Exposure Management That Keeps MSPs Ahead of Machine-speed Attacks

WithSecure Elements now connects Exposure Management and response in a single workflow: see a risk, understand its priority, and contain it – one click, one console, across every customer you manage. Findings arrive in minutes instead of days, priorities are scored in near real-time, and exploitation attempts are blocked by behavior, not just by signature.

Here’s what the newest release of proactive security capabilities means for how you run your service.

One workflow, from exposure to containment

Find the exposure in one tool. Confirm it in a second. Contain it in a third. That shuffle was survivable when exploitation took days – but with AI, it happens in hours. If that sounds like your Tuesday, keep reading.

Weekly scans aren’t enough

Most security stacks make MSPs work in fragments. Every handoff between them costs time, and time is what attackers exploit. Weekly scans and manual triage were built for a threat landscape that no longer exists. WithSecure Elements Exposure Management (XM) and Elements XDR (Extended Detection and Response) now operate as one. When a critical recommendation appears, you act on it right there: isolate the device, block the user, end the session, force a password reset.

No console-switching, no re-triaging, no handoffs between tools or teams. The time between “we have a problem” and “we’ve contained it” drops from hours to minutes – and your Mean Time To Respond (MTTR) drops with it, for every customer at once.

How it works
  1. Elements continuously matches every customer’s software inventory, configurations, and identities against live threat intelligence.
  2. New findings are created within minutes of a CVE* publication, a software change, or an identity change in Entra ID – no lengthy scan windows.
  3. Each finding is scored in near real-time based on actual exposure: internet-facing, on an attack path, exploited in the wild, asset criticality. 
  4. You remediate or mitigate directly from the recommendation, and risk history records the improvement.

* Note: Planned general availability date for the near real-time CVE capability is September 15, 2026. Subject to change.

Pre-Zero-Day Protection: Defense against vulnerabilities that don’t have a name yet

Machine-speed attacks demand machine-speed defense

This summer, the theoretical became documented fact: within two weeks in July 2026, both OpenAI and Anthropic disclosed that their AI models had autonomously breached real companies’ production systems during security testing. In the Hugging Face case (see source for technical writeup: Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident), the AI discovered a previously unknown zero-day, escaped an isolated test environment, and conducted a sustained intrusion of over 17,000 discrete attacker actions, with no human directing any of it. The models weren’t even trying to attack anyone; they were optimizing a test score, and exploitation was simply the fastest path there (see our expert’s article, A taste of what AI can do when it attacks autonomously).

In other words, AI models have now demonstrably found and exploited vulnerabilities autonomously in controlled testing. When vulnerability discovery and exploitation no longer require human skill or human hours, every unpatched weakness becomes worth attacking. Waiting for a CVE number is waiting too long in the age of agentic attacks.

Elements XM protects against N-days and Pre-Zero-Days

The CVE catalog lags reality more often than you’d think. Many vulnerabilities are already known to the vendor, meaning that a patch or security advisory exists, but no CVE has been assigned yet. Or there might never be a CVE. These N-day vulnerabilities are fully exploitable, yet invisible to any tool that scans purely against the CVE database. In our early analysis, roughly one in ten Elements Exposure Management findings falls into this category: real, actionable exposures that a CVE-driven process would simply never surface.

And Elements Exposure Management (XM) goes one step further, to vulnerabilities no one knows exist at all. Elements XM analyzes behavioral telemetry from Elements EDR sensors to discover exploitable vulnerabilities before anyone knows they exist. We call these pre-zero-day vulnerabilities. Our patent-pending capability turns each one into a finding: what the exposure is, and how to close it. No patch exists yet, by definition, so you mitigate the pre-zero-day exposure straight from the recommendation: isolate the device, reset passwords, or let Outbreak Control act automatically on critical exposures.

This isn’t theoretical. The first pre-zero-day we discovered was confirmed and patched by the vendor (FileWave 16.0.2) before it was ever exploited in the wild. More have followed.

Minutes, not days – for identities and software vulnerabilities

Speed is key for addressing Identity Exposures and CVEs

According to Verizon 2026 Data Breach Investigations Report: “Exploitation of vulnerabilities is now the most common initial access vector for breaches. It has risen to 31% in this year’s reporting dataset, while credential abuse—the previous leader—is down to 13%” (p. 10).

This shift from identity-related weaknesses to vulnerabilities like CVEs is at the heart of why our development has focused on enabling quick response actions for both identities and CVEs. With the newest Elements capabilities, when a new CVE* drops or an identity is exposed, you know within minutes which customers are affected, on which devices, and what to do. When a user is created, modified, or gains permissions in Entra ID, exposure is now re-evaluated within 15–30 minutes instead of the next day, closing the time window that identity-based attacks depend on.

* Note: Planned general availability date for the near real-time CVE capability is September 15, 2026. Subject to change.

Near realtime findings and recommendations for Software Inventory* 

Software Inventory provides nearly real-time vulnerability findings, which means no more waiting for the next scan window. Elements now continuously matches installed software against live threat intelligence feeds. When a new CVE becomes available – or when software is installed or updated on any device – Elements XM creates a finding and recommendation within minutes, not hours or days. For our partners’ services, this means leading customer conversations with intelligence instead of reacting to tickets. You tell them as a trusted advisor – before they read about it in the news. 

