Sophos has announced Exploit Path Verification (EPV), a new capability being developed for Sophos Managed Risk to help security teams identify which vulnerabilities attackers can actually reach and exploit within their environments.
The capability will be built using OpenAI’s GPT cyber models through the OpenAI Daybreak Defense Network. It is designed to move vulnerability management beyond conventional severity scores by providing evidence-backed assessments of whether a security exposure can lead to an attack.
Security teams often face thousands of vulnerabilities identified through scanning tools, making it difficult to determine which issues pose the greatest real-world risk. Sophos says a vulnerability’s severity alone does not indicate whether an attacker can reach it, whether existing controls can block exploitation, or whether multiple lower-severity weaknesses can be combined to create an attack path.
EPV is being designed to assess factors including asset and patch status, endpoint protection policies, network reachability, identity and privilege information, and known exploit availability. Based on this information, the capability will provide four verdicts: Confirmed Exploitable, Blocked by a Control, Not Reachable, or Insufficient Evidence.
The system is also expected to identify attack paths where several lower-severity vulnerabilities can be chained together. It will assess whether security controls can prevent specific attack techniques and generate remediation recommendations that can be used directly in security tickets.
Sophos said EPV will remain an advisory capability, with AI-generated verdicts clearly labelled and supporting evidence made visible to customers. Sophos analysts will also review the results before they are delivered.
“One of the most common challenges we hear from security teams today is the volume of findings they need to sift through, and the lack of clarity of which findings matter most, or in other words, put them at greatest risk,” said John Peterson, Chief Technology Officer, Sophos. “Exploit Path Verification is being built to make it clear what in their environment is reachable by an attacker, with the evidence to prove it, so they fix what counts first.”
The announcement builds on Sophos’ collaboration with OpenAI through the OpenAI Daybreak Defense Network, which the cybersecurity company joined in June 2026. The partnership has already brought advanced cyber models into areas including managed detection and response investigations, advisory assessments and exposure remediation workflows.
Under the new capability, OpenAI’s GPT cyber models will provide reasoning to assess exploitability, while Sophos will supply environment-specific data and security controls. Sophos analysts will review the resulting assessments.
“Our goal through the OpenAI Daybreak Defense Network is to give defenders the advantage of frontier AI, safely,” said McCall McIntyre, Head of Global Cyber Partnerships, OpenAI. “Sophos has been a thoughtful partner since joining the programme, and Exploit Path Verification is a clear example of frontier reasoning applied to a real defensive problem, with the guardrails that responsible deployment demands.”
Sophos currently protects more than 625,000 organisations worldwide, including 40,000 managed detection and response customers. The company said EPV is being developed for enterprise and mid-market customers using Sophos Managed Risk, with availability and early-access details to be announced at a later date.
Send news announcements/press releases to:
editor@thefoundermedia.com
