Artificial intelligence is rarely out of the headlines, and cyber security is no exception. AI is rapidly changing how businesses are protected, and how they are tested for weaknesses. But with the hype comes a good deal of confusion, and some genuine risk, for businesses trying to work out what is real and what is simply marketing.

Albrighton-based cyber security consultancy Solusec has become one of the first firms globally to be accredited under CREST's new AI-Enabled Penetration Testing standard, joining the scheme's inaugural cohort. It adds to the firm's existing CREST Penetration Testing Accreditation.

What the accreditation means

CREST, the international body that accredits the security testing industry, launched the accreditation in July 2026. It is an independent mark that a firm uses AI responsibly and transparently in its testing, giving businesses a reliable way to tell well-governed AI from marketing spin.

In practice, it means local businesses get faster, more thorough testing from a trusted local expert, independently verified, with their data kept safe and a skilled human always in charge.

Why it matters for local businesses

The timing is significant for the region's smaller firms. As more large organisations sign up to the Government's Cyber Resilience Pledge and begin requiring Cyber Essentials and security testing right across their supply chains, local suppliers increasingly need to prove they take security seriously simply to win and keep work. What was once a "nice to have" is fast becoming a condition of doing business.

When it comes to security, expertise matters

Founder Daly Whyte is keen to draw a clear distinction between what specialist cyber security providers offer and what IT support providers often try to offer themselves.

"You wouldn't take a supercar to Halfords to be tuned," he says. "Your IT provider keeps the lights on, and they are invaluable for that, and for acting on the advice a specialist gives, but specialist security testing and assurance is a different beast. Too often what gets sold is just automated tooling with a clever label and a company logo, or a business's data being dumped into AI tools with no understanding of where it goes or whether what is being relayed is valid. A skilled human understands the information in front of them, the risk, what should be done, and what needs immediate follow-up."

How to tell a real test from an automated one

If your business is asked for a penetration test, or you are thinking of buying one, a few simple questions help separate genuine testing from an automated tool with a clever label:

  • Is a qualified human actually carrying out the testing, or is a tool simply being run for you?
  • Does the provider hold independent accreditation, such as CREST?
  • Will they tell you clearly where AI is, and is not, used in the work?
  • Is the scope properly understood and agreed before anything begins?
  • Is your business data kept safe, rather than fed into public AI tools?
  • Can they show a track record of finding real issues that scans and tools miss?

About Solusec

Solusec provides specialist security testing and assurance services, including managed detection and response (MDR), from its base in Albrighton, working with businesses across Shropshire and beyond. The firm is CREST-accredited, a certified assessor for the Government-backed Cyber Essentials scheme, and led by an accomplished ethical hacker with 25 years' experience across IT and cyber security.

Find out more by emailing This email address is being protected from spambots. You need JavaScript enabled to view it. or visiting solusec.co.uk.