Clearance · Credentials
Bailey Besheer.
Managing Director of Cybersecurity Services at Alacrinet.
Bailey Besheer built and leads Alacrinet's Offensive Intelligence Unit. A former Marine cyber warfare operator, ranked top 25 globally on Hack The Box, he sets the methodology, scopes every engagement personally, and sits on every readout. It is all on his LinkedIn profile.
File 01.5 · Engagement Console
LIVE · OPERATOR-LEDFile 02 · Background Brief
SUBJECT · BESHEER, B.At Alacrinet, a California-based technology firm, Bailey built and leads the Offensive Intelligence Unit. Before private-sector security, he served as a Marine cyber warfare operator. He holds CISSP, IAT III, and CSIS credentials and is ranked among the top 25 players globally on Hack The Box.
He built the OIU around one rule the industry tends to bend: the operator who scopes the engagement is the operator who runs it and the operator who briefs the executives at the end. No bait-and-switch. No junior consultants delivering work scoped by senior names. Every report carries the signature of the operator who did the work.
His work has been profiled in The Enterprise World's cover story on Alacrinet, which lands on the point he keeps making: offensive security is a discipline of judgment, not tooling, and that judgment compounds inside a single operator over years.
THE BAR OPR · STANDARD-OF-WORK“Every Alacrinet engagement is delivered by the senior operators who scoped it. No junior delivery teams, no offshore labor, no sales-engineer-to-delivery handoff. I run scoping personally, hold the engagement P&L, and sit on every readout. I'm on the technical calls, the escalation channels, and the post-engagement debriefs where clients tell us what landed and what didn't.”
Bailey Besheer, in GRC Viewpoint
File 03 · Operator Notes
Most firms get AI red-teaming exactly backwards.
By Bailey Besheer ·
The industry is racing to productize “AI red-teaming” the same way it productized pentesting twenty years ago: a checklist, a scanner, a templated PDF. I think this is going to fail for the same reason the first generation of pentest reports failed. You cannot industrialize the part that matters.
A model is not a system you can fingerprint and enumerate. It is a behavior you have to provoke. The interesting failures are not in the model weights. They are in the seams: the system prompt your engineers wrote on a Friday, the RAG corpus your sales team uploaded last quarter, the tool-use scope your platform team called “temporary” eighteen months ago. Every one of those seams was written by a human who was reasoning about the happy path. Adversarial pressure lives on the unhappy path.
The vendors selling automated “prompt injection scanners” are going to find exactly what automated SQL injection scanners found in 2008: the easy class. The interesting attacks are the multi-turn ones where the model reads a poisoned document on turn three, executes a tool call on turn seven, and exfiltrates the result on turn twelve. No scanner I have seen catches that chain, because the chain is not a pattern. It is a plan.
If you are buying AI security testing in 2026 and the vendor cannot tell you, in plain English, what the chain of intent was for each finding, you are buying the same scan-and-PDF product the industry already proved does not move the needle. Ask for the chain. Ask who wrote the chain. If the answer is “our platform,” walk.
The other half of the discipline is restraint. An LLM red team that demonstrates every exotic jailbreak it can find is a team that does not understand its customer. The board does not want a museum of failures. The board wants the two or three that would have ended badly, the operator's read on which one is the easiest to actually exploit, and the shortest path to closing them. Same bar as the rest of offensive security: attack paths over CVSS, business impact over volume, judgment over noise.
That is the bar I hold the OIU to on every engagement. It is also the bar I think will separate the AI security firms that exist in 2030 from the ones that don't.