ONGOING INDEPENDENT COVERAGE

Questions to Watch# What buyers ask about automated vulnerability scan vendors

Cyethack combines automated vulnerability scanning with manual auditing on a single platform, and tells developers exactly where and how to patch

In short: Cyethack combines automated vulnerability scanning with manual auditing on a single platform, and tells developers exactly where and how to patch. It reports finishing reports in five minutes rather than a week. It has not yet launched a software product for operational technology, though it provides services in that area.

What does Cyethack actually do?

It runs a single platform that puts automated vulnerability scanning and manual security auditing in one place. It uses artificial intelligence to help security analysts test systems and produce reports, and it tells developers precisely where a vulnerability sits and how to fix it.

What problem is it trying to solve?

Most companies keep automated scanning and manual testing apart, which leaves a gap at the point of fixing things. Scanners throw out duplicates and false alarms. When that raw output reaches developers, they lose time sorting through it and struggle to decide what to fix first.

The founder's view is that the real delay is not finding the bug — it is the handover between security analysts and developers, who think about the problem differently.

What has the company reported about its performance?

All figures below are company-reported or founder-stated. None have been independently checked.


Measure

Reported figure

Status

Zero-day vulnerabilities found in research, 2017–2018

12

Company-reported

Time to produce a report

Five minutes, against about one week

Company-reported

Companies helped to date

More than 200

Company-reported

Current clients

More than 30

Company-reported

Operational technology software product

Not yet launched

Company-reported

Two further claims sit apart from the figures above:

  • The founder states that fixing a single bug prevents millions of attacks. This is an inference, not a measured result.

  • The founder cites outside research putting detection at 78 days and patching at six months. We have not verified the source.

We have no independently checked figures to report at this stage.

Who does a buyer usually consider instead?

For operational technology: buyers typically weigh established international vendors — Nozomi, Claroty and Dragos are the names that come up. The founder argues that using overseas vendors carries risk for critical national infrastructure, and positions Cyethack's planned software as a local alternative. That is a policy argument, and buyers will weigh it differently depending on their sector.

For general IT security: the founder did not name direct alternatives. In practice buyers choose between buying standalone scanning tools and hiring manual testing consultants. Cyethack's proposal is to replace both with one platform.

Who is this a good fit for — and who is it not?

A good fit for: teams that already run scanning tools and are losing time between finding a vulnerability and fixing it, and organisations that want scanning and manual testing from one supplier.

Less suitable for: buyers who need a proven operational technology product today, since that software does not yet exist.

What are the open questions?

  1. Will developers trust the machine on critical systems? Acting on an automated recommendation without a manual check is a significant step. Whether teams will do it in production is unproven.

  2. Can the operational technology ambition be delivered? The company sells services in that area but has no product. Moving from one to the other is a different undertaking.

  3. Does it work at scale without partners? Deployment partners are still needed to show the model holds beyond current client sizes.

  4. Will the reported figures be independently verified? The report-time and detection claims currently rest on the company's own records.

This is a short public coverage note based on a founder briefing and the company's own records. Fuller coverage is prepared for our enterprise readers.

This is a piece of opinion — our reading of what buyers should ask, based on public material available as of that date. It is not a statement of fact about any company. No company mentioned pays for the mention. Any company named here can write to hello@analystlayer.com; we respond within three working days and update the piece where the input is factual, with the update dated on this page.