Customer Stories

How Agentic Pen Testing keeps Elecsys Technologies current on security

Services

  • Penetration Testing

Cyber security isn't a once-a-year exercise. Working with Instil gives us continuous independent assurance, helping us keep pace with an evolving platform and threat landscape.


Ryan Murphy

CEO

Elecsys Technologies CEO Ryan Murphy sat down with us to explain why platform security is now central to its growth strategy. That's meant building a wider cyber security roadmap, with agentic pen testing at its centre, built to keep pace with a platform that never stands still.

Elecsys builds software that is transforming how complex electricity networks are managed. Across renewables, utilities, data centres and critical infrastructure, customers use Elecsys to manage electrical safety, operations and network information across the UK, Ireland, and a growing international footprint. In a safety-critical industry, that means moving quickly and continuously improving the platform without compromising security.

AI-assisted development means more code shipping more often across the industry, and testing that runs once a year was never built for that pace. 

Falling behind carries a real cost, slower innovation and a lost competitive edge. Most businesses struggle to close that gap in one step. Instead, Elecsys is getting ahead of it, working with Instil on a testing strategy built to keep pace with development while giving their customers confidence in a solid security posture.

For Elecsys, that curve looked like this.

1. A single test, run ahead of anyone asking for it

Proving the basics starts with a single test. For Elecsys, that meant commissioning a first ever penetration test in 2025, before any customer had asked for one.

"I knew we were building a critical mass here, the platform was getting to a certain size, and it made sense for us to have a test carried out," Ryan says.

Software keeps shipping after that first test closes out. A test is a snapshot, and if testing doesn't move as fast as development, what's actually running in production keeps drifting further from what's been checked.

2.  Finding out where one-off testing runs out of road

This is where one-off testing runs out of road. By the time a second test is due, the platform has usually moved on so far that a straight repeat doesn't make sense.

"So much had changed that it would have needed to be a full test again, not a retest," Ryan says. "There's no point testing once and fixing what you find while development never stops, that's just chasing your own tail."

The instinct at this stage is often to book another engagement, or a bigger one. A continuous problem needs a continuous solution, and more people thrown at a one-off process isn't it. The actual problem was finding vulnerabilities as they're introduced, not once a year. Acting on what's found is a development issue, one Instil doesn't get involved in.

"One of the challenges we had is that we just didn't have the capacity to actually fix findings without knock-on effects on the rest of what we were building," Ryan says.

3. Testing that moves at the same pace as the platform

The way through is a different model, not a bigger dose of the same testing. It's the model that finally matched detection to the platform's own pace. Agentic pen testing runs continuously rather than in single sweeps, so vulnerabilities get found as they're introduced instead of once a year. Agents handle the repetitive, always-on work of probing the platform in different ways each time, while Instil's own pen testers provide the governance and judgement to validate and prioritise what they find. Elecsys has committed to three years of this model.

"There's a cycle now, and we follow it," Ryan says. "I'm not the one working out when the right moment is to trigger the next test."

That timing problem was real. Elecsys had just shipped a substantial production release, big enough that it was part of the reason a full retest was back on the table. Waiting for a natural pause to test never worked, because the platform never stopped moving long enough to need one.

"There was no right time to say to Instil, come in and do a test, because the software never feels finished," Ryan says. "With the agentic and continuous approach, that sense of having to draw a line in the sand and work out when the right time is just goes away. You don't know what vulnerabilities are out there, and this isn't something you can leave for next week, next month, six months, when you've got a production environment live."

For a platform embedded in safety-critical energy infrastructure, that's security finally keeping pace with development, not trailing behind it.

It also changes what Elecsys can say to the customers who depend on its platform.

"Some customers just want a clean pen test to facilitate a contract, but what you really get is peace of mind for the C-suite, and something you can pass on as a positive signal to your own customers," Ryan says. "As a small business, you're always working with someone larger, and larger organisations demand a lot more from you to make sure your posture is in order."

What's at the end of the curve

The businesses that get furthest along this path treat security as a strategy that grows with them, not a series of one-off exercises. Elecsys has just completed ISO 27001 certification with Instil's support, a separate strand of the same wider security strategy.

We're already aligned with ISO 27001, and I think of continuous testing as part of the same thread, a security posture that matures as the company scales rather than something we do once and forget.

That's where Elecsys and Instil are heading next, building out that wider security strategy further as Elecsys grows into new markets and takes on more AI-driven tooling of its own. Security that's wired in from the start scales with the business, instead of needing to be bolted on later.

If your platform is shipping faster than your testing can keep pace with, that's worth a conversation.