The scope of attack targets expands
As information gathering and target exploration become more efficient, assets and organizations that were previously less likely to be prioritized as targets become increasingly exposed to attack.
Frontier AI × Vulnerability Management
Can corporate vulnerability response keep pace with AI-accelerated threats?
In the frontier AI* era, the critical defense is not simply finding more vulnerabilities.
It is making risk-based judgments and continuously completing the response they require.
That demands rethinking the vulnerability management framework itself.
* In this article, "frontier AI" refers collectively to large-scale, general-purpose AI systems that currently represent the most advanced technical capability.
01 / Background
As AI advances, the processes required to prepare an attack—gathering and analyzing vulnerability information, exploring attack targets, and building attack scenarios—are becoming more efficient. As a result, the threat environment surrounding vulnerabilities is likely to shift more broadly and more quickly.
As information gathering and target exploration become more efficient, assets and organizations that were previously less likely to be prioritized as targets become increasingly exposed to attack.
As gathering and analyzing vulnerability information and building attack scenarios become more efficient, the grace period between identifying a vulnerability and its exploitation risk rising will shrink dramatically.
02 / Challenge
On the attack side, much of the activity—gathering public information, exploring attack targets—can proceed based on externally obtainable information, and is well suited to being scaled up quickly and broadly with AI.
On the defense side, too, AI can be applied at every stage. Organizing diagnostic results, gathering vulnerability information, extracting candidate targets, and searching past response history can all be greatly streamlined by AI. However, the critical judgments—assessing business impact, deciding on a response policy, approving exceptions, coordinating with stakeholders—must remain the responsibility of people, grounded in the impacts and constraints unique to each company.
The diagram below contrasts the defense-side workflow for bringing a single vulnerability case to completion with the attack-side process.
Attack side
Exploitation risk materializesExploitation can begin before defense catches up
Defense side
Keeping the lifecycle turningA framework is needed so judgment, coordination, and approval never stall
The attack side can easily accelerate its entire process, while the defense side still needs judgment, coordination, and approval after awareness. What matters is a framework that keeps the lifecycle turning—not just detection, but through response completion, monitoring, and improvement.
Even when AI is used to streamline detection, analysis, and information organization, deciding a response policy, approving exceptions, coordinating with stakeholders, and confirming completion remain areas that AI alone cannot complete.
Companies therefore need a framework that streamlines the tasks AI can handle while supporting the judgment and coordination that people must own—a framework that lets response be completed continuously even with a limited team.
03 / Countermeasure 1
To keep post-detection response moving continuously, organizations need to move away from an operating style where stakeholders are tracked down and decisions made case by case. Who decides, who responds, who manages progress, and how exceptions get approved must all be organized in advance.
Policy, judgment, governance
Cross-functional driver
Establishes shared processes, decision criteria, and management methods, and coordinates with stakeholders to drive execution while making response status visible.
Technical response / implementation
04 / Countermeasure 2
Establishing a structure alone cannot prevent responses from being missed or stalling. Detection, response completion, and continuous improvement must be managed as a single lifecycle.
Vulnerability Management Lifecycle
Organize the information needed for judgment—assets, exposure status, products in use, and diagnostic results.
Asset data / configuration data / diagnostic results
Weigh business impact, exploitability, and response difficulty to decide whether to remediate, mitigate, or treat as an exception (accept the risk), and set priority.
Triage / decision criteria / exception approval / division of responsibility
Work with stakeholders to apply remediation or mitigation. Even when treated as an exception, complete approval, define a fallback measure, and set an expiration date.
Response requests / deadline management / exception management
Re-scan and confirm that risk has been appropriately reduced. Exception cases are handed off to ongoing monitoring.
Re-scanning / completion confirmation / evidence preparation
Continuously monitor response status, causes of stalling, and the expiration and re-assessment conditions of exception cases, and revisit decision criteria, processes, and structure.
Monitoring / exception re-assessment / continuous improvement
Exceptions that reach their expiration date return to "Decide"
Based on the risk of each vulnerability, it's important to choose remediation, mitigation, or exception management, and to complete the necessary approval, verification, and record-keeping. Even when treated as an exception, the reason, approver, expiration date, fallback measure, and re-assessment conditions must be made explicit—so it's kept distinct from simple neglect.
05 / Support Dirbato Provides
Dirbato's focus is not detection itself, but making the right call on each vulnerability detected, completing the necessary response, and building a state that can be continuously improved.
We connect the departments that own systems, the security function, diagnostic vendors, and development/operations vendors, and drive the response continuously through to completion.
We organize existing diagnostic and response work and design an operating process that covers priority, division of responsibility, response deadlines, exception management, and completion criteria.
We build the information management structure and workflow needed to centrally track assets, diagnostic results, response status, exception handling, and re-scan results.
We validate AI applications for organizing diagnostic results, impact investigation, triage, response records, and reporting, driving improvements in response speed and quality.
As AI advances, discovering, analyzing, and preparing attacks against vulnerabilities is expected to become even more efficient. What companies need is not simply a higher detection count.
For each vulnerability, it's important to identify the affected assets and business impact, decide on a response policy, proceed with remediation, mitigation, or exception management, and complete verification and record-keeping.
Through a cross-stakeholder PMO, a vulnerability management process, an information management platform, and the use of AI, Dirbato supports the building of a vulnerability management scheme that can continuously deliver response completion capability.
Written by: Yui Kamewari, Partner