AI for IT and Cybersecurity

The Best New IT and Cybersecurity Tools (May 2026)

Enterprise IT is being rebuilt on both ends — agentic ITSM and AI-aware security on top, mainframe modernization and data-center physics underneath. Here are twelve tools we're watching this month, across cybersecurity, ITSM, legacy modernization, and infrastructure.

PL
Product Lookout Team·May 16, 2026
Depiction of a hypothetical AI-powered IT and cybersecurity tool, protecting servers

The new wave of IT and cybersecurity tools

Enterprise IT is getting rebuilt from both ends at once, and the new IT and cybersecurity tools landing this month show it. On the user-facing side, AI-native ITSM platforms and conversational helpdesks are quietly retiring the ticket queue. On the threat side, AI-aware security tools are catching up to a world of deepfake phishing, autonomous bot traffic, and the awkward fact that a good chunk of what hits your stack isn't human anymore. Underneath all that, the unglamorous work grinds on: a mainframe-modernization wave that finance and government can no longer keep postponing, and a data-center buildout that just slammed into the laws of thermodynamics.

We stuck to tools an enterprise IT or security team would actually deploy. AI infrastructure (LLM gateways, vector DBs, agent control planes) and pure developer tooling didn't make the cut here. Both are worth your attention, but they earn their own posts.

How we picked these tools

We scanned every IT-tagged product ingested into Product Lookout over the last thirty days, then put each one through three filters:

  1. Built for the enterprise IT or security buyer. A CIO, CISO, IT director, or security engineer should glance at it and immediately know where it slots in.
  2. Solves a real, recurring problem. Not a novelty, but a workflow, threat, or pile of legacy that's eating real budget and headcount right now.
  3. A specific point of view. Each one has a clear thesis about which corner of the IT stack is most broken and worth rebuilding from scratch.

Cybersecurity in the AI era

The threat surface moved faster than the defenses. Three products this month take different swings at the same question: what does security even mean when the attackers, the traffic, and increasingly the testers are all AI-driven?

Frame Security

Frame Security is an AI-powered human risk platform: personalized security awareness training, deepfake phishing simulations, and per-employee risk scoring. The "human risk" framing is exactly right for 2026. The perimeter vanished years ago, and the real attack surface is the employee who's one convincing voice clone away from wiring money to a fake CFO. Frame builds the training, runs the simulations (deepfakes included), and hands security teams a risk score per person so they know where to focus.

Why now: the marginal cost of a believable phishing email or voice clone has dropped to roughly zero, while the average employee's ability to spot one hasn't budged. That asymmetry has to get closed somewhere, and training is the cheapest place to start.

Cerberus

Cerberus is an AI-powered penetration testing agent that leans on formal proof-carrying execution to mathematically enforce scope, blocking destructive or out-of-scope actions before they happen. AI pen testing is one of the more obvious places to point agents (humans are scarce, attacks are infinite), but the obvious objection has slowed everyone down: an autonomous agent loose in your production environment, what could possibly go wrong? Cerberus answers with proofs of scope. If those proofs survive an audit, this is the version of AI pen testing that risk and compliance teams will actually sign off on.

Known Agents

Known Agents is a bot and AI-agent traffic analytics platform that gives website owners real-time visibility into crawlers, scrapers, and agents, with LLM referral tracking, automatic robots.txt management, bad-bot blocking, and agent identity verification. It sits right where security, web operations, and the new SEO overlap. Every IT team running a public web property now has to answer one question: which AI agents are allowed to hit our site, and which aren't? Known Agents is the most credible answer we've come across so far.

AI-native IT service desk

The other big shift in IT this year is on the service-desk side. "Submit a ticket, wait three days" is finally being rebuilt around the channels employees actually live in, Slack and Teams, with AI agents that can take the action rather than just open a ticket about it.

Modern

Modern is an AI-native ITSM platform that automates the IT service desk, access management, and employee workflows through Slack and Teams. It's the platform play in a category long owned by ServiceNow and Jira Service Management. Modern's bet is that the next generation of ITSM is conversational by default, and that the economics of AI-driven first-line resolution change who can afford a real ITSM tool at all, dragging the category down-market into the mid-size enterprise.

OpenIT

OpenIT is an open-source IT helpdesk desktop app, powered by Claude Code, that handles employee Slack tickets and learns to automate resolutions over time. Think of it as the open-source counterpart to Modern: smaller scope (Slack-first, desktop app), but a solid fit for teams that want to self-host and own their data. The "learns to automate resolutions" loop is the interesting part. Most IT tickets are variations on a few dozen recurring problems, so a tool that captures a fix and replays it next time delivers exactly the compounding value IT teams are starved for.

The great legacy modernization

Mainframes, COBOL, SAP, and the rest of the trillion-dollar pile of code that runs banks, governments, and Fortune 500 ops have spent fifteen years "about to be modernized." AI is finally making the economics work. Three products this month place different bets on which legacy stack falls first, and they pair well with the broader enterprise IT and security roundup we published alongside this one.

Tessera Labs

Tessera Labs is a multi-agent AI platform for enterprise ERP modernization, data harmonization, and legacy code remediation, squeezing what used to be multi-year projects into weeks. The pitch lands on a pain point every CIO at a large company knows cold: the SAP migration that's been on the roadmap since 2019. Tessera's thesis is that the timeline was never really capped by capability. It was capped by the cost of senior consultants, and AI agents change that math.

Nova Intelligence

Nova Intelligence is an agentic AI platform for SAP teams that claims to triple developer productivity across documentation, code modernization, development, and analysis. It's more focused than Tessera (SAP only), which is either a feature or a bug depending on your stack. SAP modernization carries its own deep specificity, from ABAP to S/4HANA migration to the partner ecosystem, that a horizontal tool won't fully crack. Nova is built for the team that already lives inside that world.

