New Capability Validates Attack Paths
Sophos Brings AI-Powered Exploit Path Verification
- EPV will verify whether vulnerabilities are actually exploitable in a specific environment.
- GPT cyber models will analyze controls, reachability, privileges, patch status, and known exploits.
- AI-generated verdicts will include evidence and undergo Sophos analyst review.
September 28, 2026: Global cybersecurity company Sophos has announced Exploit Path Verification (EPV), a new capability being developed for Sophos Managed Risk to help security teams determine which vulnerabilities are genuinely exploitable in their specific environments.
EPV will be built using OpenAI’s GPT cyber models through the Daybreak Defense Network. The objective is to provide security teams with verified, evidence-backed assessments that help them determine which exposures should be addressed first.
Sophos has not announced a launch date. The company said availability, including early access and general availability timing, will be announced later.
Moving beyond vulnerability severity scores
Security scanners can identify thousands of vulnerabilities and rank them using severity scores. However, a severity score alone does not establish whether an attacker can actually reach and exploit a vulnerability within a particular environment.
A critical vulnerability may sit behind a security control that prevents exploitation. Conversely, several lower-severity weaknesses can be chained together to create an attack path that ultimately reaches a sensitive system.
Sophos is designing EPV to address this gap by evaluating environmental context rather than relying solely on generic vulnerability scores.
The capability will consider asset and patch status, endpoint protection policies, network reachability, identity and privilege information, and known exploit availability.
EPV will return four evidence-backed exploitability verdicts:
- Confirmed Exploitable
- Blocked by a Control
- Not Reachable
- Insufficient Evidence
The capability will also identify chained attack paths in which multiple lower-severity findings combine into an exploitable route.
Assessing the effectiveness of security controls
EPV is also designed to determine whether a security control blocks an entire class of attack techniques or only a known exploit or commonly available proof of concept.
That distinction can provide security teams with a more environment-specific view of exposure. Instead of asking only whether a vulnerability exists, teams can assess whether an attacker has a realistic route to use it.
The system is also being designed to generate ticket-ready remediation guidance, allowing organizations to move from exposure validation toward corrective action more efficiently.
AI-assisted, human-reviewed results
Sophos said EPV will be advisory and additive by design. Each result will be explicitly labeled as AI-generated, with the supporting evidence visible to the customer.
Sophos analysts will also review the results, keeping human expertise in the workflow rather than leaving the final assessment entirely to an AI system.
Sophos Chief Technology Officer John Peterson said one of the most common challenges facing security teams is the volume of findings they must evaluate and the difficulty of determining which findings create the greatest risk.
According to Peterson, EPV is being developed to show what an attacker can reach within an organization's environment and provide the evidence needed to prioritize remediation.
Extending the Sophos-OpenAI partnership
The EPV initiative builds on Sophos' existing collaboration with OpenAI.
Sophos joined the OpenAI Daybreak Cyber Partner Program in June 2026. The program has since been presented as the OpenAI Daybreak Defense Network. Sophos has used OpenAI cyber models in managed detection and response investigations, advisory assessments, and workflows designed to help customers discover, validate, and remediate exposure.
OpenAI describes the Daybreak Defense Network as a framework for bringing frontier AI-powered cyber capabilities into products and services already used by defenders through governed integrations and partner-operated workflows.
Its current framework includes safeguards, monitoring, human review and expert judgment, while supporting both product integrations and managed security services.
With EPV, that collaboration is being extended into a capability within an existing Sophos product.
OpenAI's GPT cyber models will provide the advanced reasoning used to assess exploitability, while Sophos will supply environment-specific evidence and security-control information. Sophos analysts will review the resulting assessments before they are delivered to customers.
McCall McIntyre, Head of Global Cyber Partnerships at OpenAI, said the goal of the Daybreak Defense Network is to give defenders the benefits of frontier AI safely. He described EPV as an example of applying frontier reasoning to a practical defensive problem while retaining safeguards for responsible deployment.
More than 625,000 organizations in reach
Sophos says it protects more than 625,000 organizations worldwide, including approximately 40,000 managed detection and response customers across enterprise, mid-market and commercial segments.
Sophos says that reach is central to the purpose of EPV, with the company aiming to make verified exploitability assessment available beyond the largest organizations with highly specialized security teams.
The capability is currently being developed for enterprise and mid-market business customers of Sophos Managed Risk.
However, Sophos has not yet announced when EPV will become available for early access or general deployment. The company said those details will be provided at a later date.
Fact-check and source note
The core claims in this report were checked against Sophos' primary announcement and its Managed Risk product information. OpenAI's current Daybreak Defense Network page was also reviewed to verify the network's scope, partner model and governance approach. Sophos' June 2026 announcement was used to verify the timing and earlier name of the partnership.
//DBTech/SGA/SVP/MNP//





