Skip to content
English
  • There are no suggestions because the search field is empty.

What are Edgescan AI Insights?

Edgescan AI Insights are observations on your data as a whole, with regards to specific questions.

Version Number: v1.0.6

Published Date: 17 Aug 2026

____________________________________________________________________________

Edgescan uses AI as an opt-in basis only, you must request for AI insights to be enabled, we default to not using AI insights for all customers.

An interactive walkthrough of our AI Insights functionality is available here.

Edgescan AI Insights allows you to ask specific questions about your data. These can be tailored to your use cases.

It should be noted that none of your data will be sent to any third party LLM for processing. We have educated LLM's around the meta-data that is associated with the vulnerabilities and gather insights based on this data. This may be risk rating, public exploits, exposure of asset and your own risk tolerance.

Edgescan AI Insights was released with support for the following questions:

  • Is my Organization vulnerable to ransomware attacks?
    • Which assets or categories of assets in this customer's organization are most susceptible to ransomware attacks - which vulnerability types should they be most worried about?
  • NIST LEV Analysis

    • Organizations gain access to the NIST Likelihood of Exploitability (LEV) score for their top five vulnerabilities. This metric provides a data-driven estimate of how likely a given vulnerability is to be exploited in the wild, enabling security teams to move beyond severity alone and prioritize remediation based on real-world risk.
  • Remediation Priority
    • Outline the remediation prioirities for this organization in a markdown table by vulnerability mentioning the affected assets.
      • Limit the number of rows to the top 10 vulnerabilities based on EXF score
  • SSVC Analysis
    • The Stakeholder-Specific Vulnerability Categorization (SSVC) is a decision-making framework designed to help prioritize vulnerability response. It considers various factors to determine the urgency and importance of addressing specific vulnerabilities.
    • Edgescan presents the decision tree for the most critical vulnerability in your organization.
  • Compliance Advice
    • Does this customer have any vulnerabilities that would affect their data compliance certifications? Which assets are affected?
  • Training Advice
    • Does this organization have technical areas where they are struggling? What training could they benefit from?
  • MITRE D3FEND
    • Includes mappings to the MITRE D3FEND framework, which provides defensive techniques and countermeasures for mitigating identified vulnerabilities. By aligning vulnerabilities with D3FEND controls, security teams gain actionable guidance on how to harden systems and reduce exposure beyond patching alone.
  • Assets Vulnerability Assessment: Critical Findings & Trends

    • Edgescan presents the CWE trends and the OWASP Top 10 breakdown for the vulnerabilities in your organization.
  • Licence Forecast Report
    • Edgescan presents a comprehensive overview of licence utilization across various licensing plans, and an analysis of if you require more licences or if you should purchase less licences.
  • CISO Report

    • An executive-level summary of your vulnerability posture: total findings with a true/false-positive breakdown, estimated analyst time saved through automation, opened and closed findings by severity, overall remediation posture, and a breakdown of which open findings appear on the CISA Known Exploited Vulnerabilities (KEV) catalogue.

  • Continuous Controls Validation: OWASP ASVS

    • Maps your validated findings against the OWASP Application Security Verification Standard (ASVS) 5.0, chapter by chapter, showing current violations and previously remediated ("avoided") non-compliances with supporting remediation guidance. This is evidence-based control validation, not a formal ASVS certification audit.

  • Continuous Controls Validation: NIS2 (CyFun)

    • The same evidence-based approach applied to the CyberFundamentals (CyFun) framework used for NIS2, organized by NIST CSF function (Protect / Identify / Detect / Respond), with each control mapped to the relevant NIS2 Article 21(2) measure.

  • Continuous Controls Validation: ISO/IEC 27001:2022

    • The same evidence-based approach applied to ISO/IEC 27001:2022 Annex A, broken down by Annex A theme and control, with current violations, avoided non-compliances, and remediation guidance. Not a formal certification audit.

  • Continuous Controls Validation: Your Policies

    • Validates your findings against your own organization's custom-defined policies, rather than an external framework, useful where you have internal standards that don't map neatly onto ASVS, NIS2, or ISO 27001.

  • Vulnerability Chaining

    • Identifies realistic multi-step attack paths across your estate, combinations of individually-scored vulnerabilities that compound into materially higher risk than their individual severities suggest (for example, default credentials leading to remote code execution, then lateral movement, then data exfiltration).

As of today, Edgescan is using Amazon Bedrock and a tuned version of Anthropics Claude to infer insights.

The data that gets presented back to you is an AI created insight with parameters tuned and tailored by the Edgescan team for maximum efficiency. Keep in mind that these are AI created, so there is a small chance at making a mistake.