Brian Sims
Editor
Brian Sims
Editor
CREST – THE leading international non-profit organisation representing the global cyber security industry – has announced the launch of the first Artificial Intelligence (AI) additions to its standards for accredited cyber security service providers. Applications are now open for organisations wishing to become assessed against them.
The first-of-its-kind initiative marks a critical transition for the industry: from voluntary commitments to independently verified standards for AI-enabled cyber security services.
Over three-quarters (76%) of cyber security providers have increased their AI usage over the past year, while 69% of them are already integrating it into daily service delivery. That’s according to CREST’s report on AI in Penetration Testing. However, recognised standards for demonstrating responsible AI use have not kept pace with this change.
As such, CREST is stepping in to address this gap head-on. The new standards provide practical and independently assessable requirements. These help service providers to demonstrate and verify responsible AI usage, both within their businesses and when delivering services.
As stated, applications are now open for existing CREST members and cyber security service providers who wish to obtain additional recognition for the use of AI within their accredited penetration testing services.
The optional AI-enabled penetration testing requirements form part of the CREST Penetration Testing Accreditation Standard and realise independent assurance of responsible AI usage.
Outpacing governance
Nick Benson, CEO of CREST, said: “AI adoption is outpacing governance and we’re here to fix that. We recognise buyers are increasingly demanding that AI-enabled services are independently assured. In such a fast-moving space, there was no time to waste. We believe these new additions to our standards will deliver a practical and enforceable framework to regain the market’s trust.”
Trust is becoming a competitive differentiator for providers. Buyers, regulators and procurement teams are demanding greater accountability and independent evidence. Given the high-stakes nature of the industry, unverified claims are no longer sufficient. The industry now needs assurance that AI-enabled services are secure, transparent and professionally governed.
Unlike voluntary agreements, this formal accreditation integrates directly into CREST’s existing complaints and disciplinary processes. This allows CREST to take action and enforce compliance across the ecosystem.
Collective experience
Chris Oakley, senior vice-president for assurance services (Americas) at LRQA Cyber Security (a US-based CREST member) said: “In the US, we’ve seen regulators and auditors quickly move from asking: ‘Is AI used?’ to: ‘How is AI governed?’ There’s already an assumption that AI is playing a role. CREST’s new AI standards are based on the collective experience of cyber industry leaders and provide a consistent answer to AI governance in cyber security.”
Sanjay Verma, managing director of CyberZone Global (a CREST member located in Australia) commented: “AI-enabled cyber security must not only be innovative, but also effective, fair and transparent. These principles are increasingly central to responsible AI governance globally and align with the intent of ISO/IEC 42001 for Artificial Intelligence Management Systems. These new CREST AI standards can translate them into practical and independently assessed expectations for providers.”
William Wright (CEO of Closed Door Security, itself a Dubai-based CREST member) explained: “CREST’s new standard comes at a critical time as organisations are becoming increasingly dependent on AI. Advanced AI systems are steadily moving towards becoming critical infrastructure. It’s essential that organisations are confident in the security surrounding them. With them now being adopted to support security operations and also to identify and remediate vulnerabilities, they require a framework approach for responsible usage that this new standard brings.”
Continual refinement
CREST developed these new standards in collaboration with the industry and will continue to refine them through its dedicated AI Working Group.
The standards follow on from the June launch of CREST’s industry-backed AI Charter and AI Principles. A global cohort of more than 100 founding signatory cyber security organisations (including more than 10% of CREST’s worldwide membership) publicly committed to supporting the responsible use of AI across industry services.
Existing CREST members and cyber security service providers are now invited to apply for this new accreditation or download the CREST Accreditation Standards in order to learn more.
*Further information is available online at www.crest-approved.org
Dorset House
64 High Street
East Grinstead
RH19 3DE
UNITED KINGDOM
01342 31 4300