This paper introduces COAST, the Cybersecurity Operations Autonomy Scale for Tooling. A framework consisting of three complementary classification components: six COAST Levels (CL0–CL5) defining the spectrum of autonomy in cybersecurity tooling from fully manual operation to full autonomous execution, supplementary Audit Levels (AL0–AL3) addressing logging and reconstructability requirements for autonomous systems, and supplementary Data Handling Levels (DH0–DH2) addressing data processing boundaries. Together, these classifications provide a shared language for tool classification, rules of engagement definition, procurement decisions, and regulatory discussion across all cybersecurity disciplines.
Download the frameworkIn many organisations, security still runs on autopilot: one penetration test per year, a report, and then a round of remedial work. But this way of working dates back to a time when software development was still predictable and straightforward.
That time is long gone. Nowadays, applications are constantly evolving. Releases, updates, and integrations follow one another at high speed, introducing new risks every single day. This is why the need is shifting from an annual pen test to Continuous Penetration Testing.
In this white paper, you will discover:


