Sophos has announced Exploit Path Verification (EPV), a new capability being built into Sophos Managed Risk to help security teams prioritise and manage exploitable vulnerabilities in their environment, built with OpenAI’s GPT cyber models through the Daybreak Defense Network.
Announced from Singapore on 8 September 2026, EPV is designed to return verified, evidence-backed verdicts on which vulnerabilities matter most, closing a gap Sophos says exists between the exposures scanners surface and the ones security teams can actually fix. Availability will be announced at a later date.
Turning Severity Scores Into Evidence-Backed Verdicts
Scanners typically surface thousands of exposures ranked by generic severity scores, which cannot tell whether a critical flaw sits behind a blocking control or whether two low-severity findings chain into a breach path. EPV is being built to reason over asset and patch state, endpoint protection policy, network reachability, identity and privilege facts, and known exploit availability, returning one of four verdicts: Confirmed Exploitable, Blocked by a Control, Not Reachable, or Insufficient Evidence.
- EPV is designed to identify chained paths where multiple lower-severity findings combine into one exploitable route
- It will assess whether a control blocks a technique class or only a common public proof of concept
- Every AI-generated verdict is labelled as such, with evidence visible, and reviewed by Sophos analysts
Extending Sophos’ Work With OpenAI
EPV builds on Sophos’ membership in the OpenAI Daybreak Defense Network, which it joined in June 2026, and which has already brought frontier cyber models into its managed detection and response investigations and advisory assessments. Sophos said it defends more than 625,000 organisations worldwide, including 40,000 managed detection and response customers, and that verified exploitability should not be a capability reserved for the largest security teams with the deepest budgets.
“One of the most common challenges we hear from security teams today is the volume of findings they need to sift through, and the lack of clarity of which findings matter most,”
said John Peterson, Chief Technology Officer, Sophos
Peterson said Exploit Path Verification is being built to make clear what in a customer’s environment is reachable by an attacker, with evidence to prove it, so defenders fix what counts first.

