News

Siemba MCP Brings Offensive Security Testing into Your AI Assistant

Written by Lavanya Chandrasekharan | Sep 25, 2026, 10:09:42 AM

September 2026 · Siemba News

Siemba MCP is now generally available. It's a Model Context Protocol (MCP) server that connects the Siemba offensive security platform directly to MCP-enabled AI assistants. It ships as a single plugin containing the connector and six skills: Test Analysis, Kill Chain, Critical Briefing, Remediation Plan, Attack Surface and CISO Report and more.

Security and engineering teams can ask a question in plain English and get finished security analysis back, without opening a dashboard or logging in separately. Siemba MCP is included at no additional cost for Siemba platform customers.

What is Siemba MCP?

Siemba MCP is a Model Context Protocol server that gives AI assistants direct access to Siemba's security data and testing capabilities. MCP is an open standard that lets AI clients connect to external tools and data. With Siemba MCP, the assistant works with the platform itself rather than a summary of it. Siemba announced general availability on September 22, 2026.

What can you do with Siemba MCP?

You can start and analyze security testing through a conversation. You name a target, and Siemba enumerates it, builds the appropriate test suite and starts running it automatically. You can then use Siemba's skills for expert-level analysis and reporting on the results.

"You can now run pentests by chatting with your LLM," said Kannan Udayarajan, CEO of Siemba. "The MCP server gives your assistant the platform itself, not a summary of it."

What are the six Siemba MCP skills?

Each skill is invoked with a simple command and runs a packaged workflow on top of the Siemba platform's test orchestration and analysis tools.

  • Test Analysis explains a running, failed or completed penetration test in plain language. When an authenticated run fails, it reads the login screenshots to diagnose the most common causes: a bad credential or an unexpected multi-factor prompt.
  • Kill Chain connects individual findings into the attack paths they create. Each chain is rated by its weakest link rather than by raw severity, and the skill names the single fix that breaks the most chains at once. This is where AI reasoning adds the most value, because it links findings that look low-severity on their own.
  • Critical Briefing gathers every Critical and High finding across your estate into one executive briefing. Findings are ranked by Siemba's risk score, and regressed findings are listed separately from new ones.
  • Remediation Plan groups findings that share a root cause into a single fix. It then orders the work by leverage, meaning how much risk each fix removes for the effort it takes.
  • Attack Surface reviews everything you expose to the internet, including domains, subdomains, certificates, TLS configuration, registrars, geographies and monitoring coverage. It points out the gaps between what's live and what's actually being watched.
  • CISO Report produces a board-ready posture report. It opens with the direction of travel (improving, stable or worsening) and maps every finding to a specific control across seven compliance frameworks: ISO 27001, HIPAA, OWASP, GDPR, CMMC, NIST SP 800-53 Rev. 5 and PCI DSS v4.0.

How is Siemba MCP different from a security dashboard?

Siemba MCP brings the answer to where you already work. With a dashboard, you log in, find the data, and then do your analysis and reporting separately, often in spreadsheets. With Siemba MCP, you ask the question in your AI client and get finished analysis back. There's no console to open, no separate login and no switching between tools.

Is Siemba MCP secure?

Yes. Every call through Siemba MCP is secured with OAuth 2.1 with PKCE and requires multi-factor authentication. Tokens rotate, calls are rate-limited, and access is scoped to the requesting account only.

Siemba MCP is also designed to limit the damage if a session is compromised. Access stays contained to:

  • one user's permissions,
  • that customer's assets only,
  • non-destructive actions only,
  • a maximum of one hour,

and all activity is fully logged.

Who can use Siemba MCP, and what does it cost?

Siemba MCP is available now to customers on the Siemba platform, bundled at no additional cost. It works with MCP-enabled AI clients. Setup instructions and the server endpoint are at mcp.app.siemba.com.

 

About Siemba

Siemba is an offensive security company headquartered in Alpharetta, Georgia. It combines attack surface mapping, autonomous dynamic testing, AI-driven vulnerability assessment and expert-led penetration testing in one continuous program. Its coverage includes web, mobile, cloud and AI systems, including large language models and AI agents. Siemba has been named a Sample Vendor in the Gartner® Hype Cycle™ for Application Security, Security Operations, and XaaS in 2024, 2025 and 2026.

 

Frequently asked questions

What is an MCP server?
An MCP server uses the Model Context Protocol, an open standard, to let AI assistants connect to external tools and data. Siemba MCP connects AI assistants to the Siemba offensive security platform.

Can I run a penetration test from an AI assistant with Siemba MCP?
Yes. You name a target, and Siemba enumerates it, creates the right test suite and starts testing automatically.

Which compliance frameworks does the CISO Report cover?
It covers ISO 27001, HIPAA, OWASP, GDPR, CMMC, NIST SP 800-53 Rev. 5 and PCI DSS v4.0.

What happens if a Siemba MCP session is compromised?
Access is limited to one user's permissions, on that customer's assets only, with non-destructive actions only, for a maximum of one hour, and all activity is logged.

How much does Siemba MCP cost?
It's included at no additional cost for Siemba platform customers.