Build vs. Buy AI Pentesting: Why Dow Chose to Partner With Synack

To hear both sides of the build vs buy debate around AI pentesting solutions, we spoke with Dow's cyber engineering team lead Dan Lacher and Synack's CTO Mark Kuhr. From Dow's perspective, Synack served as a force multiplier for a small internal red team. Meanwhile, building the Synack Autonomous Red Agent (Sara) from scratch definitely had some trial and error.

Abstract cyan waveform grid rippling across a dark background, resembling a data terrain.

Key Takeaways

  • Dow moved to continuous pentesting to close the gap left by point-in-time testing, years before AI was part of the equation.
  • Building a production-ready AI pentesting agent costs more in engineering and tokens than most teams expect.
  • Human validation still decides what's exploitable. Skip it, and teams end up chasing false positives.
  • The harness around the model, not the model itself, is what makes an AI pentesting agent perform like a real pentester.
  • AI pentesting is heading toward specialized agent swarms under strict guardrails, the same way human pentest teams already rotate and specialize.

Build or buy for AI pentesting has been a hot topic lately. A wave of new AI pentesting tools are promising autonomous vulnerability discovery, and security teams jump to the logical conclusion of building a version on their own. They’re wondering if they should stand up their own AI pentester internally or bring in a vendor who has already done the work.

We decided to dig deeper into this debate and put together this Build vs Buy webinar. Dan Lacher, the cyber engineering team lead at Dow, provided the “buy” side and shared why he chose Synack, while Synack’s CTO Mark Kuhr shared his “build” perspective of what it took to create Sara AI Pentesting.

Here is what came out of that conversation, and if you want to see for yourself, you can watch it on demand.

Dow Moved to Continuous Pentesting with Synack

Dow’s relationship with Synack goes back to 2022, before AI pentesting was part of the conversation at all. At the time, Dow’s internal red team had gone through starts and stops as people moved in and out of the company, and the security team was left running point-in-time assessments on its highest-value, web-facing assets. But Dow’s environments were changing faster than a point-in-time test could keep up.

That drove Dow toward continuous coverage with Synack. Today, Dow’s red team is small but focused, and it uses Synack as a force multiplier, directing Synack Red Team researchers at the assets that matter most rather than trying to cover everything internally. Dow has also automated the handoff, feeding newly exposed assets like cloud storage or forgotten subdomains to Synack in near real time so testing keeps pace with how fast the attack surface actually changes.

Why Dow Chose to Buy AI Pentesting

Once AI pentesting tools started showing up on the market, Dow ran proof-of-concept evaluations on several of them, and even scoped what it would take to build a capability in-house now that the red team was staffed again.

The conclusion was consistent: the token cost and engineering effort required to build and maintain a production-grade agent were larger than the problem justified. Standing up an engineering team to keep pace with model changes, prompt tuning, and orchestration is its own full-time job, and it pulls focus away from the work only Dow’s internal team can do, which is knowing its own assets and its own risk tolerance.

Why Human Validation Still Matters in Pentesting

AI agents can move fast, but they do not know which vulnerabilities are already covered by other layers of defense. Dow’s team still reviews what comes back before it reaches anyone downstream, which gives them the same confidence they get from human-validated testing, just applied to a much larger and faster-moving surface. Skip that step, and teams end up spending their time chasing false positives instead of real risk.

Why the Agent Harness Matters More Than the AI Model

On our side, building Sara reinforced a lesson that is easy to miss if you have not tried it: the model is not the hard part. We ran the same prompts against raw frontier models and against models wrapped in Sara’s purpose-built harness, and the difference in performance was not close. The harness encodes years of Synack Red Team judgment: how a human pentester evaluates a target, decides what’s exploitable, and knows when something is an accepted risk rather than a real finding.

We also learned early that lab benchmarks are a trap. Capture-the-flag style labs are useful for testing a narrow exploit path, but they do not reflect the complexity of a real enterprise app with real logins, inconsistent backend versions, and unpredictable workflows. An agent tuned only against lab environments will underperform the moment it hits production.

AI Pentesting Moving Toward Swarms of Agents

Sara is built as a swarm of specialized agents rather than one generalist model, with a real-time classifier enforcing each customer’s rules of engagement before any action executes. It is the same operating model Synack has used with human researchers for 13 years, rotating and specializing testers by skill set, just applied to agents working alongside them.

Should You Build or Buy Your AI Pentesting Program?

Buying gives you a force multiplier on day one. Building buys you a multi-quarter engineering project with a real chance of never fully catching up to a vendor that’s been refining this for over a decade. Outsourcing what isn’t core to your business is usually the better call, but only if you’re honest about what building the alternative actually takes: real staffing, a real budget, and a willingness to treat the first year as trial and error rather than a finished product. That math is starting to show up in the broader market too.

Forrester recently predicted that enterprises will defer a quarter of their planned AI spend into 2027 as the gap between AI hype and delivered value comes due. That same scrutiny applies to security testing: point-in-time testing was never going to keep pace with an adversary that doesn’t sleep, and neither will a homegrown agent that’s still working out its guardrails. If this is a decision you’re already working through, Synack is running a free Sara pentest right now. Start a free trial today and see what a human-validated agentic pentest actually looks like.

Related reading: What I Told Security Leaders at Gartner SRM 2026Continuous Security Validation: Why Synack Built for ItTenable Exposure 2026: AI Pentesting Helps Partners Turn Scanner Findings into Actionable Risk

Frequently Asked Questions

Learn how the Synack Platform can secure your organization