Redesigning the Vulnerability Management Scheme
for the Frontier AI Era

Can corporate vulnerability response keep pace with AI-accelerated threats?

In the frontier AI* era, the critical defense is not simply finding more vulnerabilities.
It is making risk-based judgments and continuously completing the response they require.
That demands rethinking the vulnerability management framework itself.

* In this article, "frontier AI" refers collectively to large-scale, general-purpose AI systems that currently represent the most advanced technical capability.

01 / Background

How AI Is Changing the Cyberattack Threat Landscape

As AI advances, the processes required to prepare an attack—gathering and analyzing vulnerability information, exploring attack targets, and building attack scenarios—are becoming more efficient. As a result, the threat environment surrounding vulnerabilities is likely to shift more broadly and more quickly.

01

The scope of attack targets expands

As information gathering and target exploration become more efficient, assets and organizations that were previously less likely to be prioritized as targets become increasingly exposed to attack.

02

The window before exploitation risk rises shrinks

As gathering and analyzing vulnerability information and building attack scenarios become more efficient, the grace period between identifying a vulnerability and its exploitation risk rising will shrink dramatically.

02 / Challenge

The Asymmetry Between
Attack and Defense in AI Use

On the attack side, much of the activity—gathering public information, exploring attack targets—can proceed based on externally obtainable information, and is well suited to being scaled up quickly and broadly with AI.

On the defense side, too, AI can be applied at every stage. Organizing diagnostic results, gathering vulnerability information, extracting candidate targets, and searching past response history can all be greatly streamlined by AI. However, the critical judgments—assessing business impact, deciding on a response policy, approving exceptions, coordinating with stakeholders—must remain the responsibility of people, grounded in the impacts and constraints unique to each company.

The diagram below contrasts the defense-side workflow for bringing a single vulnerability case to completion with the attack-side process.

The Asymmetry Between Attack and Defense in AI Use Attack / Defense Process

Attack side

AI makes it easy to accelerate the entire process

Easy to automate
01
Information gathering Public information / vulnerability data
02
Vulnerability analysis Technical detail / exploitability
03
Target exploration Public assets / attack surface
04
Attack preparation Building the attack scenario
05
Attack execution Attacking / exploiting the target

Exploitation risk materializesExploitation can begin before defense catches up

Defense side

Even with AI support,
human response remains

Requires coordination
01
Awareness Consolidating asset, configuration, and diagnostic data
02
Judgment Deciding priority, remediation, mitigation, or exception
Human judgment
03
Driving the response Response requests, deadline management, stakeholder coordination
Human coordination
04
Verification Re-scanning, completion confirmation, evidence preparation
Human approval
05
Monitoring & improvement Re-assessing exceptions, refining the process
Ongoing operation

Keeping the lifecycle turningA framework is needed so judgment, coordination, and approval never stall

POINT

The attack side can easily accelerate its entire process, while the defense side still needs judgment, coordination, and approval after awareness. What matters is a framework that keeps the lifecycle turning—not just detection, but through response completion, monitoring, and improvement.

Even when AI is used to streamline detection, analysis, and information organization, deciding a response policy, approving exceptions, coordinating with stakeholders, and confirming completion remain areas that AI alone cannot complete.

Companies therefore need a framework that streamlines the tasks AI can handle while supporting the judgment and coordination that people must own—a framework that lets response be completed continuously even with a limited team.

03 / Countermeasure 1

A Framework That Engages Stakeholders
and Drives Response to Completion

To keep post-detection response moving continuously, organizations need to move away from an operating style where stakeholders are tracked down and decisions made case by case. Who decides, who responds, who manages progress, and how exceptions get approved must all be organized in advance.

Policy, judgment, governance

Executive / management layer,
security oversight function

  • Setting risk tolerance and priorities
  • Approving and governing exception handling
  • Maintaining situational awareness and accountability

Cross-functional driver

Vulnerability management
operations PMO

Establishes shared processes, decision criteria, and management methods, and coordinates with stakeholders to drive execution while making response status visible.

