The speaker, Edo, co-founder and CEO of NOVY, discusses the evolving landscape of offensive cyber security. He notes that adversaries are scaling up advanced persistent threats and finding novel vulnerabilities faster than ever, rendering traditional tools ineffective. Organizations must adopt a new approach to detect and mitigate issues before attackers exploit them.
Edo shares his origin story: after military service in an elite engineering unit and a decade in an Israeli security agency cyber unit, he worked in three cybersecurity startups. In September 2024, the release of the O1 reasoning model prompted him, along with co-founders Omer and Gond, to found NOVY. They realized AI could provide the intuition needed for autonomous penetration testing, solving capture-the-flag challenges without predefined scripts.
To validate their vision, they interviewed 40+ cybersecurity experts, uncovering two consistent pain points: scanners generate false positives and lack intuition, while manual pen testing is point-in-time and expensive. Experts agreed that continuous, AI-driven penetration testing for web applications was a critical need. NOVY’s platform mimics human hackers, combining vulnerability discovery, exploitation, and lateral movement into a unified, autonomous system. Early adoption was strong, with thousands of customers attracted to easy deployment and quick results.
I think that we need to understand that the economics of offensive cyber is changing right now. I mean, the abilities of the bad guys to really scale up their ability to do a lot of advanced persistent threat in parallel, their ability to find more and more novel insights that they couldn't be done before really makes us as a security leader or people that are taking care of cyber security that we need a different approach and the ability is really for us is finding the bad thing before the bad guys will have to find them. Traditional tools are un-capital of doing it. So having all of the tools of the bad guys in finding issues but also providing us leveraging the context that we have on the terminal network and how we are structured and what we have from IT and security perspective. So we will have the ability to move faster than the bad guys in fixing and mitigate issues before they can have. Edo, thanks for making some time for me today. Yeah, of course, Justin. Every time that you call me, I'm Xermen. Oh, two kinds. Now, Euguffin, you're the co-founder and CEO of NOVY, really driving innovation in that whole pen testing with AI, AI pen testing, and I hate those terms in this category, but we'll get into that later. I really would like to rewind that wheel and go back to the beginning. Walk me through your origin story, how you got into this whole field and your career path and then ultimately how you've thought about doing a startup. So walk me through the beginning stages of you being you. Yeah, definitely. So I'm not the classic in the way like a cyber security interpenure in Israel. I didn't start in 8200. So during the military, I was a warrior and elite engineering combat unit that is specialized in finding tunnels in Gava Street. And I've been there as a paramedic and a warrior for four years. And during those years, I was really starting to appreciate the amount of intelligence that we're being able to get from the Israeli security agency. And after the military, I started a computer science degree. And yeah, and as a student, I tried to be elected to the Israeli security agency and I was lucky enough to get in to the cyber unit. So my dream back then was that I will be able to get, you know, provide a very good intelligence to people like me that are in the military and really needed in real time and very in a very high quality. So I've been there for almost a decade. And this is where I really learned the basics of cyber security and got a very good expertise in that. I was even getting the Prime Minister of the Israeli ward for an operation that I was getting for few years. Yeah, and this is one of my top moments in my career. Every time that I'm going to my mom's house, though I have a picture of me and shaking the hands of the Prime Minister and so proud. Oh my god, I mean, do you have brothers and sisters siblings? So I have a brother and sister that I have. So when you go back to your mom's house, do you drag them along with you to look at the photo together as a whole family? Yeah, let's see who is the biggest, the best talent here in the country in the family. To be honest, I always tried to be like, I don't know, I tried to be a wrong person. And even on high school, I was a full-close dancer. So I did for I did dancing for six years and yeah, so I tried to do a lot of different things and I did find my destiny. Wait, what kind of dancing? For Clore, it's like different countries, that's type of dancing. Yeah, yeah. See, I grew up in Germany. Did you do any of the German, like dancing, the old later Hosen? Yeah, yeah, yeah, yeah, yeah, it was a great way for me as a teenager, you know, with most of the dancers, so the like girls that look very, very good, so it's a very good way to know like with dancers. So I really enjoyed it. We even had a trip to the US that we did a like a tour in different cities in the US performing. Yeah, so it was a really good experience back then. So a little bit about my origin. But I found my destiny in cyber, like honestly, like I think that I got the best training in the world. It's a great organization, there's a security agency, and you're really working with the top notch people. Everyone was, you know, you really feel that you're doing something very special and important for your country, for your people. And during those years, this is where I met Omer, he's gone to my CTO, he's a top PO program graduate and he was a team leader in my team, in my group, sorry, and go on the self-confirmed, the chief product officer, he was in 800 during those years. So the three of us are very good friends since I'm like 15 years, going 15 years back. And many of our founding teams today are people that are work with us during those days. So to be honest, in the way, this is where Novi started, because a lot of what we're doing today, with AI, when it comes to penetration testing, a lot of this expertise, the modus operandi of how we operate, the bonding that we have with the people that are working with us, it's a lot of a lot of that we got from those years working together, you know, under a very high stress, long hours, including weekends. So in a lot of ways, it's a very, very good atmosphere to prepare you for startup, because in general, it's a very large organization, but water was shocked and really appreciate that even as an employee in this organization, you always can be heard and come with initiatives and with new types of ideas, the organization is very flat in a way. And I think that many of the ways that this type of organization works, very quickly, a lot about innovation, a lot of hours. And all of those aspects really simulates in a very, very good way, a lot of aspects of startups. So I think in a lot of ways, not only Novi, but in general, the Israeli cyber security startups, like really booming, and because you have a very good example on how it should look like. So, yeah, so the origins of Novi is really on those days, the three of us working together are really good friends. And nine years ago, I moved to the private sector, I've been in three different cyber security startups. And in September 2024, it was when O1, the first reasoning model of O1 was released. And the three of us all may have gone and myself understood that there is something significant that can be done with this type of new AI tooling. And specifically when it comes to offensive security, we did a POC, we tried to to solve all kinds of capture of the flag challenges, combining utilizing O1, which back then was the only reasoning model that you could work with. And add to that, the right tools, prompt engineering, and injecting to the memory of an agent, very good examples and knowledge base that it can learn from and getting more context. And we were pretty shocked from the fact that we were able to solve real capture of the flag challenges. If you will tell us solve this challenge, we know how to solve it as humans, but we don't know how to write a Python script, for example, that knows how to solve it without giving it instruction in advance on what to do. Because pretty early on, you're getting into a situation that you have infinite numbers of options on where should I go now or what can I do now? And you cannot do any more traditional code of if else, if else. Again, infinite numbers of options. And then this is where you need some kind of intuition. And we did find a way utilizing those really state-of-the-art AI models to leverage those in order to solve this type of problems. And we did understand that this is the right timing for a real something very new that you couldn't done before, doing penetration testing in the level of the best experts in the world, but in in a machine speed in continuous way. So before we get jump into that, go back. Where are the other startups that you worked in before founding OV? Yeah, sure. So the first one, I John very, very early on, like I was the first employee in the company, the company named Fiber MDX.
We did cyber security for hospitals and medical devices back then. So for me, it was like a very good combination because I was a paramedic in the army. And I was really in between going to be a doctor and going to be like computer science to think that I really like. So for me, it really was a combination that I was cyber and the medical world. And those years, I really learned that I really like the outbound activities. So sales going to conferences in the US. And this is why I transitioned to the US. I was living in New York City. So the great experience, even my second daughter was born in New York City. So, and so I've been there for four years. We were like, why a late foes count? Then I moved to Orca Security, a cloud security company. It was a really great journey in Orca. Really, you know, it's the first time that I really felt what it means being in a startup that have a product market fit. The growth in the beginning from five to $50 million that happened very, very quickly. And I think it's a company that's really solving until today, a real pain. And you know, it was a big transition to the cloud and the ability to do cloud security and agentless manner was very, very unique back then. And after that, I moved to Orca Security and non-human identity company. And in September 2024, this is when like me, Omen and Gond said, okay, this is our time. Like there is. So you saw that opportunity because the LMS coming out and that reasoning capability, what was that journey look like from, hey, here's something that I think we can do to that seed check founding. I did you talk with a lot of security leaders on what you wanted to do or hey, you already knew it and you're just gonna drive into it. What happened? - Yeah, so I mean, good question. So in the beginning, like we understood that there is a technological shift, okay. But now comes the question of what we can really, what is the real pain that we can really solve now because we want to be the business. We don't, I mean, this is, like the aim of start right? So, so we, first of all, we came up with a very big vision like we call the company Novi, which is like an acronym of Novo Negobility Exploitation Editor. Like we will solve the problems of vulnerability. - I just know that. - It's fiber. - Yeah. (laughing) - Well, you got to get t-shirts with the end.O.D. and the acronym format, no? - Yeah, I'm so good at it. I like it, yeah, we do it. I was sent to his sweat. - This is what you get when you talk to