How Iberia Cards Uses Sara AI Pentesting to Stay Ahead of Modern Threats
Iberia Cards CISO José Manuel Rivera García explains why he's stuck with Synack's PTaaS model across multiple organizations, and how running Sara AI Pentest alongside human researchers helps him balance regulatory compliance with real risk reduction. He also shares candid advice for other CISOs on avoiding the false sense of security that comes from infrequent testing and over-reliance on perimeter controls.
Key Takeaways
- Traditional point-in-time engagements can create a false sense of security—recurrence and volume matter as much as depth.
- Sara AI Pentesting complements human researchers rather than replacing them, enabling more frequent testing between deeper SRT engagements.
- AI is lowering the barrier for attackers to launch targeted, business-logic-aware attacks—making offensive security testing more urgent, not less.
- The Synack model solves two problems simultaneously: effective risk reduction and regulatory compliance.
- Shift-left and Zero Trust are no longer strategic choices—they're becoming survival requirements.
When organizations talk about penetration testing, the conversation often centers on compliance checkboxes and annual reports. José Manuel Rivera García, CISO of Iberia Cards, a regulated credit financial institution specialized in payment and card services, thinks differently. With a career spanning R&D, open banking, and regulated financial infrastructure, Jose has built security programs that operate under serious regulatory scrutiny. We sat down with him to hear how Iberia Cards has approached offensive security testing, why he kept coming back to Synack across multiple organizations, and how he put Sara AI Pentest to work on real production assets. Here’s what he said.
How Did You End Up At Iberia Cards, What Has Been Your Experience In The Tech World?
My journey in technology started in R&D, but the real turning point came at RSI, the company that provides the core banking system and digital channels to the Caja Rural group and a large part of the mid-size and smaller banks in Spain. That’s where my transition into security happened: an executive development program at ICADE and direct mentorship from the company’s CISO helped me pivot from a purely technical role into a management position as one of his direct reports. That’s where I learned to think as a business-oriented executive, not just as a technologist.
From there I joined Fintonic as CISO, one of the first open banking companies in Spain, where security had a very specific dimension: customer data was literally the business. That forces you to mature very quickly in risk management, regulation and security architecture all at the same time.
When I arrived at Iberia Cards as CISO of a Credit Financial Institution regulated by the Bank of Spain, I found the environment where all of that converges: demanding regulation, payment infrastructure, and the need to build security that works within the real constraints of a specialized entity. The common thread throughout my career has been implementing Zero Trust architectures adapted to the operational and business reality of each organization, with the conviction that security has to enable the business, not slow it down.
What Triggered Your Need For A PTaaS Vendor, And How Did You Ultimately Discover Synack?
My relationship with Synack goes back to RSI, where we were already working with them in a continuous format. The model convinced me from the start: having a platform backed by real researchers, working on an incentive basis, generates a type of value that traditional consulting firms with closed-scope projects simply cannot replicate. When cybersecurity became my direct responsibility, it was one of my first decisions: prioritize this model over fixed-hour engagements with a predetermined deliverable.
I have evaluated alternatives—not just different vendors but different models to achieve the same goal. What keeps bringing me back to Synack is the convergence of three things you rarely find together: professionalism, breadth in vulnerability discovery, and real depth in findings.
With Synack I solve two problems simultaneously. On one hand, effective risk reduction: every vulnerability reported to me has real impact, these are not lists of generic misconfigurations that any automated scanner would have caught. On the other hand, regulatory compliance: the reports and the platform allow me to maintain interactive tracking with researchers throughout vulnerability management, which greatly facilitates the traceability the regulator requires.
What Did You Like About The Point-In-Time Synack14 Test Offerings?
The tests focused on customer-facing payment services and associated web applications, both the public-facing areas and the authenticated sections, as well as the associated APIs. I didn’t come to Synack without context: we had conducted previous ethical hacking exercises and I had a fairly clear idea of where the low hanging fruit was. That’s why I opted for a grey-box approach, providing user credentials so the researchers could go beyond the exposed surface and also work on authenticated business logic.
The results delivered value on several levels. In some cases they confirmed suspicions I already had, which also has its own utility: it turns a technical intuition into a documented, reproducible finding. But the most valuable outcome wasn’t what they found—it was what it allowed me to do with it. For the first time I could go to senior management with a real case, not a hypothetical scenario, and demonstrate that risk perception is something measurable and tangible. That completely changes the conversation at the executive level.
When First Considering The Shift From Human Researchers To AI Pentesting, What Were Your Primary Questions And Concerns?
My starting point with any automation tool is skepticism. I’ve seen too many solutions that stay on the surface: trivial findings, generic configuration issues, things any conventional scanner would have detected. The cost savings AI promises are real, but irrelevant if the depth isn’t there.
What made me take the step was a meeting with Synack’s product and technical teams. It wasn’t a standard commercial demo: it was a real technical conversation about how they built Sara, what decisions they made to give it intelligence and context, and how the triage process works to differentiate trivial findings from those that represent real risk. That gave me enough confidence to try it—not as a replacement for the human researcher model, but as an additional layer to evaluate how far AI can actually go in terms of depth and relevance of results.
The question I was asking wasn’t “can AI do pentesting?” but “can this AI find what matters?” That’s a much higher bar.
How Is The Widespread Adoption Of AI Impacting Your Team’s Security Strategy, And What Role Does Offensive Security Testing Play In Protecting Your Organization?
We’re seeing the impact of AI on two simultaneous fronts, and they need to be managed differently.
