August 13, 2026
How We’re Using AI and Human Expertise to Karate-Chop Emerging Vulnerabilities

When unexpected security vulnerabilities arise, timing and next steps are key. To keep customer environments secure without causing unnecessary panic, we've upgraded our emerging vulnerability response process.
By combining an automated AI pipeline — which filters background noise and completes initial threat research — with hands-on human expertise to analyze and act, we can evaluate, respond to and communicate about security vulnerabilities more effectively. Whether a vulnerability requires an immediate patch, a configuration workaround or no action at all, our goal is to provide clear, proactive answers in our customers’ inboxes before they have to ask.
The Goal
If you’ve spent any time in IT or cybersecurity, you know the feeling. You open your phone, and there’s a headline about a newly discovered vulnerability in a tool or technology your business relies on.
In a managed security services partnership, you shouldn't have to spend your time worrying, nor should you have to send us an email asking, "Hey, did you see this?"
Historically, our team kept a constant pulse on vendor advisories and security feeds. We were evaluating threats behind the scenes, but we realized a key gap existed: If we looked at a vulnerability and determined it wasn't relevant, we didn't always proactively let our customers know.
That meant they were occasionally left wondering whether we had already assessed the situation or if it had somehow slipped through the cracks.
Beyond UpKeep
Managing infrastructure requires balancing security with operational stability. You don’t upgrade core firewalls or routers on a whim during business hours like you might update an app on your phone — updates must be carefully planned.
That’s why last year, we introduced UpKeep, a feature of our NWG Manage service that involves regularly reviewing vendor releases and providing recommendations for upgrading customer’s devices.
But threats like to pop up outside of those regular review cycles. When a high-risk vulnerability emerges outside of regular maintenance windows, we need to act fast, evaluate the real impact and provide definitive answers.
To bridge this gap, we built a streamlined process designed to achieve three things:
- Filter out the noise so our security experts can focus on what actually affects the environments we manage.
- Speed up initial threat research from hours to minutes.
- Proactively communicate our findings, whether an urgent fix is needed or not.
How It Works
AI use should always be informed and governed by human experts. That’s why we designed a hybrid process where AI handles the repetitive, high-volume data gathering, while human security professionals review the work and make the critical decisions.
Here is a look at the path a security signal takes through our pipeline:
Step 1: Automated Signal Intake and Noise Filtering
Vendor advisories, CISA alerts, and security feeds flood in constantly. Our automated pipeline (powered by n8n and an AI agent) monitors these sources every minute. When one of these notifications hits our inbox, the AI performs an initial relevance check, asking: Is this an actionable security alert for systems we support, or is it irrelevant noise (like state-sponsored attacks on nuclear plants or generic weekly marketing newsletters)?
Signals discarded as irrelevant are sent to a dedicated channel where a human team member can quickly audit that decision to avoid false negatives.
Step 2: Automated Research and Pre-Processing
If the signal passes the initial relevance check, the AI crawls security databases (like the National Vulnerability Database), gathers CVSS scores, identifies affected software versions and compiles the initial threat context.
Instead of our engineers having to spend 45 minutes researching and scanning long documents, the AI generates a standardized, easy-to-read ticket containing all the essential research up front.
Step 3: Human Analysis
An NWG technical analyst reviews the ticket and determines relevance, threat level and potential impact. These are some of the questions they ask:
- Does this affect a vendor we actively support?
- Is this a global, critical event (e.g., Log4j) that necessitates a general awareness notification?
- Does this affect specific devices or versions we currently manage?
- What is the true severity and exploitation status?
- Does this allow Data Exfiltration, Remote Code Execution (RCE) or Authentication Bypass? Is there an active Proof of Concept (PoC)?
- Is it actively being exploited in the wild?
Because we maintain a live database of all managed customer devices, software versions and maintenance windows, our team can map out exactly which environments are affected and when remediations can safely occur.
The security team member makes a binary decision of whether action is needed or not.
Step 4: Transparent Communication and Execution
Once that determination is made, we respond according to our standardized playbook.
We communicate with the customer either way.
- If Action Is Required: We notify the customer with a clear explanation of the threat, the affected devices, and the exact next steps they and/or we will need to take.
- If No Action Is Required: We still send an update, letting the customer know we evaluated the vulnerability and explaining why their environment isn't at risk.
Early Wins
Since rolling out this updated process, we’ve put it through its paces across every major vulnerability scenario — from false alarms and non-critical bugs to high-severity emergency updates.
Here’s what we’ve seen so far:
- Less "Did You See This?": Customer inquiries have dropped as we’ve increased proactive communication around emerging vulnerabilities.
- Faster, Consistent Decisions: By speeding up the initial research process and standardizing review and response, our security team reaches confident determinations more efficiently.
- Positive Feedback: Customers have shared how much they appreciate receiving brief, scannable updates that state, "We saw this, here’s how it affects you and here’s what we’re doing about it."
Conclusion
We view this process as a living system that requires continuous improvement — whether that’s tuning how frequently we audit discarded signals, expanding the range of threat intelligence sources fed into the pipeline, or evaluating and updating our standardized review and response playbooks as we continue to put the process to good use.
At the end of the day, this is another tool to help us help our customers. What hasn't changed is our commitment to providing the people, mature processes and technology to make sure architecture is built right, runs right and gets fixed right away when something happens. Schedule a call if you want to learn more about our Managed Security services!
Publish Date: August 13, 2026