me, value-at. This is what happens. - That's true, yeah. (laughing) - Until now, it's worked perfectly, I agree. So, so we said to ourselves, okay, we do understand that there is a unique technology, like a very broad vision. But what really, like what is the current pains and where we should start? So what we did is, admitting with more than 40 different cybersecurity experts, mostly in North America. We came with a pretty simple methodology. We build the presentations, free slides, that's it. The first slide is a very like bold statement, which was something around your offensive security program is the broken, and this is why you're, you're an easy target for hackers or something like that. Because we have a thesis that something is broken with offensive security, but we want to crystallize it better, to distill the root colors. So, this was the first slide, and then we spent most of the time like 20, and 30 minutes around it, around, do you agree with that, Mr. Ciso? And 80, 90% of the time there also was yes. And then, okay, so how are you trying to handle with it today? What are the different tools that you have today? And why do you think that it's true? Do you think that is going to, this problem is just going to grow, or it's going to stay the same? And then the next slide was, okay, now that we've discussed about this topic, let's try to understand together what are the four root colors for this bold statement and why, okay, we're agree with us. We're just trying to analyze the data in the situation today. And we found out that there was very consistent two root colors that repeated themselves, very, very, like 90% of the time, and even more. One is, I have a lot of different scanners, dust tools, the time-capaculation security testing for my apps. I have like external exposure scanners, I have the classical vulnerability scanners, like Rapid Seven and Qualies. That works in continuous fashion, but really like an intuition and provide me tons of false positive. And they don't really have the ability to find novel vulnerabilities. And then if you have a security practitioner who want to put them out higher, then we are choosing to allocate budget for manual penetration testing or red teaming exercises, which sometimes provide novel insights, but it's really just point in time. And so this was very consistent that people, especially organizations that do care from security that are not doing penetration testing only for compliance check the box. They are willing to pay for it, they are looking for a very good solutions. And if you will be able to do it in continuous way, it will be a dramatic shift and something that couldn't be done before. And then the third slide was, let's say that we were able to build this amazing machine. Where do you want it to work? Like you need to put a flag, you want it in the CI/CD, you want it in production, you want it in the cloud, on the on-prem, cell parties, et cetera. And it was also here, it was not consistent as before. I mean, there were people that put it, I want to do penetration testing for my AI agents. I want to do penetration testing, but the common sense was I want to do penetration testing for my web applications. And then came the question, okay, why this is the first place? And there was two reasons for that. Number one is organizations where they generate much more code with vibe coding and AI assistance for developers. And the attackers are studying also to leverage AI. So, these are our back then, we're expecting them to start at least focus on the things that are external exposed, which is many times the web applications. So based on those three slides and very consistent responses, we understood that if you will be able to build penetration testing capabilities in a human level and a good place to start is in web applications, this is where we went to YL and other funds that we've met with, with the scissors that we are going to revolutionize the space of penetration testing with AI. - Got it. So it's a really interesting market. I remember when you and I first talked, I don't know if we you and I talked about it, but it was, you know, pen testing is kind of a human oriented boutique kind of thing. I get it, you know, the advancing automation into that would be amazing. But it was, but it wasn't that exciting, but it wasn't until over that weekend that I really sat down and thought about what I would call the three different components that are really in this, like vulnerability discovery plus human component of that. You've got the red team penetration testers in one box. You've got the vulnerability scanners, you know, we've got a couple large companies in there. Then you've got this desk market, really for, you know, A and B plus maybe a CICD pipeline kind of integration, QA testing kind of process. But if you combine all three of those, oh man, that's pretty awesome. Is that how you're thinking about it or is it completely different? - Yeah, yeah, definitely. I mean, one of the things that is also part of our discovery course after that we came up with this idea. So we said, let's say that you have your own white head hacker that your friendly white head hacker that works for you. What you'd like you to do, so it was really like you described. It's, I would like this person or team that worked for me to come from the outside like real hackers, discover all of my external exposed assets, understand what are the entry points into my organization, find me known vulnerabilities that I should patch, but also novel vulnerabilities and maybe something in my business logic. And then go, move forward, like, right, finding a way maybe to do a lateral movement inside the corporate, et cetera. So, and if you think about it until today because of the limitation of the technology or the abilities of people to really scale, because this is exactly what we are seeing here that there is a very unique opportunity here.
