Swedish cybersecurity company Outpost24 has introduced the next generation of its CyberFlex managed application security program. Its latest update reflects a gap in how organizations used to approach cyber risk and tries to raise the bar for app cybersecurity as artificial intelligence reshapes both digital transformation and the threat landscape.

Founded in 2001 and now operating from 14 offices worldwide, Outpost24 provides cyber risk management solutions to thousands of organizations across industries. The company’s latest CyberFlex release debunks the traditional model of fixed annual application security testing, which doesn’t work well in the age of AI and real-time payments. Instead, it offers continuous, risk-led and most importantly adaptable approach crucial as organizations’ digital environments evolve.
The launch happens at a time when artificial intelligence is speeding up software creation, cloud computing, and digital changes, but it simultaneously assists cyber criminals in identifying and taking advantage of weaknesses quickly. As companies come up with new programs, AI strategies, cloud solutions, takeovers, and external integrations within the year, the security personnel are facing attack zones that are completely different from the ones they evaluated previously in their annual planning.
According to Outpost24, this growing mismatch makes the need for application security programs that can dynamically identify and prioritize real-world risks rather than relying on predefined testing schedules urgent.
The majority of application security programs still operate on fixed and highly structured testing scope. But, the fact is that due to dynamic nature of business operations changes occur all the time without prior notice. This means that during the time between the assessments new vulnerabilities emerge in the application which may not be discovered until the next assessment is carried out. Thus, the question of constant visibility into the changing attack surfaces is being stressed by the organization.
Now CyberFlex has updated its CyberFlex platform which implements the principle of automated scanning, testing and even advisory services in one single workflow. Rather than commissioning individual assessments throughout the year, organizations operate under one contract that allows security budgets to be reallocated between testing, validation, and advisory services as priorities change, without requiring repeated contract negotiations.
The program is delivered by Outpost24’s EU-based, CREST-certified penetration testers and is available through structured service tiers that can be expanded as an organization’s security maturity develops.
“Security teams are being asked to defend dynamic environments, while many AppSec programs are still planned around fixed scopes and annual cycles,” said Omri Kletter, Chief Product Officer at Outpost24. “CyberFlex is designed to close that gap and set a new standard for modern application security. It gives organizations the visibility to understand what has changed, the expert validation to understand what matters, and the flexibility to shift investment as risk evolves.”
One of the key features of the latest announcement is the continuous attack surface visibility powered by AI-based risk insights. The add-on enables organizations to keep track of both their known and unknown as well as shadow IT assets, which will allow them to get an overview of how their external exposure changes over time and to prioritize their treatment. Further, it will also create reports following which organizations are able to show their boards, executives, and auditors that they indeed manage to achieve some measurable improvements.
This announcement is a reflection of a more important trend resulting in organizations in the area of cybersecurity that go away from occasional vulnerability assessments and move towards constant vulnerability management. AI technology has made the process of software development much faster. However, it has in turn allowed hackers to automate the reconnaissance process and vulnerability detection. One example is Anthropic’s testing of Claude Mythos, the frontier model that remains unreleased for now due to its reported stark coding capabilities that make existing security tools fade in comparison. As a result, many experts in the field of security believe that application-based security services must be adaptive now.
Industrial and technology distributor RS Group is among the organizations planning to adopt the enhanced CyberFlex capabilities.
“CyberFlex has made it much easier to connect testing activity to real business risk,” said Rebecca Wensley, Head of Security Operations, RS Group. “We get clearer visibility into our attack surface, expert validation where it matters most, and a more practical way to prioritize remediation and demonstrate measurable security progress to stakeholders.”
Beyond continuous testing, the platform introduces greater flexibility in how security investments are managed. Organizations can redirect budgets toward penetration testing, validation exercises, or advisory services as emerging risks change throughout the year, allowing security programs to respond more dynamically without revisiting procurement processes.
Nearly 70% of organizations say the rapid pace of AI development is their top GenAI-related security concern, while 73% are already investing in AI-specific security tools, according to the 2025 Thales Data Threat Report based on a survey of more than 3,100 IT and security professionals.


