Skip to main content
Why Aspiron
For candidates
Vacancies
CyberBytes
Resources
Contact Us
Group
Group
Why Aspiron
For candidates
Vacancies
CyberBytes
Resources
Contact Us

Continuous Never Existed: Cytix Co-Founder Ben Armstrong on Why the Rebrand Isn't Really a Pivot

Written by: 
Amy McLean

Continuous Never Existed: Cytix Co-Founder Ben Armstrong on Why the Rebrand Isn't Really a Pivot

At Black Hat 2026, we sat down with Ben Armstrong, co-founder of Cytix, days after the company relaunched its brand from a "security testing" company to a "software change risk" company. Ben explains why it's a repositioning rather than a pivot, where a fresh funding round is going, and why he rates the UK as a serious place to build a cybersecurity company.

Cytix co-founder Ben Armstrong joined Aspiron Search at Black Hat 2026, days into a full brand relaunch. Highlights below.

‍

From Security Testing to Software Change Risk

Cytix's new positioning challenges their original perspective: the company has "stopped being a security testing company and started being a software change risk company." Ben reframes what that means. "Nothing's fundamentally changed about what we do. We've just realized more specifically all the different ways people use our product," he said. "When you put a security lens on top of a system like Jira or ServiceNow, security testing becomes easier to focus as a result. And so we've just moved our attention to the step earlier in the workflow."

The clarity came around RSA, roughly four months earlier. Cytix had partners like NCC Group and KPMG, enterprise customers fixing change management, and others buying purely for testing. "I had to join the dots: what connects these things? The missing link was change intelligence, change risk," Ben said. "Software change is a fundamental problem for security teams, like identity, like cloud. There's never really been a platform for it."

‍

Why "Continuous" Testing Was Always a Myth

Cytix's roots were in penetration testing; Ben's co-founder Tom spent his whole career in it, and the idea for Cytix came from a limit the industry rarely says out loud. "We felt like 'continuous' can't exist. You can't test every feature in every system, every minute of every day," Ben said. "Applications change all the time, so why not use those changes to create micro-tests that run continuously."

That change-detection engine, built on AI from day one, is what turned Cytix into a change-risk platform. It also explains a new use case: helping teams decide where to point pentesting agents. "You can't run them on every pull request, it's too expensive," Ben said. "You need to understand the risk of the changes first."

‍

Letting the Booth Do the Talking

Repositioning a product this broad creates its own problem: what do you say to someone who walks up to the stand? Cytix's answer was to stop pitching a category and ask a question instead. "If I said the term 'software change risk', what does that mean to you?" Ben said. It's a deliberate exit from a crowded field of DAST, SAST, pentesting, and bug bounty vendors all selling the same message at Black Hat.

‍

Hiring for the Next Stage

Cytix has just closed a new funding round, and the first money is going to operations, not sales. "Until last week, we didn't have a single person in the business who wasn't a seller or a dev," Ben said. The first ops hire should free up roughly 40% of Tom's time for building the company rather than running it.

The second priority is go-to-market, starting small: "I need bright, hungry salespeople. We've already hired two, with a longer-term target of around six.” Ben doesn't expect the positioning to be perfect first time. "If I'm 80% right, you'll kill it in this industry. If I'm 60% right, I'll be thrilled."

‍

Building From the UK

Ben pushed back on the idea that being UK-based is a disadvantage against better-funded US and Israeli rivals. "Some of the brightest, sharpest people are in the UK, and you can get that level of talent for less funding and still produce the same output as a business with double the money," he said. He also sees the UK as groundwork for US expansion: "It's so closely aligned. If you do well in the UK, it's much more likely you'll do well in the US." Cytix's customer base is roughly 70/30 UK to global today, a split Ben expects to shift through partnerships like NCC Group.

‍

FAQ

What is Cytix? A UK-founded company building a software change risk platform, using AI to understand the risk in software change.

Why did Cytix rebrand? Customers were already using the platform beyond testing, for governance and deciding which changes warrant a pentest, so the positioning caught up to how it was actually being bought.

How is Cytix using its new funding round? First on an operations hire to free up founder time, then on a small go-to-market team growing from three sellers toward around six.

Tablet of Contents

TOC Element

Recent Posts

Securing the Agentic Workforce: The EDR for AI Agents - Evoke Security

August 28, 2026

AI in Cybersecurity: The AI vs AI Arms Race Reshaping Security in 2026

August 5, 2026

Building a Cybersecurity GTM Team from Seed to Series B

August 4, 2026

North America

+1 315 556 2555

United Kingdom

+44 20 4530 6936

Company

Why Aspiron?
For Candidates
CyberBytes

Useful Links

Resources
Contact Us
Aspiron Group

Support

Privacy Policy
Cookies Policy
Terms & Conditions

North America

+1 315 556 2555

United Kingdom

+44 20 4530 6936

© {{year}}  Aspiron Search Limited – All rights reserved