Sophos, a global
cybersecurity leader, announced Exploit Path Verification (EPV), a new
capability that will be built into Sophos Managed Risk to help security teams
better prioritize and manage exploitable vulnerabilities in their environment.
The capability will be built with OpenAI's GPT cyber models through the
Daybreak Defense Network, to return verified, evidence-backed verdicts that
give defenders the clarity they need to fix the exposures that matter first.
Availability will be announced at a later date.
Security teams face
a widening gap between the vulnerabilities they can find and the ones they can
fix. Scanners surface thousands of exposures and severity scores and rank them,
but a severity score cannot tell whether a critical flaw sits behind a control
that blocks it, or whether two low-severity findings chain into the path that
leads to a breach. As a result, security teams often patch by generic score,
rather than by whether an attacker could reach and use a flaw in their specific
environment.
Sophos is designing
EPV to close that gap. It is being built to reason over asset and patch state,
endpoint protection policy, network reachability, identity and privilege facts,
and known exploit availability, and returns a clear evidence-backed exploitability
verdict:
Confirmed
Exploitable
Blocked by a
Control
Not Reachable
Insufficient
Evidence
EPV will also be
designed to identify chained paths where multiple lower-severity findings
combine into one exploitable route, assess whether a control blocks a technique
class or only a common public proof of concept, and draft remediation text
ready for a ticket.
The capability will
be advisory and additive by design. Every verdict is labeled as AI-generated
with its evidence visible, and Sophos analysts review the results.“One of the
most common challenges we hear from security teams today is the volume of
findings they need to sift through, and the lack of clarity of which findings
matter most, or in other words, put them at greatest risk,” said John Peterson,
chief technology officer, Sophos. “Exploit Path Verification is being built to
make it clear what in their environment is reachable by an attacker, with the
evidence to prove it, so they fix what counts first.”
EPV extends Sophos'
work with OpenAI. Through the OpenAI Daybreak Defense Network (formerly OpenAI
Daybreak Cyber Partner Program), which Sophos joined in June 2026, the company
brought frontier cyber models into MDR investigation, advisory assessments, and
workflows that help customers discover, validate, and remediate exposure. EPV
will build on that work inside a product customers already run. OpenAI's GPT
cyber models provide frontier reasoning to help assess exploitability. Sophos
supplies the environment-specific evidence and product controls, and its
analysts review the results delivered to customers.
“Our goal through
the OpenAI Daybreak Defense Network is to give defenders the advantage of
frontier AI, safely,” said McCall McIntyre, Head of Global Cyber Partnerships,
OpenAI. “Sophos has been a thoughtful partner since joining the program, and
Exploit Path Verification is a clear example of frontier reasoning applied to a
real defensive problem, with the guardrails that responsible deployment
demands.”
Sophos defends more
than 625,000 organizations worldwide, including 40,000 managed detection and
response (MDR) customers across enterprise, mid-market, and commercial
segments, delivered through one of the industry's largest partner ecosystems.
That reach is central to EPV's purpose. Verified exploitability should not be a
capability reserved for the largest security teams with the deepest budgets.
EPV is in
development for enterprise and mid-market business customers of Sophos Managed
Risk. Sophos will announce availability, including early access and general
availability timing, at a later date.
Leave A Comment