Hypercubic

Hypercubic is an AI-powered mainframe modernization platform that helps enterprises understand, maintain, and transform COBOL-based legacy infrastructure. COBOL is the most extreme version of the legacy problem: the engineers who wrote it are retiring, the documentation never existed, and the systems still move trillions of dollars a day. Hypercubic is going after the financial services, government, and healthcare buyers for whom "rewrite the mainframe" has been a polite fiction for two decades.

Modern infrastructure: data center, cloud, endpoint, file storage

Beneath all of the above sits the actual physical and digital substrate, and it's having a moment. The data center is bumping against thermodynamic limits, Kubernetes secret management is still a mess, file storage is finally being rebuilt for data sovereignty, and the last-mile problem of running Windows apps on Linux desktops never really went away.

Madrone

Madrone cools data centers with a novel thermodynamic process, cutting power and water consumption by 30 percent without mechanical chillers. With AI workloads pushing data-center power demand to genuinely alarming levels, cooling efficiency has gone from line item to binding constraint. Madrone is a deep-physics bet on the unglamorous infrastructure everything else depends on. Any CIO building or expanding a data center this year should at least know the category exists.

Kloak

Kloak is an agentless Kubernetes secret manager that uses eBPF to swap credential placeholders for real secrets at the network edge. Kubernetes secret management has been a footgun forever: Vault is heavy, native Secrets aren't actually secret, and every team ends up nursing some half-built sidecar pattern. Kloak's eBPF approach is the first genuinely fresh architectural answer we've seen in a while, and it's worth a look for any platform team feeling that pain, especially the crews leaning hard on AI-driven DevOps and CI/CD tooling.

Sync-in

Sync-in is an open-source, self-hosted platform for file storage, sharing, synchronization, and real-time collaborative editing, with full data sovereignty. It's the Nextcloud problem space rebuilt with modern collaboration baked in. The buyer is the IT director at a government agency, healthcare system, or European enterprise where "we can't put this in Google Drive" is a hard constraint and the existing self-hosted options feel a decade behind.

Winpodx

Winpodx is an open-source Linux tool that runs Windows apps as native Linux windows using a containerized Windows instance and FreeRDP RemoteApp. It targets a pain mixed-OS shops know well: one legacy Windows app holding back an otherwise all-Linux fleet. This isn't a platform play, just a clean fix for an annoying problem, and the kind of thing IT teams quietly fall in love with.

Frequently asked questions

What are the best new IT and cybersecurity tools in 2026?

On the security side, Frame Security leads in human risk and phishing defense, Cerberus is the strongest AI penetration testing tool we've tested, and Known Agents is the right answer for bot and AI-traffic visibility. For ITSM, Modern (enterprise) and OpenIT (open source) are the most credible AI-native helpdesks. For legacy modernization, Tessera Labs, Nova Intelligence, and Hypercubic each lead their slice, covering ERP, SAP, and mainframe respectively. Pick based on which problem is actually draining your team's capacity.

Are AI penetration testing tools safe to run in production?

The category leaders, Cerberus being the example here, ship with formal scope guarantees, audit logs, and approval gates for any destructive action. The risk profile is closer to a scoped, automated red team than a fully autonomous agent. Introduce them the way you'd introduce any new pen test vendor: start narrow, validate the audit trail, then expand. If your governance team wants more on the controls side, our roundup of AI tools for legal, risk, and compliance is a useful companion. Treat the AI as a tool, not a magic wand.

Is AI-native ITSM ready to replace ServiceNow or Jira Service Management?

For mid-size enterprises, increasingly yes. The AI-native tools (Modern, OpenIT, and others) handle the long tail of common tickets at a unit cost the legacy platforms can't match. For very large enterprises with deeply embedded ServiceNow workflows, the migration cost is real and the replacement timeline runs in years, not months. The pragmatic pattern most CIOs are running: layer AI-native tooling on top of the existing platform for first-line resolution, and let the platform decision get re-litigated at the next contract renewal.

What is the difference between AI infrastructure tools and AI-powered IT tools?

AI infrastructure tools (vector databases, LLM gateways, agent control planes) are the picks and shovels for teams building AI products themselves. AI-powered IT tools (Modern, Frame Security, Hypercubic, and the rest) apply AI to a traditional IT or security workflow. Both are worth tracking, but they answer to different buyers, carry different risk profiles, and raise different roadmap questions. This post stays on the second category, the tools that change how an IT or security team operates day to day.

How urgent is mainframe and ERP modernization in 2026?

More urgent than it's been in a decade, thanks to two pressures compounding at once: the engineers who wrote the original systems are aging out of the workforce, and AI agent tooling has finally made the modernization economics work at sub-consulting-firm prices. The CIOs taking it seriously this year aren't the ones with the worst legacy stacks. They're the ones who can read the writing on the wall and want to move while the AI-modernization vendors still have capacity to take the work.

Where this is heading

The shape of the enterprise IT stack in 2027 is already visible in these twelve products. The help desk turns conversational and self-improving. The security training program runs deepfake simulations. The pen test becomes an audited AI agent. Bot traffic shifts from background noise to a measured, managed surface. The SAP migration that's been on the roadmap for five years actually ships. The mainframe gets a second act. The data center cools itself with physics instead of chillers. And the boring problems (secrets management, file storage, that one stubborn legacy Windows app) finally get the focused open-source fixes they always deserved.

We'll keep tracking this category on Product Lookout. If you're building or running an IT or cybersecurity product that's changing how a team works, tell us. It might land in the next post.

The Lookout newsletter

Want the next Radar list before it’s public?