Technical response / implementation

System-owning departments,
development/operations, vendors

  • Confirming impact and detailing the response approach
  • Implementing remediation or mitigation measures
  • Re-scanning and reporting completion

04 / Countermeasure 2

The Vulnerability Management Lifecycle
That Needs Redesigning

Establishing a structure alone cannot prevent responses from being missed or stalling. Detection, response completion, and continuous improvement must be managed as a single lifecycle.

Vulnerability Management Lifecycle

01

Understand

Organize the information needed for judgment—assets, exposure status, products in use, and diagnostic results.

Asset data / configuration data / diagnostic results

02 Human judgment

Decide

Weigh business impact, exploitability, and response difficulty to decide whether to remediate, mitigate, or treat as an exception (accept the risk), and set priority.

Triage / decision criteria / exception approval / division of responsibility

03 Human coordination

Drive the response

Work with stakeholders to apply remediation or mitigation. Even when treated as an exception, complete approval, define a fallback measure, and set an expiration date.

Response requests / deadline management / exception management

04 Human approval

Verify

Re-scan and confirm that risk has been appropriately reduced. Exception cases are handed off to ongoing monitoring.

Re-scanning / completion confirmation / evidence preparation

05 Ongoing operation

Monitor & improve

Continuously monitor response status, causes of stalling, and the expiration and re-assessment conditions of exception cases, and revisit decision criteria, processes, and structure.

Monitoring / exception re-assessment / continuous improvement

Exceptions that reach their expiration date return to "Decide"

"Response completion" doesn't mean fixing everything technically

Based on the risk of each vulnerability, it's important to choose remediation, mitigation, or exception management, and to complete the necessary approval, verification, and record-keeping. Even when treated as an exception, the reason, approver, expiration date, fallback measure, and re-assessment conditions must be made explicit—so it's kept distinct from simple neglect.

05 / Support Dirbato Provides

Support Dirbato Provides

Dirbato's focus is not detection itself, but making the right call on each vulnerability detected, completing the necessary response, and building a state that can be continuously improved.

01

Cross-stakeholder vulnerability response PMO

We connect the departments that own systems, the security function, diagnostic vendors, and development/operations vendors, and drive the response continuously through to completion.

  • Designing the execution plan and response playbook
  • Managing progress and quality of external vendor remediation work
  • Analyzing and escalating stalled cases
02

Designing the vulnerability management process and operating scheme

We organize existing diagnostic and response work and design an operating process that covers priority, division of responsibility, response deadlines, exception management, and completion criteria.

  • Selecting priority initiatives and building a roadmap
  • Establishing decision criteria for triage and response policy
  • Formalizing rules for exception management, re-scanning, and evidence management
03

Visualizing management data and building the operating platform

We build the information management structure and workflow needed to centrally track assets, diagnostic results, response status, exception handling, and re-scan results.

  • Organizing management scope, data items, and data integration
  • Designing the response workflow and record-keeping method
  • Building monitoring metrics and dashboards
04

Advancing security operations with AI

We validate AI applications for organizing diagnostic results, impact investigation, triage, response records, and reporting, driving improvements in response speed and quality.

  • Selecting AI use-case themes
  • Assessing applicability and running PoCs
  • Establishing usage rules and review processes

Turning Detection into Risk Reduction:
Building "Response Completion Capability" as an Organizational Strength

As AI advances, discovering, analyzing, and preparing attacks against vulnerabilities is expected to become even more efficient. What companies need is not simply a higher detection count.

For each vulnerability, it's important to identify the affected assets and business impact, decide on a response policy, proceed with remediation, mitigation, or exception management, and complete verification and record-keeping.

Through a cross-stakeholder PMO, a vulnerability management process, an information management platform, and the use of AI, Dirbato supports the building of a vulnerability management scheme that can continuously deliver response completion capability.

view security service