SHIFT Co., Ltd., which supports customers in creating marketable software services and products, has launched a new service, “Frontier AI Vulnerability Rapid Response Support, ” to support vulnerability response in the Frontier AI era, amid growing concerns about the increasing sophistication and speed of cyberattacks accompanying the evolution of generative AI technology.
Organizations in the financial and public sectors are concerned about shortening the lead time from vulnerability discovery to attack code generation and execution, necessitating a review of their traditional vulnerability response processes. This service provides end-to-end support for management and CISOs, including risk assessment, visualization of target systems and dependencies, identification of technical debt, emergency patching, quality verification after patch application, and audit trail management.
To provide this service, SHIFT has assembled a specialized team that combines security experts, delivery capabilities in the financial, public, and enterprise sectors, and expertise in software quality assurance and testing. We are also considering the use of AI testing solutions such as “Nemuranai,” which autonomously supports test design and execution 24 hours a day, 365 days a year, and will support our customers in building a system that can continuously enhance their response capabilities from normal times to emergencies and post-incident improvements.
Also Read: CyberSolutions Launches AiSE for Enterprise Security
With advancements in generative AI technology and the emergence of supply chain risks, cybersecurity is no longer a problem limited to specialized departments, but a common management issue for companies and public institutions. In particular, the evolution of frontier AI, which refers to cutting-edge general-purpose AI models, is expected to shorten the lead time from vulnerability discovery to attack code generation and attack execution, necessitating a review of existing vulnerability response processes.
The Financial Services Agency and the Bank of Japan are urging financial institutions and other organizations to take short-term action in light of the evolving threat posed by frontier AI. The National Cyber Security Office is also working to strengthen cybersecurity measures in light of the increasing sophistication of AI capabilities. Organizations that possess critical systems are required to establish systems that enable them to respond quickly and appropriately, including asset visibility, vulnerability management, patch application and monitoring, and resilience enhancement.
In this environment, when companies and public institutions receive vulnerability information, they need to identify the affected systems, prioritize patch application, determine whether patch application is feasible, coordinate with development and maintenance vendors, and verify the impact after patch application, all within a limited timeframe. Furthermore, if patches cannot be applied immediately due to unsupported products, they also need to consider risk reduction measures, including the application of virtual patches (mitigation measures such as WAFs), migration plans, and decisions on risk acceptance.
Furthermore, vulnerability remediation is not simply a matter of applying patches. After remediation, it is necessary to quickly and reliably verify that there is no impact on existing operations or related functions, and to retain the necessary evidence. This quality verification process is difficult to manage with a development and maintenance system that handles emergency responses in parallel with normal operations, and can become a bottleneck in emergency vulnerability response.
SHIFT has launched this service to provide end-to-end support, from upstream risk assessment and crisis response to quality verification after patch application, evidence management, and even post-incident improvement.
SOURCE: PRTimes


