
Six packaged skills turn a plain-English question into finished security analysis. No dashboard, no separate login, no context switch.
ATLANTA, Sept. 22, 2026 /PRNewswire/ -- Siemba, an offensive security company that combines attack surface mapping, autonomous testing and expert-led penetration testing in one continuous program, today announced the general availability of Siemba MCP. Siemba MCP is a Model Context Protocol server, distributed as a single plugin containing the connector and six named skills, that connects Siemba's security data and testing capabilities directly to AI assistants. Security and engineering teams can ask a plain-English question inside their existing AI client and get finished security analysis back, without opening a separate console.
Each of the six skills is invoked with a simple command and runs a packaged workflow built on the Siemba platform's underlying test orchestration and analysis tools.
"You can now run pentests by chatting with your LLM. The MCP server gives your assistant the platform itself, not a summary of it," said Kannan Udayarajan, CEO of Siemba. "You name a target, and Siemba enumerates it, creates the right test suite, and starts running, all automatically. You can then deploy our skills to do the next level of expert analysis and reporting. That's a meaningfully different way of working than logging into a dashboard to go find the same answer and then doing your analysis and reporting on spreadsheets."
What Siemba MCP can do: six skills
Siemba MCP ships with six skills at general availability:
- Test Analysis explains a running, failed or completed penetration test in plain language. The skill reads login screenshots to diagnose the most common cause of a failed authenticated run: a bad credential or an unexpected multi-factor prompt.
- Kill Chain maps individual findings into the attack paths they form. Siemba MCP rates each chain by its weakest link rather than by raw severity, then names the single fix that breaks the most chains at once. This reasoning across separate, individually low-severity findings is the skill that best demonstrates what an AI assistant adds to a security workflow.
- Critical Briefing pulls every Critical and High finding across the estate into one executive briefing, ranked by Siemba's risk score, with regressed findings called out separately from new ones.
- Remediation Plan groups findings that share a root cause into a single fix, then sequences the work list by leverage: risk removed per unit of effort.
- Attack Surface reviews everything an organization exposes to the internet, including domains, subdomains, certificates, TLS configuration, registrars, geographies and monitoring coverage, and names the gaps between what is live and what is actually being watched.
- CISO Report generates a board-ready posture report that leads with direction of travel (improving, stable or worsening) and maps every finding to a specific control across seven compliance frameworks: ISO 27001, HIPAA, OWASP, GDPR, CMMC, NIST SP 800-53 Rev. 5 and PCI DSS v4.0.
How Siemba MCP is secured
Every call through Siemba MCP is secured by OAuth 2.1 with PKCE, requires multi-factor authentication, uses rotating tokens, is rate-limited and is scoped to the requesting account only. If a session is compromised, access is contained to one user's permissions, on that customer's assets only, with non-destructive actions only, for a maximum of one hour, fully logged.
Availability
Siemba MCP is available today to customers on the Siemba platform bundled at no additional cost. It is compatible with MCP-enabled AI clients and setup instructions and the server endpoint are at https://mcp.app.siemba.com/#connect
About Siemba
Siemba combines attack surface mapping, autonomous dynamic testing, AI-driven vulnerability assessment, and expert-led penetration testing into one continuous program. Its certified in-house pentesters are trusted by the Big 4, and every fix is revalidated automatically on the platform and expert-signed on engagements. Siemba covers web, mobile, cloud, and AI systems including large language models and AI agents. Headquartered in Alpharetta, Georgia, Siemba has been named a Sample Vendor in the Gartner® Hype Cycle™ for Application Security, the Gartner Hype Cycle for Security Operations, and the Gartner Hype Cycle for XaaS (Everything as a Service) in 2024, 2025 and 2026.
SOURCE Siemba
Share this article