AI DEFENCEBY ALTARI SYSTEMS
Menu

Coverage / Vulnerability & risk

AI vulnerability management grounded in real exposure.

AI vulnerability management should connect a weakness to the environment where it exists. AI Defence is designed to assess vulnerabilities in operating systems, packages, dependencies, images and services, then prioritise findings using exposure and operational context.

IN DEVELOPMENTExplore the specified scope. See capability availability.

Connect the advisory to the affected asset

A useful vulnerability finding identifies the affected component and version, where it is deployed and the evidence supporting the match. The specification covers OS and library CVEs, application dependencies, containers, web servers, databases and network services. It also covers insecure defaults, deprecated protocols and unsupported software.

Version-based evidence can be incomplete, particularly where packages carry backported fixes or the deployed component differs from the repository definition. An uncertain match should be reported as uncertain and investigated rather than converted into a definitive exposure claim.

Use severity alongside exposure and consequence

CVSS describes technical severity; it does not by itself describe the business risk of a deployment. AI Defence’s specified correlation considers exploitability, internet exposure, process privilege, business importance, possible lateral movement, known exploit evidence and compensating controls.

Consider two instances of the same vulnerable service. One is public, privileged and connected to production data. The other is isolated in a non-production environment with restricted access. The vulnerability may be identical while the urgency and appropriate remediation plan differ.

Illustrative risk model: internet exposure + vulnerable service + known exploit evidence + elevated privilege can justify urgent investigation. It is not evidence of a confirmed compromise.

Treat resolution as an evidence-backed state

A recommended fix could involve a package update, configuration restriction, dependency repair or removal of an unnecessary service. The chosen response needs customer authorisation and operational planning. Where a source change is required, it should proceed through the project’s review and test controls.

Verification should confirm the corrected component or configuration is actually deployed and that the original exposure is resolved. The baseline then needs updating through the governed workflow. New advisories and newly vulnerable software remain targets for continuous detection.

Questions answered

Does a critical CVSS score always mean the first fix?

A critical score deserves attention, but prioritisation also requires evidence about exploitability, reachability, privileges and business impact. Compensating controls should be documented rather than assumed.

Which vulnerability feeds are integrated?

The specification requires vulnerability and known-exploit context. Specific feed integrations and refresh intervals have not been established here as generally available capabilities.

Start with understanding

What does your environment need to defend?

Discuss the assessment scope, current capabilities and the control you need with Altari Systems.

Talk to Altari