And this is by the way the way that hackers are working, right? I mean, they're combining a lot of different mythologies and a lot of different aspects of cyber in order to find a way to penetrate in. So I definitely agree with you that it becomes very interesting once you understand that the segmentation that wasn't here today in offensive security is can be removed so you can really build a real platform or at one stop tools that works like a real hacker that is very creative, doesn't stop between boundaries because okay, now it's and try to move forward and leverage basically everything that they have in their hands, right? And so this is in order to try to find an entry point. So there you are, you started your fundraise and the teams building, you know, starting to build the product, I would imagine those conversations that you had trying to figure out where you wanna focus and then maybe soft pitching this idea of one of many as well as in how you get those first design partners, what was that engagement like? I mean, for me, it's, oh my God, I can understand a scanner that would not go into exploitation, but we're really talking about the exploitation or in the fuzziness of identifying unknown vulnerabilities that their in-lies could, the concern around operational impact, right? Was that a big push? Was that something that you saw in those early days or not so much? - Yeah, good question. Overall, I feel, I mean, many times we are finding organizations that tell us, listen, I mean, you're targeting our web applications. So what you can do and the other bed guy you can do. So it's better that you will find it before they will do it. And, but there are organizations that are little bit more concerned, so you can definitely deploy us in staging environment or so it's not. So we didn't find it as a very big obstacle until now. And in general, what we have found, this is why you also, I think they raised very quickly the A-RAR because we were able to attract pretty quickly a few thousands of customers. And so the movement from design partners to paying customers was very, very quick on that front. So we do feel that there is a real need today in the market. - Sure. - And once you are really showing a very good results and the ability to move very, very quickly with you is pretty unique, I think in this space, like a very easy deployment and quick time to value. So, well, I'm kind of fascinated because I started out many, many, many moons ago doing attack and penetration work. And you know, you do your footprinting, your discovery, your exploitation and you kind of go through that cycle. But embedding it into a automated, a fully autonomous kind of capability, there's concerns about taking down the service, of course. But then there's, how do you mirror that complexity of whatever tech it is, what all the exploits are, how to analyze them, even how to find unknowns, how did you build out that beginning component of the solution? - Yeah, so basically what we did is, once we started it, we said, we have the state of the out-element today that are really great and evolving all the time. And you can think about it as a brain of a person. This brain is with 180 IQ, but it doesn't really have any experience or expertise or capabilities when it comes to offensive security. So what we decided to do is really mimic the same way that we train hundreds of different penetration testers. And how does it work? So let's say, just in you are a young person, that is smart person, what you can argue. - But you don't know those. (laughing) - But then right, you are a young, motivated person. And also pretty smart. And then, but in order to get you into a phase that you will be a very good penetration tester, what you will need to have is very good tools, to be familiar with a lot of different tools, be familiar with techniques on how to find vulnerabilities, and also train you with giving you a lot of good examples that you can learn from. - Yeah. - If you think about this, is how you train penetration testers. So our architecture really mimics the same thing. Like we have an MCP server that contains thousands of tools, the techniques that many times only we know, we are articulating ourselves, our research team, the cyber expert in the team into prompts. And we are, we are collecting a lot, a lot of very good examples in our knowledge base. So once the agent is trying, for example, to exploit an SQL injection vulnerability or cross-site scripting or any other types of vulnerability, we have the option to inject to the memory of the agent, a very good examples. So now's come a lot of AI engineering, let's call it or agent engineering, because it's not a one agent, it's a hive mind of AI agents that are communicating with one another, and you have a router that supervises on all of those and sharing data with one another, and how do you manage the context window of each one of those, and how you're dealing with elituations and how you validate things are real and what is not. And how you are fine tuning it over time, and how you augment it with, with more inputs or a several contexts that you are getting from the user. But in a very high level, the methodology was really around treating it as a brain and giving it the experience that you need to have as a penetration tester. - Intrusion. - So, yeah, I mean, the knowledge that we had, I mean, you can think about it, I mean, Cheshapity knows all of the rules of chess, right? I mean, it's, but still, Cheshapity is not the best chess player in the world. Like you have, if you look on how deep blue and other was trained is really with a lot of good examples, and try to play the game many, many times, and so different prioritations, it's not only by just treating the rules of the game, right? - So you really had to create, yeah, you really had to create your own training capabilities for the tools, or at least the access to the tools and knowledge of the tools, you had to create your own corpus data of all exploitations, all fingerprinting kind of attributes, et cetera, et cetera, et cetera, to kind of pull it into, a real world scenario, training capability of a full process, or more of that circular kind of loop process, was it easy to do, or was it more complicated, or harder to pull together than you expected, or? - So both, to be honest, I mean, (laughs) In the beginning, the start is very, like it's pretty amazing, like you can get into very unique results pretty quickly. I mean, because the agents today, the way that they architecture, the elements themselves, like really brilliant. So the beginning is promising, but then you are starting to get very quickly to a lot of very big challenges of, as I mentioned before, context management and also pricing issues about tokens. And this is where we are really having, we have today in the team, the guy that our head of AI was for seven years, and employee number five in AI 21, which is a company that tried to compete with CHRGPT, and he was the VP of platform over there. We have a few PhDs. So like, when you really try, start to find tuning it and being able to get into the level that you are able to really understand the logic of the application with the agents, and finding novel vulnerabilities that are business logic, this is where things are starting to be very complex. So on that front, when it comes to AI, we really feel that we are doing, I mean, we are in the, on the hardest thing that they're being done today, and like the best labs in the world today, open AI and stroppy can others, like reinforcement learning, and massive training at scale, and building simulations, environments, so all of those things are not trivial, and you have a very small amount of people in the world that can do it. So this is why we are getting such a good result that are pretty unique, like, say that just in person from the street can get. - So I know we kind of jumped into it, but I'll ask my typical questions. What is Novi? - So Novi is the best hacker in the world that is also the best AI defender in the world.
