HomeCase StudiesHow VerifiedThreat Uses Human-Centered AI to Transform Cybersecurity Defense

How VerifiedThreat Uses Human-Centered AI to Transform Cybersecurity Defense

Richard Jones has an extensive experience in AI/ML at scale. Formerly Portfolio Technical Director AI/ML Centre of Excellence at GSK, Richard was responsible for developing a data integrity quality machine learning program worldwide, and has extensive background in cybersecurity.
Richard Jones
By Richard Jones · AI/ML Cybersecurity specialist with over 15 years in developing AI/ML platforms · London England
Published August 10, 2026 · 5 min read
This case study is based on responses submitted directly by the founder or member of the team from VerifiedThreat. They have verified ownership of their domain verifiedthreat.com on SaaS Browser.
VerifiedThreat homepage

How VerifiedThreat got started

Most people have seen how AI has transformed the way we do business today and the pace of innovation. In cybersecurity, it was realizing the only way to defend against the latest AI attacks was to fight fire with fire, and develop a comprehensive platform that integrates the latest real-threat intelligence with external-facing red team simulation at massive scale. Now, tools such as Mythos can discover zero-day exploits from source code, the attack surface is only going to increase exponentially. You can't patch your way out of a problem this big. That's like bringing a knife to a gunfight. Moving to continual threat exposure management, managed at machine speed with intelligent agents, so you are proactively protecting, is the only way forward. But it's very difficult to achieve this in practice. Moving towards continual assessment is challenging. That's why we created the platform VerifiedThreat. Large companies struggle, well-resourced with dedicated cybersecurity staff, red teams, purple teams, extensive budgets, and smaller companies don't stand a chance.

Growing VerifiedThreat: what worked and what didn't

The VerifiedThreat marketing strategy centers on fostering deep, consultative relationships rather than relying on traditional, high-volume advertising channels, which have consistently underperformed. We have found that broad-spectrum ads fail to resonate with our target audience of technical decision-makers, such as CISOs and CTOs, who prioritize substance and actionable intelligence over surface-level messaging. Instead, we have seen significant success through knowledge-led initiatives, including educational seminars, specialized online content, and community forums. By consistently providing value through deep-dive threat analysis, industry-specific use cases, and executive-level briefings, we establish ourselves as trusted partners rather than just another vendor. This content-first approach creates the necessary dialogue to understand complex client environments, allowing us to demonstrate the tangible ROI of our platform. By pivoting away from costly, low-conversion ad campaigns toward consistent, value-driven thought leadership, we are successfully building a loyal client base anchored in expertise and mutual trust. The ad stuff just hasn't worked for us.

What VerifiedThreat customers really think

The high volume of false positives generated by traditional scanning tools remains one of the most significant complaints from customers. These conventional tools focus heavily on patching and identifying known exploits. But they often flag version discrepancies blindly, overlooking cases where a business faces upgrade dependencies or has implemented workarounds. This leads to bloated reports with numerous issues labeled as urgent, while the overall scope of actual threats is missed. VerifiedThreat resolves this by blending real-time threat intelligence with dynamic target assessments to discover hidden vulnerabilities. It provides critical contextual data, including the asset's value, along with the actual code required to verify the vulnerability. This ensures customers receive precise, actionable data, allowing them to effectively prioritize the vulnerabilities that truly matter to the business. That's why we named VerifiedThreat! We do what we say on the tin. The platform shows the actual code used to expose the vulnerability and shows the priority by asset criticality. Customers get a smaller list of vulnerabilities that actually matter to the business and can reduce risk.

“We just can't do this manually. It's impossible; we just don't have nearly the resources.”

— A VerifiedThreat customer

What most people get wrong about Cloud Security & Compliance Tools

Ultimately, people buy from people, not platforms, no matter how good they appear to be. In the complex landscape of cybersecurity, decision makers are not looking for another automated dashboard or impersonal interface; they are instead seeking help from partners. They need experts who understand their specific infrastructure, can navigate their unique operational constraints, and offer guidance rooted in real-world experience. When we show up as advisors - people who truly care about the client's resilience - we bridge the gap between technical data and business strategy. A platform is merely a tool, but a trusted advisor provides the context, the nuance, and the confidence required to make critical decisions. By prioritizing the human element in our sales journey, we move beyond being a vendor to becoming an extension of our clients' teams, fostering long-term relationships built on reliability, shared goals, and the tangible, human assurance that their assets are genuinely protected.

What's next for VerifiedThreat

We're continuing to expand our intelligent agents and are working on potential attack chains - where often a small vulnerability can be exploited to create a much wider cybersecurity issue or an actual breach. This has its challenges, as looking at potential attack chains also develops the chance of recording more false positives. But the value of the attack chain is extremely high. Often, the attack chain is not obvious, and attackers are constantly creating new attack chains. It's extremely difficult and time-consuming to manually red-team each attack chain.

VerifiedThreat traction so far

We've deployed over 12,000 agents in our orchestrated suite, capable of monitoring millions of assets with continual assessment.

Richard's background

I've spent over 15 years developing AI/ML platforms in cybersecurity and large production environments at massive scale. At GSK Plc, one of the most highly regulated industries in the world, we had to have very strict discipline to develop "Explainable AI", where each function of the machine learning was understood and could be repeated and tested for drift over time. This precluded some of the GenAI modules due to its inherent lack of reliability. This is the discipline necessary in cybersecurity. Clearly, dealing with data integrity in a pharmaceutical context allowed me to understand the limitations of AI, how to ensure the "human in the loop" was central to the progress, and how to measure precision and recall over time with an extremely high level of data integrity.

Biggest lesson building VerifiedThreat

While we initially explored building internal agents focused on simulating attacker lateral movement, we discovered through direct client feedback that they perceived these agents as potential security vulnerabilities acting inside their own internal network. This critical realization prompted us to re-evaluate our strategy, emphasizing external red-team attack simulation. Instead of pushing internal automated agents that might create uncertainty, we shifted our focus toward external red team simulation. Simulating attacker tooling gives us a much better idea of the actual attack surface and likely methods to exploit vulnerabilities. This evolution ensures that risk reduction remains the foundation of every interaction, proving that our commitment to client security and peace of mind outweighs any operational convenience.

VerifiedThreat at a glance

MRR
$10-50k
Target market (B2B/B2C)
Business
Pricing
From $99/mo to $989/mo
Free trial
Yes
Growth model (Product/Sales)
Sales led
Uses AI
Yes

VerifiedThreat SEO metrics

Domain rank
5
Referring domains
1