CHAPTER 11

Vulnerability Management

Ido Geffen, serial cybersecurity entrepreneur, had this to say about vulnerability management: “Everyone knows that finding impactful vulnerabilities is more art than science. It requires intuition and expertise that can’t be easily replicated. Automated scanners flood teams with endless alerts, most of them irrelevant.

And for years, that was the limit. We all knew the problem but there was no way to scale the intuition of a human pentester. That changed with the new generation of AI. For the first time, AI can actually reason — understand flows, spot inconsistencies, chain ideas, explore attack paths, and think before acting. It means we can finally bring human-level insight to a machine-level scale.

The next evolution in security isn’t competing over who finds more vulnerabilities. It’s about finally being able to find the ones that actually matter to your business and to do it continuously.”

Finding, tracking, prioritizing, and tasking remediation of vulnerabilities is as onerous a task as responding to alerts, just at a different time scale (alerts: today — vulnerabilities: whenever). If the desired end state from SOC Automation is 100% triage of alerts, the goal of AI-assisted vulnerability management is zero known vulnerabilities. Don’t forget that the entire field of vulnerability management is set up to fail because there is no solution for the next undiscovered vulnerability, the so-called zero days. IT-Harvest tracks 368 vulnerability management products from 272 vendors.

It is no surprise that the problem of managing the vulnerability remediation process has led to the creation of 29 startups that have deployed AI to tackle the problem.

CompanyCountryInvestment ($M)Employees
ZafranUSA$70.5M148
Sweet SecurityIsrael$120M99
RootUSA$37.6M48
AISLECzechia-45
MazeUnited Kingdom$31M37
CogentUSA$11M34
depthfirstUSA-31
MindgardUnited Kingdom$12.47M25
DefectDojoUSA$7M22
Emperical SecurityUSA$11.94M21
Symbiotic SecurityUSA$3M21
Zest SecurityIsrael$5M21
ArmourZeroSingapore-20
DuxUSA-20
RedRokUSA-16
JavelinUSA-12
Kikimora.ioBulgaria$1.28M11
SpecularUSA-11
krixoCanada-9
STYRKUSA$3.5M8
ZeroPathUSA$5.5M7
AisyUnited Kingdom-6
OctosightUSA-6
MindFortUSA$0.5M4
MaayaAIUSA-3
ThreatCanaryUSA-3
Mountain TheoryUSA-2
ArtiphishellUSA--
Transilience.AIUSA-13