RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail
The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers’ increasingly advanced capabilities.
The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers’ increasingly advanced capabilities.
Chris Thompson made a career breaking into banks, nuclear power plants, and defense contractors—and getting paid to do it. Now, he recognizes that red team penetration testing is evolving dramatically.
This premise is the basis of RemoteThreat, an integrated offensive cyber operations platform he and Shawn Jones, co-founder and CTO, founded in 2025. The startup just emerged from stealth with $7 million in pre-seed funding and aims to help organizations stay ahead of attackers who are picking up the pace, largely due to artificial intelligence (AI).
Rather than replacing humans, the platform uses AI to assist teams in enterprises, as well as government organizations, during mission objectives while testing how their defenses will hold up against a variety of threats.
Frontier AI models are advancing so rapidly that traditional penetration testing won’t exist in two years as it stands today, explains Thompson, RemoteThreat CEO and co-founder.
Traditionally, a few senior testers manage teams of 20 junior analysts who conduct one- to three-week assessments, but that model is breaking down. Organizations won’t pay for three-week engagements anymore, and Thompson predicts the same change will soon hit even high-end red teaming work, as economic pressures increase.
“Pen testing is going to be a commodity market; it’s going to be done at scale,” Thompson tells Dark Reading.
Preparing For the Frontier AI Future
During his 20-year cybersecurity career, Thompson saw big banks pay $400,000 over a three-month period for pen testing services. But, at the end of the day, executives would request access to the team’s tooling and methodology.
The platform is built to allow organizations to do just that and ultimately leverage AI to take advantage of that as well. Thompson is betting that teams want a platform they can build and play on themselves, versus outsourcing it to other providers.
“Let’s prepare these companies for when models advance a year from now and they [adversaries] start to be a lot of stealthier,” Thompson says. “Let’s give them the platform to test against that.”
An important piece of that involves unique tooling. Real nation-state actors don’t use the same tools twice. They don’t rely on static payloads that security tools can signature and block. They’re highly adaptable, and simulations must match that. RemoteThreat works to prepare organizations by building tools from scratch every time.
Beyond that, Thompson says the tooling can bypass Tier 1 endpoint detection and response (EDR) providers and security controls. Attackers, particularly ransomware threat actors, have become increasingly skilled at bypassing EDR.
“When you’re up against a skilled actor, you’re going to be up against the frontier models in a year from now that can build more exquisite tooling,” he says. He warns that organizations can’t overly rely on EDR providers to be the only control preventing someone from getting on a bank’s foreign exchange platform, stealing healthcare data, or breaking into a nuclear controlled network, for example.
Make Some Noise
While developing the platform, the founders focused on a series of questions that addressed what happens if an attacker does get in a victim environment. They wanted to push teams to challenge assumptions on how well their networks are actually protected: What happens when attackers bypass an organization’s EDR? How do they simulate an adversary going after critical objectives once they’re inside? How do they prove whether compensating controls will stop them?
And perhaps the most important — how do organizations design defenses that force attackers to make enough noise to get caught?
The platform doesn’t look to automate all processes; it’s about moving faster and at a scale that was previously unachievable, adds Thompson. Organizations are allowed to use their own AI models, but they don’t need AI. They can use the platform as a human red team operator, or a hybrid version with some AI assistance.
There is a huge push on internal teams to test more and to test faster at a higher degree of sophistication, he says. The pressure is on now, but Thompson asks: What happens when even small-time criminal groups start to use frontier models to boost attack velocity?
“Are we [organizations] going to be the juiciest target or is it going to be our competitors?” he poses. “How do we reduce our attack surface, make us better at detecting when they do gain an initial foothold, and ultimately, make us a less attractive target than the next person down the street?”