APPSEC DISPATCH INVICTI NAMED A LEADER IN IDC’S SEPTEMBER 2026 DAST ASSESSMENT ● PROOF BEFORE PRIORITY ●
Company / Application security

Invicti and the expensive art of being believed

A security scanner can find a flaw. Getting someone to fix it is another business entirely. Invicti has built its application security platform around the evidence that travels between the two.

A website fails a security test. Someone fixes it. Someone pays for another test. The test finds something else. There is a peculiar business hidden inside this loop: paying, repeatedly, to learn whether the last payment achieved its purpose.

Channel 4 knew the routine. Its security team commissioned penetration tests from outside companies, repaired the problems and commissioned more tests. For a broadcaster with thousands of web assets, the cycle had become expensive. Invicti offered a way to bring routine scanning and repeat testing into the team’s own hands. The interesting question was how much of that loop software could absorb.

The story in four points
  • Invicti tests running web applications and APIs, then validates supported vulnerabilities with evidence.
  • Its heritage combines Netsparker and Acunetix; Kondukto adds management of findings across tools.
  • Customers buy automation, reporting and developer handoffs as well as scanning.
  • The useful measure is work removed from the queue, alongside coverage achieved.

The bill for checking twice

In Invicti’s published Channel 4 account, CISO Brian Brackenborough reported an initial reduction of approximately 60% in the annual penetration-testing budget. Spending later fell to roughly one-fifth of its original level. The team could identify websites without personally identifiable information and scan them continuously, including sites created for new programmes. That is a specific change in a specific testing programme, rather than a promise that every customer can dismiss its penetration testers.

“We can fire up Invicti, run the tests as often as we like.”

Brian Brackenborough · Channel 4 CISO

That experience supplies a useful starting point for understanding the company. Invicti sells application security software. Its buyers have websites, internal applications and APIs to defend. Their shortage is often the time needed to test them, investigate results and shepherd repairs. A scanner that produces an impressive pile of warnings may make that shortage worse.

Channel 4 · reported spending
Before
100
Initial change
40
Following year
~20
The bill gets a haircut. Penetration-testing spend indexed to 100 before adoption; customer-reported figures, not subscription prices.

A flaw with a receipt

The technical centre of Invicti is dynamic application security testing, or DAST. It examines an application while it runs, interacting with its exposed behaviour rather than only reading the source code. Invicti’s proof-based approach takes supported findings further: controlled tests attempt to establish exploitability and supply evidence. The report can carry something a developer can inspect, rather than merely a suspicion to debate.

Think of the difference between being told that a door might be unlocked and being shown that it opens. The demonstration does not describe every door in the building. It does, however, make one conversation considerably shorter. This is Invicti’s distinctive pitch: reduce the uncertainty attached to a finding before it becomes somebody else’s task.

Invicti product illustration displaying a verified command injection and its proof of exploit
Suspicion arrives with paperwork. Invicti’s product illustration puts a verified finding beside the evidence behind it.

The company’s 2021 analysis examined six years of anonymized usage data covering more than 540,000 unique vulnerabilities. It reported confirmation accuracy above 99.98%, using customer false-positive flags followed by researchers’ review. That denominator matters. It measures the reliability of confirmed findings; it does not mean the scanner finds 99.98% of every vulnerability an application contains.

99.98%

Vendor-reported accuracy of automatic confirmation.
Confirmation accuracy ≠ complete coverage.

Invicti also publishes a 94% confirmation rate for direct-impact vulnerabilities. Its technical explanation makes the ambition fairly plain: eliminate much of the routine verification work where automatic proof is possible. An unconfirmed finding still needs judgment. A beautifully demonstrated flaw also needs a repair.

A scanner learns to manage the queue

The company has a longer memory than its incorporation date suggests. Invicti was formed in 2018 by bringing together Netsparker and Acunetix. Acunetix’s history reaches back to 2005. In 2022, the Netsparker product brand became Invicti. The result is a company assembled around an established technical craft, rather than a new name that appeared with a new acronym.

Portrait of Invicti founder Ferruh Mavituna
A founder outlasts a product name. Ferruh Mavituna is listed today as founder and strategic advisor.

