Expanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery
CrowdStrike, Thursday, August 6th, 2026
CrowdStrike argues AI cybersecurity benchmarks must go beyond vulnerability discovery to reflect real defender work.
CrowdStrike argues that evaluation of AI for defense has narrowed too far around vulnerability discovery.
The company contends benchmarks should reflect the operational reality of security teams, including the techniques adversaries use to gain initial access.
They should also cover the tasks that consume most of a defender's time, which are rarely finding novel bugs. CrowdStrike proposes expanding benchmark scope so AI capability claims map to actual security outcomes.