So, nobody knows how to detect novel vulnerabilities in complex environments and personalizing defense mechanisms at the same time. So, this is the unique aspect. When you understand that from working with hundreds of enterprise environment, customers in the past, they're just showing more new issues. And we just another headache, if you're not really giving me the ability of the practitioner to solve it quickly. So, I think it's a very unique, yeah. I really want to dig into the defense. But before I we do that, I want to ask, what is an integration look like? So, there I am, a hypothetical new customer. I'm ready to kind of, let's say I'm doing a POV or I'm ready, I signed on the dotted line. What's next? Yeah, so let's sign an NDA. Choose, no, certainly, signing an NDA, give us an access to the application that you would like us to test. And that's it, basically. It's very internal. What if it was an external website? Of course, the contract that has an NDA and everything into it, as well as a check because I'm paying for things. Yeah, so it's just signing an NDA. We are, yeah. And from there, yeah. No, and then what do I do? Do I go to your, I get an account on your service and configure, configure my IP addresses, sort of thing or was that look like? Yeah, so you can define some kind of some guardrails, if you like. I mean, how quickly, if you want to put like rate limits to how quickly we are working, you can put, for example, adding headers. So every request that we will do, if you're shocked, him will know that it's no, we can provide you static IP addresses, so you will know that this is no via not something malicious, now happening. But other than that, it's basically that all that is state, like from there, we, we're making the same way that we're hacking some working. In a matter of a few hours, few days, you will start to see what you're able to cover and the issues that we were able to detect and also guiding you on how to remediate or mitigate. And so you also brought up potential internal websites that I want to, you know, or a sub domain or whatever that might be as part of my CI CD pipeline or standard QA testing. Is that a different type of integration? Yeah, I mean, if you would like to integrate us into your CI CD process, this is great. You just need to configure it, so we will be notified every time that you're doing a public request, for example. And so we will have an access to the code and then we will be able to test only the delta of what has changed. One of the best practices in our, in our perspective is let's do a one several assessment and what you currently have in production. Let's find the critical issue that you currently have, but for now on, let's work in continuous way that we will integrate into your CI CD and we will be able to every time that you have a change, we will be able to test specifically this change. So you will be able to see that you are secure than the things that have been changed are being checked as soon as possible before they're getting into production. Now going back to something that you brought up earlier in regards to defense. That integration into the code base also relate to your point that you are making earlier or maybe a better way of asking, what did you mean by hey, we can help solve these problems for you, not just find more. We are looking for an answer advantage of what we can do compared to the better guys. And what we have is a relationship, a good relationship with the organization that we are working with, right? I mean, as a hacker, you are trying to collect as much information as you can possibly, like everything that you can do in order to find gather information, but we are working in. In collaboration with the organization that we are protecting on, so we can have an answer advantage on the sense that we can understand from them in advance what is the crown jewels, what is the ecological stack that they have. And then really being to personalize the defense mechanism to their specific technological stack and we can have an access to the code that the bad guys hopefully doesn't have yet. And then being able to highlight issues that very quickly and giving you a specific instructions on, change this line of code in this function in order to remediate this issue. And this way, this quick ability to understand about, oh, I have new issue, this is how should I meet to get remediated and then you're getting faster compared to the bad guys. That they don't have this feedback loop or all of this understanding of what's happening in the customer environment. How do I connect to, let's say, and I apologize about this, I have an IP address for an external web page and I've got a code repo of that code for how do I link the two together in no V so you know when you scan X, this is a code repo to be able to do that compare and contrast. Yeah, so basically it's part of the when you start a new assessment or in general, and you do the onboarding part of what you're telling us is here is my domain and now you can give us more knowledge, for example, here credentials or this is how you should authenticate to this application. One of the questions that you are asking you is what is the reposite is connected to this occasion. And then this is how we know so it's. Is it is it just a code repo or is it other types of data like, you know, build documents, architecture documents or you know, could I pointed to a G drive of all of that. So, you can include app security content as well as engineering content for context. Yeah, definitely so part of the knowledge base that we are collecting and this is one of the cool stuff let's call it around LLM is the ability to digest a lot of unstructured data. And access to the code something like it's