On the external front, we’re observing lower-volume attacks that are much better aligned with business logic. Traditional vulnerability scanners lose relevance when attackers have access to tools that allow them to add organization-specific context to the reconnaissance and exploitation process. That raises the bar for what you need to be able to detect and prevent.
On the internal front, my stance is conservative but enabling. At Iberia Cards we are deploying AI gradually, with each use case previously analyzed and controlled. The goal is to establish frameworks that allow us to accelerate the business securely—not block adoption, but channel it properly. We encourage the use of specialized AI with specific, measurable and repeatable use cases.
In that context, working with Synack on AI implementation for the offensive security block fits perfectly with that philosophy: specialized AI, with a defined purpose, controlled and with verifiable results. It’s consistent with how we want AI to work across the entire organization.
In parallel, we are strengthening our security measures against the emerging risks that AI brings: improving perimeter detection and working internally on control quality to detect and prevent misuse, both from outside and from within.
Tell Me About Your Recent Experience With Sara AI Pentesting
We ran Sara on the same assets we had previously worked on with human researchers, also expanding the scope to an additional commercial website. That gave us a real point of comparison—not just evaluating Sara AI Pentesting in the abstract.
The most relevant context to keep in mind is that we ran the test without credentials, which limits depth by design: without authenticated access, the AI cannot explore business logic in the same way a researcher working grey-box can. Even so, the deliverables were good and provided value. I still need to repeat the exercise with credentials to see how far Sara goes when it has the same starting point as human researchers. That will be the definitive test.
As for reporting, the format works well from a CISO perspective. I still see a certain gap compared to the narrative depth and context that human researchers bring to their findings, but the direction of improvement is clear and the pace at which the tool is evolving builds confidence.
The real differentiator of Sara for me is not that it replaces the researcher model, but that it complements it: it enables more frequent testing at a reasonable cost and effort. It will likely become a recurring element in our annual program, covering the cadence between deeper engagements with the Synack Red Team (SRT). It’s a balance that makes a lot of operational and economic sense.
What Are Your Primary Challenges Regarding The Recent Release Of Mythos, And Rapid Public Adoption Of AI?
Mythos will significantly improve scalping capabilities, and there’s a secondary effect we shouldn’t ignore: the launch of newer, more powerful models drives down the cost of older ones. Malicious actors also manage a business plan, and if AI hasn’t scaled well at high volumes until now, more specialized and affordable models will make targeted attacks against particularly vulnerable organizations a very obvious and accessible use case.
This has direct implications for timing. The time to effective exploitation of vulnerabilities has already decreased considerably before Mythos. With it, patching timelines will need to compress proportionally, because the window between disclosure and exploitation will keep narrowing.
For organizations, this means that practices like shift-left cybersecurity, secure development, and Zero Trust architectures will stop being voluntary and intentional decisions and become survival requirements. This isn’t rhetoric: it’s the logical consequence of an ecosystem where attackers have increasing leverage.
What concerns me most is not Mythos itself, but the iterative and exponential dynamic it represents. Months after an Anthropic release, other companies reach similar capabilities, sometimes with a greater appetite for risk in how they release their models. We don’t know exactly what Mythos will bring, but we do know the improvement curve is not going to stop.
And in that ecosystem, organizations operate at a structural disadvantage. Attackers don’t have to comply with compliance requirements, they don’t fear having assets exposed, they don’t permanently play cat and mouse. That asymmetry isn’t going away—we have to compensate for it by continuously evolving our entire security ecosystem, not in annual cycles.
What Advice Would You Give To Other CISOs Looking Into PTaaS And More Importantly AI Pentesting?
PTaaS is especially powerful for organizations that don’t have the budget or critical mass to maintain an internal offensive security team with rotating expertise. A small internal team produces poor findings not due to lack of talent but lack of diversity of perspectives. Synack’s model inverts that equation: their core business is precisely that service, which allows them to connect the right professionals to each engagement, rotate expertise across areas, and achieve much more comprehensive coverage.
The main trap I’ve seen teams fall into is thinking that one annual exercise means they’re covered. The model rewards finding vulnerabilities in volume and severity, which means that if one part of your application is particularly vulnerable, researchers will concentrate there. My recommendation is to run as many passes as your budget allows—recurrence is part of the value.
Another common mistake is layering perimeter security controls in front of the scope. I understand the logic, but it creates a false sense of security: researchers have limited time to bypass layers, the cybercriminal has infinite time. What really matters is exposing the application layer and doing real shift-left—finding problems in the business logic, not at the perimeter. The serious problems are always there, and there’s always time to improve the perimeter later.
There’s probably room to keep improving the approach, but with this philosophy I’ve been able to extract real value from ethical hacking exercises, and I’ll likely continue working this way.
Want To Try Sara AI Pentesting For Yourself?
Jose has spent his career building security programs that have to work within real business constraints—regulatory pressure, limited resources, and an evolving threat landscape that doesn’t wait for annual review cycles. For security teams navigating the same pressures, AI pentesting can make a real difference. If you’re ready to find out for yourself, start a free trial of Sara AI Pentest and see what it uncovers in your environment.
Read the Full Case Study
Find out how Iberia Cards moved beyond point-in-time compliance exercises to continuous, intelligence-driven testing that surfaces the business logic risk scanners miss.
Frequently Asked Questions
Iberia Cards sees Zero Trust as a philosophy to adapt to each organization’s operational reality, not a fixed template. The goal is security that enables the business rather than slowing it down.
The Iberia Cards CISO points to newer, more capable AI models pushing down the cost of older ones, giving attackers cheaper access to targeted, business-aware exploitation. This would shrink the window between disclosure and exploitation for financial institutions.


