Sophos Unveils EPV to Improve Management of Exploitable Vulnerabilities

sophos sistema defensa de ciberseguridad

Sophos, a company specializing in cybersecurity solutions, has announced the development of Exploit Path Verification (EPV), a new capability that will become part of Sophos Managed Risk. The technology aims to help security teams identify and prioritize the vulnerabilities that pose a real risk to their systems.

To build EPV, Sophos will draw on OpenAI’s GPT cyber models through the Daybreak Defense Network. The goal is to provide verified, evidence-backed exploitability assessments so security leaders can determine which vulnerabilities require the most immediate action.

One of the main problems security teams currently face is the sheer number of vulnerabilities they have to manage. While security scanners can locate thousands of flaws and assign each one a severity score, those scores don’t always reflect the actual risk present in a given environment. For example, a vulnerability rated critical might already be neutralized by a protection mechanism, while several low-severity vulnerabilities could be chained together to let an attacker reach a sensitive target.

As a result, patching decisions in many cases end up relying mainly on the severity scores assigned by the tools, without sufficiently analyzing the real chances of exploitation within each infrastructure.

With EPV, Sophos aims to deliver a more complete analysis tailored to each environment. The capability will factor in elements such as device status and patch levels, endpoint protection policies, network exposure and accessibility, available identities and privileges, and the existence of known exploits. With all of that information, the system will be able to determine more precisely whether a vulnerability can be exploited and back up its assessment with evidence.

Another planned capability is detecting exploit chains — situations where several seemingly low-severity vulnerabilities can be combined to create an effective attack path. EPV will also be able to determine whether a security mechanism blocks a given attack technique broadly, or only prevents a specific published proof of concept.

Finally, the tool will let teams generate remediation recommendations ready to be added directly to reports or incident reviews, making it easier for security teams to act and helping them focus their efforts on the vulnerabilities that carry the greatest real risk.

This capability is advisory and complementary by design. Every verdict is labeled as AI-generated, with its supporting evidence visible, and Sophos analysts review the results.

“One of the most common challenges security teams tell us about today is the volume of findings they have to sift through and the lack of clarity about which ones matter most — in other words, which expose them to the greatest risk,” says John Peterson, Chief Technology Officer at Sophos. “Exploit Path Verification is being built to make clear which parts of your environment are reachable by an attacker, with the evidence to prove it, so teams can fix what really matters first.”

EPV expands Sophos’s collaboration with OpenAI. Through the OpenAI Daybreak Defense Network (formerly known as the OpenAI Daybreak Cyber Partner Program), which Sophos joined in June 2026, the company has been incorporating cutting-edge cyber models into MDR investigations, advisory assessments, and workflows that help customers detect, validate, and remediate vulnerabilities. EPV builds on that work within a product customers already use. OpenAI’s GPT cyber models provide state-of-the-art reasoning to help assess vulnerabilities. Sophos contributes environment-specific evidence and product controls, and its analysts review the results delivered to customers.

“Our goal through the OpenAI Daybreak Defense Network is to give defenders the edge of frontier AI, safely,” says McCall McIntyre, Head of Global Cyber Alliances at OpenAI. “Sophos has been a deeply engaged partner since joining the program, and Exploit Path Verification is a clear example of frontier reasoning applied to a real defensive problem, with the safeguards that responsible deployment demands.”

EPV builds on Sophos Managed Risk’s existing IASM capability, which already lets teams view vulnerabilities from an attacker’s perspective without credentials, and follows a broader industry pattern of pairing frontier AI models with security tooling to close the gap between finding a vulnerability and confirming it can actually be exploited, as Cloudflare has also done recently with OpenAI’s Daybreak models.

Scroll to Top