really not a must from our end. So yeah, any network architecture or if you have a documentation or even, you know, gira tickets from the past like all of those can be digested and we are. We are more than happy to get any more context that can be provide. And then the agents really improve based on that and so wait if you're ingesting gira tickets, you could probably say hey they said they fix problem X. But we see it other 15 other places and you know we were able to exploit a 15 other places on the site itself kind of concept is that what you're seeing. Many time in we also we have two examples in that we are now having in our blog post and adding it a lot of example that. The researchers of ours were able to find specific vulnerability in an app and then. After that that we're adding this logic and right tooling to the agent that it's kept defining 15 more. And vulnerabilities or even zero that vulnerability so yeah, definitely if we know in advance and this is also something that we really like to do is the ability to know about. Past issues that you have and then that's valid date that it doesn't come back or maybe you. You found it in one place, but you have this type of problem in other places. Yeah, this is definitely a strength of what we're currently doing. This is a fairly new technology with a lot of you know I would call buzzword labeling with AI and a marketing sense across the industry. How do is there data if I was a customer to say are you better or worse than the human pen testers that we are currently paying money or maybe even my own team that we're funding yes I get the you're constantly doing the scanning the always on automation. But are you really identifying zero days etc etc is there data that you can point to to show that the technology is matured to that point. Yeah, so I mean we are starting to you know putting in our blog a lot of good example, but I think in the end the way I said the proof is in the pudding so for us the big make up like as hey Mr potential customer. We are here to help you you already did. And it's a very interesting testing so you have your latest report so you have a benchmark. Put no view on the under the same give us the same application and you will see that the deployment was much easier faster and you are more than welcome to see that we will find things that the bad that the other guys didn't find. and we did it faster, deeper than wider. Yeah, so.
And by the way, part of the team, also like the people that support the customers are really top-notch people like we have Omri was the number one in the leader world of the fact that one for the last few years Ba was for the last nine years was leading the strategic Israeli Red teaming doing hands-on should red teaming to the Iron Dominion Israeli Air Force Omri and a lot of other people in our team like really expertise is filled. Yeah, so we are working in the end with customers and if we And we are helping them and guiding them from our knowledge and so you have this very unique mix because I do feel that's currently Let's put a side AI and everything and like we have the best penetration testing we are the best penetration testing company in the world So if you would like us, we can also do for you Non-open-intration testing and giving you a report that you can show to your auditor So like it's not that you need to choose between the really new technology compared to the human aspect of it. So Well, I think what I like is you know, I've started to see in the book bounty programs the automation tools starting to get to Like in the top five if not the top one and I think I'm a nist not nist. I think um maybe DARPA ran a program Between last RSA and now of trying to identify the efficacy of Automated vulnerability discovery tools So I think those and it's been a while since I've taken a look at it But I think those are two things that might be interesting to kind of bring up in regards to just industry wide For the listeners of saying is this real or is this hype right those aren't those are data points I agree hey easy a POV with You know an external vulnerability scan type of a tool Whether automated or not or advanced or not is a fairly low bar to kind of really yeah Here's my URL or IP address go ahead and scan show me the results But the interesting thing I didn't know is the integration with the code repels another directories To really pull together Not only better analysis on how to perform the attack but also Hey, here's where we're finding the problem in code so you can actually fix it Right and so that that's more than just you know a vulnerability red teaming pen testing Kind of thing at least that I've done in the past, right? Yeah, I mean in the end this aspect that um You can work with that the same way that you're doing with judge pt right it's over time Once you're providing it more context and speak with it more It's really evolving and providing you better results that is Specifically for you So like the problem with automation until today and like let's say Dust tools are just starting to try to fuzz everything that is related like everything in your app doesn't matter if What's the app is doing? Like on that front what we're building is very very Different on the spec it will test things that are really relevant to your specific vacation It's not try to fuzz everything and and I mean it doesn't make any sense and you you're also getting a lot tons of false positive and also Many times like it's really you know like a kind of a denial of service attack because there's really like Exhausting that the API of the system in every front so You can now do a different thing You've alluded to like zero days and other things in this conversation In reality with your customers and the POVs that you've done Uh one Is are there have there been Uh surprises of hey, I didn't expect that in in reality when solution meets reality, right? And I think the second one is you know, what is the reality of finding zero day vulnerabilities? In solutions if somebody has gone through all of the pen testing red teaming You know their own scanners etc Are you able to still find those problems there? Maybe those will be the two questions to kind of ask next Yeah, yeah, so I don't remember Yeah, I know and almost any POV that we did are deployment that we didn't find And novel insights at the customer no knew anything else like because of how deep it goes um Yeah, it's almost always finding that not always You know critical stuff, but it is finding things that weren't unknown before that are relevant and needs to be addressed Mm-hmm Any any shock and a's from your current customer base That uh you didn't expect leave their names out of this of course. Yeah, yeah, of course I think that um I mean the fact that we are finding a lot of issues that is related to um Debility from move Gather data from one user to it like one user that can see the data of another user Doesn't matter if you have insurance company or other company Uh, it is something that we are finding pretty common and Like it was very hard to detect until today because Like automatic tools doesn't have this ability to understand. Oh, now. I'm seeing a data of Edo and I'm just in um And For people like that there's a lot of pre-mortations that you need to try here That is So not a lot of penetration testers are even capable of detecting these type of issues. So I think this is an example of an area that we do find a very interesting result And it is also like most of the time with High severity with those types of things because most of the in most apps It's you don't want to use or a will be able to see the data of scuder be Yeah, if it's an insurance policy or health status or credit card number down matter Um So we're finding many interesting aspect of those types of it's called idle or ball of vulnerabilities Interesting So I I have to ask and again another staple question that I go to you've got a really interesting landscape of competitors You've got Incumbans you've got different market segments you've got a whole bunch of things but you've got new competitive startups of course, right? How do you differentiate when you say what what is different about no v? What is that differentiation? Yeah, so first of all is um Is the call of the product the the fact that we are training our own AI model giving us Results that no one else can provide because our model is and it's very hard to achieve it is trained and specialized in finding vulnerabilities. It's really fine tune for it So the ability for us to find noble insights is no one that other cannot find it's very unique The second thing is the fact that okay, we found this inside but now we are also personalizing the fixes So we are here with you. We are not just Another alerts machine We will give you Steps to replicate so we can be validated. It's a true positive and then because of this Very unique capabilities that the team have in in in AI and offensive fibers and it gives us the ability to really move Very quickly and at this in the beginning with a very low amount of previous knowledge So we don't have an access to the code or stuff like that so the deployment is so easy So it's much easier to move forward with us very very quickly And really test the technology Very interesting um what's the one thing you want the audience to take away from if there was one thing That's a good question. I mean the abilities of The bad guys to really scale up their ability to to do a lot of Advanced process and threat in parallel And their ability to find more and more novel insights that they couldn't be done before really makes us as a security Leaders or people that are taking care of cyber security Uh, that we need a different approach and the ability is really For us is fighting the bad thing before the bad guys will have to it will find them and traditional tools are on the capital of doing it so um We need again to to kind up with this that we have an answer advantage compared to the bad guys So I think having all of the tools of the bad guys in finding issues But also providing Us leveraging the context that we have on the terminal network and how we are structured and what we have From IT and security perspective So we will have the ability to move faster than the bad guys and fixing and mitigate issues before they connect so That's awesome. Well, I got asked it's got to feel great uh, you know doing your startup, but you know is going very well If memory serves, I think you recently just raised another round that got published. I think it was fairly large, right Yeah, so we were raising more than 50 million sub dollars uh in four months Uh