* Note: Planned general availability date for this capability is September 15, 2026. Subject to change. 

Priority scoring that scales across your customer base*

Flat CVE lists sorted by CVSS don’t scale across a managed portfolio. Elements scores every finding against its real context, transparently – you can see exactly which factors drive each priority. Across all your managed companies, that means fixing the highest-risk items first, everywhere, without per-customer triage. MyReports reporting shows the exposure trend over time: hard evidence that your exposure management activities are reducing real exposure, not just generating reports. That’s proof for quarterly reviews – and support for customers working toward the risk management requirements in Article 21 of the NIS2 Directive. 

* Note: Available as a pilot version at the moment, general availability release of the capability is expected during H2-2026. Subject to change. 

A platform that reports its own blind spots

Elements turns coverage gaps into recommendations: a device missing EDR, an agent silent for too long, a misconfigured policy, an unmanaged device on the network each with the steps to close it. No more manual agent audits across your customer base. 

Summary of what changes, in numbers

Before Now
Threat intel to recommendation  Hours or days  Minutes* 
Zero-day defense  Signature-dependent  Behavior-based, automatic 
Identity exposure refresh  24–36 hours  15–30 minutes 
Response actions  Separate XDR console  One click from Exposure Management

(unification of XM+XDR workflow) 

Coverage gaps  Manual audit per customer  Auto-detected across all customers 
Risk scoring  Quite static, opaque  Transparent, near real-time** 

 Notes:  

* Planned general availability date for this capability is September 15, 2026. Subject to change. 

** Revamped priority scoring available as a pilot version at the moment, general availability release of the capability is expected during H2-2026. Subject to change. 

 

Where this is heading

Today you see exposure in near real-time and act on it in one click. Our next step is deeper automation: playbooks that automatically remediate threats based on rules you define, so response happens at machine speed. 

You stay the hero. Elements stays the safety net.

 


Availability

Available now for WithSecure Elements Exposure Management (XM) customers. Response actions require an Elements XDR subscription. Behavior-based zero-day protection requires Elements EPP and EDR (Elements Endpoint Security). Identity related new features require a WithSecure Elements MDR for Identity (Entra ID) subscription.  

Overwhelmed by options? The Elements Proactive Bundle takes the guesswork out — everything you need and all the capabilities listed here, in one convenient package. 

Ready to secure your business against AI-accelerated threats with Elements Exposure Management (XM)? 

→ Buy Elements XM


FAQ

What is exposure management? 

Exposure Management is the continuous identification, prioritization, and remediation of security weaknesses – vulnerabilities, misconfigurations, identity risks, and coverage gaps – based on how likely attackers are to exploit them in a specific environment. 

How does WithSecure Elements help MSPs respond faster? 

Response actions – isolating devices, blocking users, forcing password resets – are taken directly from the recommendation in Elements Exposure Management, with an Elements XDR subscription. One workflow covers discovery, prioritization, and containment across all managed customers. 

How does Elements protect against undisclosed (zero-day) vulnerabilities? 

Pre-Zero-Day Protection is a patent-pending capability combining XDR behavioural telemetry with Elements XM analytics to surface exploitable vulnerabilities before they are publicly known. We proved this in April 2025, discovering a vulnerability in FileWave before it was reported. When a finding surfaces, IT admins can act immediately to mitigate exposures inside the platform — even when patching isn’t an option. There is a variety of different pre-emptive exposure mitigation actions available, depending on the type of exposure that has been found. 

Does Elements Exposure Management support NIS2 compliance? 

Continuous risk monitoring, prioritized remediation, and documented risk history support the technical and organizational measures required under Article 21 of the NIS2 Directive. WithSecure is headquartered in Finland and processes data in the EU. 

What next?

Discover WithSecure™ Elements Exposure Management.
– No credit card required. No obligations.No complexity.

Fast onboarding, faster security outcomes

Most cybersecurity platforms are built for enterprises with dedicated security teams and unlimited budgets. WithSecure Elements is different — proactive, AI-powered, and designed from the ground up for mid-sized companies that need real protection without the complexity. Built in Europe, compliant by default, and backed by human experts who are ready when you need them

Blog post

Read our latest blogs

Industry Recognition

Incident Response Managed Security

Among Notable Vendors in Cybersecurity Incident Response Services by Forrester

Forrester named WithSecure among Notable Vendors in the Forrester report, The Cybersecurity Incident Response Services Landscape, Q3 2026.

Industry Recognition

Managed Security

Recognized in Gartner Voice of the Customer for MDR

WithSecure recognized in Gartner Voice of the Customer for MDR with 100% Willingness to Recommend

Industry Recognition

Industry Recognition

Recognized as European Leader in the 2026 Cyberhive Matrix

WithSecure is recognized as a European Leader in three categories of the Cyberhive Matrix™ 2026 – the independent evaluation of European cybersecurity solutions.