The conventional metrics for measuring autonomous pentesting are exploitability (rewarding a system for constructing a working exploit) and coverage (finding as many bug types as possible). But this does not reflect real world resource-constrained product security where you need to look at the cost and human triage effort required to validate, prioritize, and remediate bugs.
In this webinar, Xint researcher Quoc Tran breaks down how to measure operational efficiency through the decisioning inputs that matter to product security teams in practice: recall per dollar and per hour, triage load, and the marginal value of ensembling. He then demonstrates how time and cost intensity varies using commercially available frontier LLMs with light harnessing as well as through more mature harnessing structures. This includes a deep dive into the incremental cost to find each marginal bug and its implication to how product security teams should weigh those costs against the capabilities of real attackers.