Sophos is developing Exploit Path Verification (EPV), a new capability for Sophos Managed Risk designed to help security teams identify which vulnerabilities can actually be exploited in their specific environments.
EPV will use OpenAI GPT cyber models through the Daybreak Defense Network to analyze factors including asset and patch status, security controls, network reachability, identity and privilege data, and known exploit availability. The system will produce evidence-backed verdicts such as Confirmed Exploitable, Blocked by a Control, Not Reachable, or Insufficient Evidence.
The technology is designed to go beyond conventional vulnerability severity scores by identifying attack paths where multiple lower-severity vulnerabilities can be chained together. It can also assess whether existing security controls block an attack technique and generate remediation recommendations for security teams.
Sophos said EPV will remain an advisory capability, with AI-generated verdicts clearly labeled and supporting evidence made visible. Sophos analysts will review the results before they are delivered to customers.
The capability builds on Sophos’ collaboration with OpenAI, which began when the cybersecurity company joined the OpenAI Daybreak Defense Network in June 2026. Sophos provides environment-specific security data and controls, while OpenAI’s models provide AI reasoning to assess potential exploitability.
EPV is currently in development for enterprise and mid-market customers using Sophos Managed Risk. Availability and early-access details will be announced at a later date.


