Vulnerability Management
Ido Geffen, serial cybersecurity entrepreneur, had this to say about vulnerability management: “Everyone knows that finding impactful vulnerabilities is more art than science. It requires intuition and expertise that can’t be easily replicated. Automated scanners flood teams with endless alerts, most of them irrelevant.
And for years, that was the limit. We all knew the problem but there was no way to scale the intuition of a human pentester. That changed with the new generation of AI. For the first time, AI can actually reason — understand flows, spot inconsistencies, chain ideas, explore attack paths, and think before acting. It means we can finally bring human-level insight to a machine-level scale.
The next evolution in security isn’t competing over who finds more vulnerabilities. It’s about finally being able to find the ones that actually matter to your business and to do it continuously.”
Finding, tracking, prioritizing, and tasking remediation of vulnerabilities is as onerous a task as responding to alerts, just at a different time scale (alerts: today — vulnerabilities: whenever). If the desired end state from SOC Automation is 100% triage of alerts, the goal of AI-assisted vulnerability management is zero known vulnerabilities. Don’t forget that the entire field of vulnerability management is set up to fail because there is no solution for the next undiscovered vulnerability, the so-called zero days. IT-Harvest tracks 368 vulnerability management products from 272 vendors.
It is no surprise that the problem of managing the vulnerability remediation process has led to the creation of 29 startups that have deployed AI to tackle the problem.
| Company | Country | Investment ($M) | Employees |
|---|---|---|---|
| Zafran | USA | $70.5M | 148 |
| Sweet Security | Israel | $120M | 99 |
| Root | USA | $37.6M | 48 |
| AISLE | Czechia | - | 45 |
| Maze | United Kingdom | $31M | 37 |
| Cogent | USA | $11M | 34 |
| depthfirst | USA | - | 31 |
| Mindgard | United Kingdom | $12.47M | 25 |
| DefectDojo | USA | $7M | 22 |
| Emperical Security | USA | $11.94M | 21 |
| Symbiotic Security | USA | $3M | 21 |
| Zest Security | Israel | $5M | 21 |
| ArmourZero | Singapore | - | 20 |
| Dux | USA | - | 20 |
| RedRok | USA | - | 16 |
| Javelin | USA | - | 12 |
| Kikimora.io | Bulgaria | $1.28M | 11 |
| Specular | USA | - | 11 |
| krixo | Canada | - | 9 |
| STYRK | USA | $3.5M | 8 |
| ZeroPath | USA | $5.5M | 7 |
| Aisy | United Kingdom | - | 6 |
| Octosight | USA | - | 6 |
| MindFort | USA | $0.5M | 4 |
| MaayaAI | USA | - | 3 |
| ThreatCanary | USA | - | 3 |
| Mountain Theory | USA | - | 2 |
| Artiphishell | USA | - | - |
| Transilience.AI | USA | - | 13 |