In October 2021, Invicti announced a $625 million growth investment led by Summit Partners. Existing investor Turn/River Capital would remain a significant shareholder. The money was intended to support growth and product development. It is an investment figure, with no published valuation attached in that announcement.

The next revealing move came in August 2025: Invicti acquired Kondukto, a specialist in application security posture management, or ASPM. CEO Neil Roseman described customers asking for a unified view of risk. A good scanner could supply credible findings, yet teams still had findings from code analysis, dependency checks and other tools to reconcile. The acquisition targeted that organisational problem.

ASPM brings reports into a shared management process: normalize them, correlate them, prioritize work and route it. Here the scanner’s evidence becomes an input to a larger system. The strategic bet is that accurate runtime information helps a security team decide what deserves attention across a crowded collection of tools.

Invicti’s broader platform also incorporates static code and component analysis. Its Mend partnership adds SAST, software composition analysis and container capabilities beside runtime testing. These approaches see different things. Source analysis can inspect code that a web crawler never reaches; component analysis can flag a dependency even when it is not loaded. Runtime evidence helps provide context, without making those other views redundant.

The ticket is part of the product

For a less grand, more instructive example, consider Park ’N Fly’s published experience. The airport-parking business needed to cover internal applications, kiosks and facility-management software. It integrated Invicti with Azure DevOps and Jira. Scanning and the work of creating, assigning and explaining issues became less manual; CTO Ken Schirrmacher estimated savings equivalent to at least one full-time employee.

The detail to copy is the handoff. An alert becomes useful when the responsible developer receives sufficient evidence and remediation guidance in a familiar queue. Without that, the security team has bought itself another place to log in. Automation earns its keep when it removes the clerical steps surrounding expertise, leaving people to exercise that expertise where it matters.

Customers range beyond software companies: the ING EURAsia IT Audit team’s account describes testing varied, custom-built applications and choosing Invicti for ease of configuration and meaningful reports. Invicti reports more than 5,000 customers in over 115 countries. Financial institutions, public bodies and healthcare organisations have reasons to value repeatable testing and reporting, although a report alone cannot confer regulatory compliance.

There is a corresponding craft inside the company. Its careers materials describe practical hiring exercises, creative problem solving and quarterly company-wide wellness days. More tangibly, its public Brainstorm repository combines local language models with a fuzzing tool to discover web paths. That modest piece of public engineering says something useful about its expertise: finding where an application can be tested is itself a security problem.

Invicti colleagues pictured together in a team photograph from its careers page
Even automated security has a group photograph. Colleagues pictured in Invicti’s careers gallery; the company recruits across several countries.

Buy the handoff, measure the work

Invicti’s commercial model is subscription software with quoted platform packages and service options. Web + API concentrates on runtime testing; Core broadens coverage; Flex adds enterprise flexibility. A separate Agentic Pentest offer advertises assessments for $500 or less, with reports within 24 hours. Those figures describe that offer, rather than the price or scope of an enterprise subscription.

Its market includes commercial alternatives such as Burp Suite, Rapid7 InsightAppSec and StackHawk, alongside open-source ZAP. OWASP’s guide lists several of these approaches. The comparison is most useful on real applications: authentication, API coverage, evidence quality and the development team’s ability to act. Invicti’s runtime foundation suits buyers who put those requirements near the centre of their programme.

A practical trial should follow several findings from discovery through retesting. Count analyst minutes spent verifying them, developer time spent reproducing them and the delays between assignment and repair. Treat scan configuration as part of the experiment. Invicti’s own triage checklist asks whether authentication held, API definitions were complete and controls such as rate limits affected the result. Software cannot give evidence about a page it never reached.

The economics also need local measurement. Suppose, purely as an illustration, a team investigates 100 alerts for 20 minutes each: that is more than 33 hours before any repair. Remove half that investigation and roughly 17 hours return. Whether those hours justify a subscription depends on the actual workload. Invicti’s cost guidance recommends comparative pilots and workflow measurement, rather than translating an accuracy statistic directly into labor savings.

The current ambition is larger than a scanner. On September 29, 2026, Invicti announced a Leader placement in IDC’s DAST assessment. Recognition is useful context; a successful handoff is useful evidence. The most persuasive Invicti demonstration ends with a developer fixing a well-explained problem, and a retest showing that the fix worked. The alert has finally earned its audience.