Skip to content
Release: Australia · Updated: 2026-06-04 · Official documentation · View source

Exploring Now Assist for Vulnerability Response

Get information about how your vulnerability managers, analysts, and cybersecurity teams can use generative AI skills and agents with Vulnerability Response and supported applications.

Now Assist for Vulnerability Response overview

For more information about how generative AI skills and agents are supported in the Unified Security Exposure Management (USEM) workspace, see Now Assist in Unified Security Exposure Management.

With generative AI skills and agents provided with the Now Assist for Vulnerability Response application, use generative AI to help you with the following tasks:

  • Natural language data queries

    Vulnerability analysts and remediation owners can enter questions in plain language and receive comprehensive answers about all types of findings that include host, container, and test results vulnerabilities with Security Exposure 360.

  • AI Security Exposure Management

    AI exposures is a dedicated module that provides visibility into the entire AI attack surface, including vulnerabilities, validation or automated red teaming findings, and security posture findings or configuration issues in various AI assets

  • Agentic AI exposure assessment

    Assess exposure to known and CISA-listed vulnerabilities, identify affected assets, understand business impact, and create watch topics.

  • Smarter remediation guidance

    Compare remediation options that are based on asset context and receive AI-recommended fixes to accelerate execution.

  • Remediation and SLA visibility

    Monitor remediation progress, SLA compliance, and missed targets by severity, team, and asset type.

  • Exception approvals with impact analysis

    Approve or reject exception change requests with on-demand analysis of risk and business impact.

  • Create custom API connectors (Security Posture Control)

    Create your own API connectors in the Security Posture Control workspace with the Connector builder framework module. Note: Security Posture Control and its supported applications are required for this generative AI feature.

Users

UserDescription
Vulnerability managers, vulnerability admins, and analystsWith the Security Exposure 360 agentic workflow, chat with an AI agent using natural language to retrieve host (Vulnerability Response) and Application Vulnerability Response (AVR) data, as well as Container Vulnerability Response and Configuration Compliance data.
Vulnerability analysts, Chief Information Security Officers (CISO)sMonitors the organization’s overall risk posture across integrated environments, ensuring accurate asset discovery and classification for AI exposures correlation. These roles serve as an escalation point for remediation teams, assigns remediation tasks based on asset ownership and severity, and organizes AI exposure information into dynamic remediation tasks to streamline prioritization. Additionally, the role delivers actionable dashboards and reports to track remediation progress, highlight critical AI exposures, and communicate the current risk posture to stakeholders.
Vulnerability managers and analystsDetermine your exposure to vulnerabilities in your environment and their potential impact to your configuration items (CIs) and business services.
Vulnerability managers and analystsGet insights into how well you're achieving your remediation targets for vulnerabilities according to your Service Level Agreements (SLAs).
Vulnerability managers and analystsProvide steps for analysts to remediate vulnerable items (VITs) that are assigned to them with watch topics and remediation efforts.
Vulnerability managers and analystsGet clear remediation assistance for how to resolve remediation tasks that includes potential, preferred solutions, if they are available.
Vulnerability managers and analystsIdentify and review duplicate vulnerable items that are imported by your vulnerability scanners. Identify the primary vulnerable item that is associated with a configuration item.
Vulnerability managers and analystsGenerate insights to prioritize findings that are based on contextual summaries, actionable recommendations, and quick links in the Security Exposure Management (SEM) workspace.
Vulnerability managers and analystsGet on-demand recommendations to approve or reject exception requests directly from the Exception Change Approval record in the Security Exposure Management (SEM) workspace.
Developers and cybersecurity teamsGet guidance for how to accelerate the creation of custom API connectors for the Security Posture Control workspace.

Benefits

BenefitFeatureUsers
Ask questions in natural language to help you quickly retrieve vulnerability and exposure data across legacy sources.Retrieve VR dataVulnerability \(host\) and Application Vulnerability Response \(AVR\) managers, admins, and analysts
AI exposures is a dedicated module that provides visibility into the entire AI attack surface, including vulnerabilities, validation or automated red teaming findings, and security posture findings or configuration issues in various AI assets.Guardrail detector skill and agentic workflowVulnerability analysts, Chief Information Security Officers \(CISO\)s
Understand your security posture with AI-generated contextual summaries, recommendations, and insights to help you prioritize critical findings and take action directly from the findings view.SEM Insights skillVulnerability managers, admins, and analysts
Enable exception and false positive approvers to make faster, more consistent decisions while reducing manual analysis effort.Approval Recommendation skillVulnerability managers, admins, and analysts
Get guidance for how to accelerate the creation of custom API connectors for the Security Posture Control workspace.SPC Setup Connector skillDevelopers and cybersecurity teams
Identify the primary \(first-found\) vulnerable item for a configuration item and remove duplicate Host Vulnerable items \(VITs\).Vulnerable item deduplication skillVulnerability managers and analysts
Get guidance for how to resolve remediation tasks that includes available potential, preferred solutions from third-party vendors.Recommend preferred solution for VIT skillVulnerability managers and analysts
- Identify assets with Common Vulnerabilities and Exposures \(CVEs\). - Determine the number of active vulnerability items \(VITs\) that correspond to CVEs. - Identify business services with known vulnerabilities. - Create watch topics for vulnerable item \(VIT\) remediation based on the information provided. The AI agent can create a Remediation Effort for the active VITs associated with the watch topic.Assess vulnerability exposure agentic workflowVulnerability managers and analysts
Gain insight into the progress of your Service Level Agreement \(SLA\) compliance summary for the past 30 days. View Groups and Asset Types that missed SLAs to help you track and adjust targets.Analyze vulnerability remediation status agentic workflowVulnerability managers and analysts
Retrieve relevant context and details for the vulnerable items assigned to you. Analyze, plan, and create steps for remediation.Remediation AssistanceVulnerability analysts

What to explore next

To learn more about generative AI skills and agentic workflows with Now Assist for Vulnerability Response, see: