Sophos, a global cybersecurity leader, today announced Exploit Path Verification, a new capability that will be built into Sophos Managed Risk to help security teams better prioritize and manage exploitable vulnerabilities in environment. Announced from Oxford, United Kingdom, capability will be built with OpenAI's GPT cyber models through Daybreak Defense Network, to return verified, evidence-backed verdicts that give defenders clarity they need to fix exposures that matter first.
Security teams face widening gap between vulnerabilities they can find and ones they can fix. Scanners surface thousands of exposures and severity scores rank them, but severity score cannot tell whether critical flaw sits behind control that blocks it, or whether two low-severity findings chain into path that leads to breach. As result, security teams often patch by generic score, rather than whether attacker could reach and use flaw in specific environment.
Sophos designing EPV to close that gap. It is being built to reason over asset and patch state, endpoint protection policy, network reachability, identity and privilege facts, and known exploit availability, and returns clear evidence-backed exploitability verdict. EPV will also be designed to identify chained paths where multiple lower-severity findings combine into one exploitable route, assess whether control blocks technique class or only common public proof of concept, and draft remediation text ready for ticket.
Capability will be advisory and additive by design. Every verdict labeled as AI-generated with evidence visible, and Sophos analysts review results.
"One of most common challenges we hear from security teams today is volume of findings they need to sift through, and lack of clarity which findings matter most, or in other words, put them at greatest risk," said John Peterson, chief technology officer, Sophos. "Exploit Path Verification is being built to make it clear what in their environment is reachable by attacker, with evidence to prove it, so they fix what counts first."
EPV extends Sophos work with OpenAI. Through OpenAI Daybreak Defense Network, which Sophos joined in June 2026, company brought frontier cyber models into MDR investigation, advisory assessments, and workflows that help customers discover, validate, and remediate exposure. EPV will build on that work inside product customers already run. OpenAI's GPT cyber models provide frontier reasoning to help assess exploitability. Sophos supplies environment-specific evidence and product controls, and its analysts review results delivered to customers.
"Our goal through OpenAI Daybreak Defense Network is to give defenders advantage of frontier AI, safely," said McCall McIntyre, Head of Global Cyber Partnerships, OpenAI. "Sophos has been thoughtful partner since joining program, and Exploit Path Verification is clear example of frontier reasoning applied to real defensive problem, with guardrails that responsible deployment demands."
Sophos defends more than 625,000 organizations worldwide, including 40,000 managed detection and response customers across enterprise, mid-market, and commercial segments, delivered through one of industry's largest partner ecosystems. That reach is central to EPV's purpose. Verified exploitability should not be capability reserved for largest security teams with deepest budgets.
About Sophos
Sophos, global cybersecurity leader, defends more than 625,000 organizations worldwide with Sophos Fusion, industry's first and most complete AI-native cybersecurity defense system. Powered by agentic AI and elite human expertise, Sophos detects, investigates, and neutralizes threats before they become business-disrupting events.