Continuous Never Existed: Cytix Co-Founder Ben Armstrong on Why the Rebrand Isn't Really a Pivot
At Black Hat 2026, we sat down with Ben Armstrong, co-founder of Cytix, days after the company relaunched its brand from a "security testing" company to a "software change risk" company. Ben explains why it's a repositioning rather than a pivot, where a fresh funding round is going, and why he rates the UK as a serious place to build a cybersecurity company.
Cytix co-founder Ben Armstrong joined Aspiron Search at Black Hat 2026, days into a full brand relaunch. Highlights below.
From Security Testing to Software Change Risk
Cytix's new positioning challenges their original perspective: the company has "stopped being a security testing company and started being a software change risk company." Ben reframes what that means. "Nothing's fundamentally changed about what we do. We've just realized more specifically all the different ways people use our product," he said. "When you put a security lens on top of a system like Jira or ServiceNow, security testing becomes easier to focus as a result. And so we've just moved our attention to the step earlier in the workflow."
The clarity came around RSA, roughly four months earlier. Cytix had partners like NCC Group and KPMG, enterprise customers fixing change management, and others buying purely for testing. "I had to join the dots: what connects these things? The missing link was change intelligence, change risk," Ben said. "Software change is a fundamental problem for security teams, like identity, like cloud. There's never really been a platform for it."
Why "Continuous" Testing Was Always a Myth
Cytix's roots were in penetration testing; Ben's co-founder Tom spent his whole career in it, and the idea for Cytix came from a limit the industry rarely says out loud. "We felt like 'continuous' can't exist. You can't test every feature in every system, every minute of every day," Ben said. "Applications change all the time, so why not use those changes to create micro-tests that run continuously."
That change-detection engine, built on AI from day one, is what turned Cytix into a change-risk platform. It also explains a new use case: helping teams decide where to point pentesting agents. "You can't run them on every pull request, it's too expensive," Ben said. "You need to understand the risk of the changes first."
Letting the Booth Do the Talking
Repositioning a product this broad creates its own problem: what do you say to someone who walks up to the stand? Cytix's answer was to stop pitching a category and ask a question instead. "If I said the term 'software change risk', what does that mean to you?" Ben said. It's a deliberate exit from a crowded field of DAST, SAST, pentesting, and bug bounty vendors all selling the same message at Black Hat.
Hiring for the Next Stage
Cytix has just closed a new funding round, and the first money is going to operations, not sales. "Until last week, we didn't have a single person in the business who wasn't a seller or a dev," Ben said. The first ops hire should free up roughly 40% of Tom's time for building the company rather than running it.
The second priority is go-to-market, starting small: "I need bright, hungry salespeople. We've already hired two, with a longer-term target of around six.” Ben doesn't expect the positioning to be perfect first time. "If I'm 80% right, you'll kill it in this industry. If I'm 60% right, I'll be thrilled."
Building From the UK
Ben pushed back on the idea that being UK-based is a disadvantage against better-funded US and Israeli rivals. "Some of the brightest, sharpest people are in the UK, and you can get that level of talent for less funding and still produce the same output as a business with double the money," he said. He also sees the UK as groundwork for US expansion: "It's so closely aligned. If you do well in the UK, it's much more likely you'll do well in the US." Cytix's customer base is roughly 70/30 UK to global today, a split Ben expects to shift through partnerships like NCC Group.
FAQ
What is Cytix? A UK-founded company building a software change risk platform, using AI to understand the risk in software change.
Why did Cytix rebrand? Customers were already using the platform beyond testing, for governance and deciding which changes warrant a pentest, so the positioning caught up to how it was actually being bought.
How is Cytix using its new funding round? First on an operations hire to free up founder time, then on a small go-to-market team growing from three sellers toward around six.