LG CNS has successfully reduced the time required for penetration testing by 80%—from five days to just five hours—by adopting Amazon Web Services’ (AWS) artificial intelligence security agent. The case is drawing attention as a prime example of using AI technology to address the growing demand for security audits amid a limited pool of specialized professionals.
AWS Korea held an ‘AWS Security 101’ press briefing at its Seoul office on the 1st, unveiling a multi-layered security strategy for the high-performance AI era. During the event, Lee Jin-wook, Team Lead of LG CNS’s RED Team, presented the results of applying the AWS Security Agent to actual operations. “A penetration test that used to take five days was completed in five hours,” Lee explained. “Because multiple agents run simultaneously internally, performing a total of 20 hours of work in parallel, the actual time and cost were drastically reduced.”
The LG CNS RED Team is a dedicated organization responsible for vulnerability assessments and penetration testing of LG CNS’s services, systems, and solutions. With a recent spate of major security incidents and the proliferation of AX (AI Transformation) projects, demand for black-box penetration testing—which simulates conditions identical to those faced by real hackers—has surged. LG CNS projected that security audit requests would increase by approximately 30% in 2026 compared to 2024. However, the RED Team’s staffing is limited, making it difficult to handle the exploding demand with human resources alone.
Consequently, LG CNS began reviewing various AI pentest tools in early 2025, but high false-positive rates made practical application difficult. After evaluating AWS’s AI security agent, the company confirmed its low false-positive rate and high accuracy, deciding to adopt it at the end of last year. “The AWS Security Agent had a low false-positive rate, and since many of LG CNS’s services already run on AWS, integration was easy,” Lee said, explaining the background of the adoption.
The actual application method was implemented without significantly altering existing inspection procedures. When a white-hat hacker presses the start button, the agent autonomously attacks the target system, and the white-hat hacker then verifies the results. Humans only perform additional checks on areas the agent might miss, such as complex business logic. Lee described this as “simply adding an agent layer on top of the existing process.”
Accuracy varied significantly depending on the amount of information provided. When only account information was supplied, the true positive rate was just 60%, but this jumped to 90% when additional context, such as role-based permission data, was provided. The structure essentially means results depend on how meticulously the user sets the context.
The cost and time savings were clear. Based on the entire process including white-hat hacker verification, the inspection period was reduced by about 40%, from an average of five days to three days, while costs fell by 30%. When the agent was operated independently, the inspection period was slashed by 80% from five days to one day, and costs were cut by up to 70%. Furthermore, the variance in results based on individual white-hat hacker capabilities was minimal, ensuring consistency in audit quality.
Cases were also confirmed where the AWS Security Agent, in the process of actively discovering vulnerabilities, identified new vulnerabilities based on artifacts that had not been previously found. Lee evaluated that automating the entire penetration testing lifecycle—including dashboards summarizing test execution results, report generation, and threat scoring—significantly boosted work efficiency.
Having confirmed the effectiveness in terms of speed, expertise, cost, and pipeline integration, LG CNS plans to conduct a Proof of Value (PoV) for some services by the second quarter of this year before expanding the application to LG Group affiliates starting in the third quarter. “For regular annual audits, the agent alone should be sufficient,” Lee predicted.
Regarding concerns that the role of the RED Team might be replaced by AI, Lee dismissed them as unfounded. He outlined two future talent profiles for the RED Team. He forecasts that demand will grow simultaneously for highly sophisticated white-hat hackers capable of penetrating and spreading across an entire enterprise, and for white-hat hackers who interpret the results generated by agents and communicate them to developers. In fact, the LG CNS RED Team’s headcount is increasing, and other LG Group affiliates are increasingly forming their own internal RED Teams.
Meanwhile, at the briefing, Shin Eun-soo, Senior Security Specialist Solutions Architect at AWS Korea, introduced the changing threat landscape in the AI era and AWS’s multi-layered security strategy. “With the advent of an era where multiple frontier AI models detect vulnerabilities, the average time to exploit has shrunk from years to within hours,” Shin diagnosed. According to AWS, the average exploit time has rapidly accelerated from 2.3 years in 2018 to 5 days in 2024, and down to 20 hours this year. In contrast, patching vulnerabilities still takes more than 30 days, intensifying the overload on security personnel.
Shin explained that AWS has embedded ‘automated reasoning’—a mathematically provable security technology—into most of its security services. AWS Security analyzes 400 trillion network flows per day, while Amazon GuardDuty monitored an average of 8.8 trillion events per hour in the second half of 2025 and protects over 1 billion EC2 instances. Shin then introduced ‘AWS Continuum,’ which handles security at machine speed from discovery to verified remediation. AWS Continuum is a security framework that combines prioritization, validation, and remediation agents to automate the entire discovery-to-action lifecycle, including penetration testing, code scanning, and threat modeling. A key feature is its applicability even to systems not running on AWS.
AWS Continuum is an AI-based security service unveiled at the AWS New York Summit in March and is currently in beta (preview). Its three agents—prioritization, validation, and remediation—take on the roles of threat analyst, RED Team operator, and security engineer, respectively, automating the entire process from vulnerability discovery to remediation. It currently provides code vulnerability analysis capabilities, prioritizes issues based on business impact using SSVC (Stakeholder-Specific Vulnerability Categorization), validates findings by executing actual code in a sandbox, and even generates patches.
“Currently, the two services exist separately, but the Security Agent’s functions will gradually be absorbed into Continuum,” Shin stated. “Through this, users will be able to integrate not only code vulnerabilities but also risk modeling, design reviews, code reviews, and penetration testing using a single AWS Continuum service.”
The LG CNS case is significant in that it demonstrates the concrete effects achievable when AI agents are practically integrated into an enterprise’s security operations. Particularly as the shortage of security talent intensifies across industries, it shows that AI-based automation tools are evolving beyond merely saving time and money to complementing and augmenting the capabilities of human experts. With the addition of AWS’s Continuum integration plan, competition in the integrated AI security platform space—spanning everything from code vulnerability analysis to penetration testing—is expected to begin in earnest.