A 3 Million Yen Security Assessment for 50,000 Yen—AI Fuzzing Disrupts the Notion That Security Is Only for Large Corporations

A 3 Million Yen Security Assessment for 50,000 Yen—AI Fuzzing Disrupts the Notion That Security Is Only for Large Corpor

By Kai

|

Related Articles

A 3 Million Yen Security Assessment for 50,000 Yen—AI Fuzzing Disrupts the Notion That Security Is Only for Large Corporations

Security assessments cost 3 million yen per instance.

This was the reality for small and medium-sized enterprises (SMEs). When requesting vulnerability assessments from external security vendors, the cost typically ranged from 1 million to 3 million yen. Including penetration testing, it was not uncommon for costs to exceed 5 million yen. For companies with annual revenues of several hundred million yen, this was not an amount they could afford to pay even once a year.

As a result, what happened? A prayer: “We probably won’t be targeted.”

However, that prayer is no longer effective. According to a survey by IPA (Information-technology Promotion Agency), about 60% of companies that suffered from cyberattacks are SMEs with fewer than 300 employees. For attackers, SMEs, which often have weaker defenses, are merely “easier targets.”

And now, this structure is on the verge of being overturned.

What GitHub’s AI Fuzzing Agent Means

The AI fuzzing agent being developed by GitHub is an AI tool that automatically explores code vulnerabilities. Fuzzing refers to the technique of sending large amounts of random data or abnormal inputs to a program to identify crashes or unexpected behaviors—essentially, vulnerabilities.

Traditional fuzzing required security engineers to design test cases tailored to the target system and manually adjust them. Given the high hourly rates of specialized personnel, it was natural for costs to reach several hundred thousand yen per project.

The AI fuzzing agent autonomously executes the tasks previously performed by human experts. It reads code, generates attack patterns, detects vulnerabilities, and even produces reports. The only human involvement required is to “press the execute button” and “read the results.”

What is happening here is the collapse of the “cost of expertise” in security assessments.

Out of the 3 million yen assessment fee, the tool’s license fee is at most several tens of thousands of yen. The majority of the remaining cost is labor—compensation for the knowledge and experience of experts. If AI can replace that knowledge and experience, it is structurally inevitable that costs will drop to the range of 50,000 to 100,000 yen.

Autonomous Penetration Testing—The Commoditization of the “Attacker’s Perspective”

It’s not just fuzzing. Research on autonomous penetration testing utilizing LLMs (large language models) is also progressing rapidly.

Penetration testing involves attempting to infiltrate a system using the same methods as actual attackers to identify vulnerabilities. Until now, this was a job only possible for highly skilled “white hat” hackers, with typical costs ranging from 2 million to 5 million yen per assessment, taking 2 to 4 weeks.

Recent research has shown that LLM-based agents can autonomously execute the following processes:

  • Scanning networks and identifying targets
  • Cross-referencing with known vulnerability databases
  • Generating and executing attack code
  • Attempting privilege escalation
  • Generating reports on detection results

Of course, at this point, they lack the flexibility of human penetration testers. However, for the purpose of “comprehensively checking known vulnerabilities,” they are already approaching practical levels. What SMEs need is not protection against state-level advanced attacks, but rather to close basic gaps such as “forgotten patches,” “configuration errors,” and “neglected old libraries.” In that domain, AI can cover sufficiently well.

The important point is that this change signifies the commoditization of the “attacker’s perspective.” Until now, only a select few experts could possess the attacker’s viewpoint. Now, it will be available as an AI tool that anyone can use. This is good news for defenders, but we must not forget that attackers will also use AI.

Changes in Costs Will Alter “Behavior”

Here, we want to consider how changes in costs will alter the behavior of SMEs.

The traditional structure was as follows:

Item Traditional Cost Cost After AI Utilization
Vulnerability Assessment (Web) 1 million to 3 million yen/instance 50,000 to 100,000 yen/instance
Penetration Testing 2 million to 5 million yen/instance 100,000 to 300,000 yen/instance
Continuous Monitoring Monthly 300,000 to 1 million yen Monthly 30,000 to 100,000 yen
Hiring Security Personnel Annual salary 6 million to 10 million yen Can be replaced with AI tools + part-time roles

What happens when prices reach this range?

It shifts from “doing it once a year if the budget allows” to “doing it every month.”

This is an essential change. Security should not be a “once-a-year health check” but rather a “daily temperature check.” With costs decreasing, this can finally become a reality.

If a manufacturing company with an annual revenue of 300 million yen can conduct security assessments for 50,000 yen a month, that amounts to 600,000 yen a year. This is less than one-fifth of the traditional cost of a single assessment, allowing for 12 assessments to be conducted. It is clear which option is safer.

The Pentagon’s 30 Million Dollars and SMEs’ 50,000 Yen

The Pentagon (U.S. Department of Defense) is investing 30 million dollars (approximately 4.5 billion yen) in the development of an AI-powered lie detector. AI security at the national security level still requires massive investments.

However, there is a reversal in structure here.

Large corporations and government agencies build custom security systems. They spend tens of millions to hundreds of millions of yen to create their own defensive systems. Meanwhile, the proliferation of AI tools leads to the “commoditization of generic security assessments.”

What SMEs need is not custom-made armor but “off-the-shelf armor that is sufficiently sturdy.” And AI is dramatically improving the quality of that off-the-shelf product while significantly lowering the price.

In other words, there is a possibility that SMEs can acquire 80% of the defensive capabilities that large corporations obtain for 4.5 billion yen for just 50,000 yen a month. The remaining 20% pertains to preparations against state-level attacks, which are unnecessary for most SMEs.

This is not a story of “mimicking large corporations.” It is a story of “the defenses that SMEs truly need have finally become affordable.”

So, What Should Be Done?

What SME owners and IT personnel should do now is threefold.

1. First, Understand the Current Situation

Do you know what vulnerabilities exist in your company’s website or systems? If not, start by trying out AI security assessment tools that are available for free or for several tens of thousands of yen. There are several open-source fuzzing tools available on GitHub.

2. Switch from “Annual Assessments” to “Continuous Checks”

The greatest benefit of AI tools is that the reduction in costs allows for “increased frequency.” Automate assessments to be conducted monthly or even weekly. Avoid personalizing the process; let the tools handle it. Humans only need to focus on “analyzing the results and making decisions.”

3. Think with the Assumption of Being Attacked

The era of believing that SMEs won’t be targeted is over. In supply chain attacks, SMEs are targeted as entry points to large corporations. Protecting your own company is also about protecting your business partners. Conversely, having security measures in place can become a trust factor in business dealings—essentially a competitive advantage.

Security Transforms from “Cost” to “Competitiveness”

The collapse of costs for security assessments through AI is not just a matter of cost reduction for SMEs.

Until now, security was something that “companies with surplus could do.” Now, it is becoming something “any company can do.” The next development will be the differentiation between “companies that are doing it” and “companies that are not doing it.”

When a business partner asks, “What are your security measures?” the response from an SME that can say, “We conduct AI assessments monthly. Here’s the latest report,” will be vastly different from that of an SME that replies, “We’re not really doing anything.” It is clear which will be chosen.

The cost has dropped from 3 million yen to 50,000 yen. The significance of this number is not that it has become “cheaper.” It means that “there are no longer any reasons not to do it.”

POPULAR ARTICLES

Related Articles

POPULAR ARTICLES

JP JA US EN