expired controls
  • Routing proven findings to their owners, evidence attached

Operator-led, by design

  • Business-context judgment: which proven risk hurts you most
  • OT, ICS and anything that must never go down: operator-led, reversible
  • Novel attack chains and business-logic abuse
  • Verifying AI output against ground truth
  • Social and physical engagements

The split moves in one direction: what an operator cracks becomes an automated test, so the autonomous share grows. It never reaches everything, and we don’t claim it will.

Where operators come in

Four things that take a human.

Judgment

Know which risk actually matters

Incenter proves what’s exploitable, not just what a scanner would flag. But which of those proven findings would hurt you most (the system, the data, the deadline that matters) is a judgment only someone who knows your business can make.

So a human does it. An operator sets the business context, so the platform scores risk against the systems you really run.

AI hallucination

Know it isn’t making things up

AI-assisted tools are confident and wrong. They invent findings that read as real and miss ones that are. A model can’t tell the difference: it has no ground truth.

So a human does it. Operators keep watch, so no fabricated finding slips through, and the platform proves each real one by exploiting it for real.

Systems you must not break

Test what it can’t be let loose on

On operational tech (power, water, production lines, medical) an automated exploit could halt a plant or put people at risk. You would never turn a bot loose in there.

So a human does it. An operator leads it personally: reversible steps, inside strict rules of engagement.

Creativity

Invent an attack no one has seen

Tools match known patterns. Real attackers chain small, individually-boring flaws into a breach, and abuse business logic no signature covers. That takes an adversary’s imagination.

So a human does it. Operators think like the attacker and find the paths automation won’t invent on its own.

The clearest case: OT & ICS

Some systems you never turn a robot loose on.

On operational technology, a “successful” automated exploit isn’t a green checkmark. It’s a stopped production line, a tripped safety system, or worse. The blast radius is physical. So here, automation doesn’t just fall short. You actively don’t want it acting on its own.

How an operator does it instead: an operator leading personally, one careful step at a time, every action reversible and pre-agreed in the rules of engagement, proving the risk is real without ever tripping the thing that keeps the lights on.

SafetyPeople on the plant floor
UptimeOne outage, thousands hit
PhysicalValves, turbines, current

This is the rule, not the exception. Every Incenter run — OT or not — is scoped to what you approve and change-controlled, so it tests live systems without disrupting them.

How this changes over time

The split between automated and operator-led work isn’t fixed. When an operator finds something, we build it into the platform as an automated test, so the automated share grows over time. The work that stays with people is the work on this page: judgment, systems that must not break, and attacks with no known pattern.

See where we’re going →