And yeah, like I think that, I mean, only gone and myself and the team that we have with us we really feel that we are the best team in the world to solve this type of problem. We are feeling the momentum and in the end, the fact that we have, you know, we are very focused on in the end to deliver very good results for customers. And this is the model of the company in the end. Like, let's people that are working with us really believe and feel that we are providing them the value, we are protecting them and we will do whatever it takes in order to keep this reputation. - That's awesome. If somebody in the audience wanted to get a touch with you, learn more, do a POV, whatever, what's the best way for them to reach out? - Yeah, so you can just direct message me over LinkedIn. You can submit, look at them on the website. But I would be more than happy to be contacted directly. I mean, especially new people that are interested in the company and what we are doing most of the time. I want to take the first meeting by myself to hear what their interests, I mean, this is the best way for me to make sure that I'm connected to the market, what people are looking for. Yeah. - Well, you got 51 or 50 or so million, you got to build out that sales team. You got to put that money to work and get a head of sales to kind of reach out and touch somebody over in the customer, right? - Yeah, so we will publish soon. Now we really hired a very unique VP of sales. - Oh, congrats. - Yeah, yeah, let me definitely feel that this is the right person for us to scale it up. And yeah, I mean, because we feel that we have a very unique opportunity here and yeah, we want to get as quickly as possible to as much organization as possible that so we will be able to protect them as soon as possible. So yeah, this is. - And that's novy.com or. - Dot security. - Novy and no VEE. - Yeah. - And no VEE. - Dot security, perfect and Edo Geffen G EFF E N for our audience listeners, audio listeners to be able to find you on LinkedIn. And then they hit you up with massive DMs. It's going to be amazing. It's going to be great. - Greg, do you get a lot of those LinkedIn spam messages that seem to be floating around nowadays? - Yes, yeah, I get a lot of those. But also very interesting people that are. So yeah, I'm making sure at least once in a day to look on the message that I'm getting. - You're two kind. I get a lot of messages. I don't mean to bang on LinkedIn, but whatever. Hey, so the guys I said hi, of course. Congratulations on everything. The fundraiser was great and you guys are going to be awesome. - Yeah, I'm sure that I will keep admitting you during the event. So yeah, awesome. - All right. - Thanks, Edo. (upbeat music)
Podcast Summary
Key Points:
The economics of offensive cyber are changing, with adversaries scaling up advanced persistent threats and finding novel vulnerabilities.
Traditional security tools are insufficient; organizations need to find and fix issues faster than attackers.
The speaker, Edo, co-founder and CEO of NOVY, has a unique background
NOVY was founded after the release of the O1 reasoning model, which enabled AI-driven penetration testing by solving capture-the-flag challenges through intuition-like capabilities.
Through conversations with 40+ cybersecurity experts, NOVY identified two root causes of broken offensive security: scanners produce false positives and lack intuition, while manual pen testing is point-in-time and expensive.
The initial focus is on web applications, as organizations generate more code with AI assistance and attackers target external exposures.
NOVY aims to combine vulnerability discovery, manual pen testing, and CI/CD integration into a unified, autonomous platform that mimics human hackers.
Early adoption was rapid, with thousands of customers drawn to easy deployment and quick time-to-value.
Summary:
The speaker, Edo, co-founder and CEO of NOVY, discusses the evolving landscape of offensive cyber security. He notes that adversaries are scaling up advanced persistent threats and finding novel vulnerabilities faster than ever, rendering traditional tools ineffective. Organizations must adopt a new approach to detect and mitigate issues before attackers exploit them.
Edo shares his origin story: after military service in an elite engineering unit and a decade in an Israeli security agency cyber unit, he worked in three cybersecurity startups. In September 2024, the release of the O1 reasoning model prompted him, along with co-founders Omer and Gond, to found NOVY. They realized AI could provide the intuition needed for autonomous penetration testing, solving capture-the-flag challenges without predefined scripts.
To validate their vision, they interviewed 40+ cybersecurity experts, uncovering two consistent pain points: scanners generate false positives and lack intuition, while manual pen testing is point-in-time and expensive. Experts agreed that continuous, AI-driven penetration testing for web applications was a critical need. NOVY’s platform mimics human hackers, combining vulnerability discovery, exploitation, and lateral movement into a unified, autonomous system. Early adoption was strong, with thousands of customers attracted to easy deployment and quick results.
FAQs
The economics of offensive cyber are changing as attackers scale up advanced persistent threats and find novel vulnerabilities, requiring security leaders to adopt a different approach to detect and fix issues faster than attackers.
NOVY is a cybersecurity startup focused on AI-driven penetration testing. The acronym stands for 'Novo Negobility Exploitation Editor,' aiming to solve vulnerability problems.
They interviewed over 40 cybersecurity experts using a three-slide presentation. They found that 80-90% agreed that offensive security programs are broken, with two root causes: scanners produce false positives and manual testing is point-in-time.
Organizations have many scanners that lack intuition and produce false positives, while manual penetration testing provides novel insights but is not continuous. NOVY aimed to offer continuous, automated penetration testing at a human expert level.
Based on customer feedback, NOVY focused on web applications, as they are externally exposed, generate more code with AI assistance, and are a primary target for attackers.
NOVY uses state-of-the-art reasoning AI models combined with tools, prompt engineering, and a knowledge base of examples to mimic the intuition and expertise of human penetration testers, solving capture-the-flag challenges autonomously.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.