Predictive Attack Surface Intelligence

PASI

The existing security stack is reactive: an incident happens, an alarm rings. PASI turns security telemetry into multivariate time series, projects it forward with a foundation model, and produces action before the incident.

Time series forecastingConformal intervalsMulti-tenantOn-premise or SaaS

Why it exists

The attacker’s exploit window is shorter than the defender’s patch window.

In an average organisation a critical CVE takes 60–150 days to patch, while a proof of concept appears in 5–20 days. That gap is a structural weakness in defence. Add alert fatigue, blind shift planning and patch prioritisation tied to static scores such as CVSS.

PASI reduces four data classes — network telemetry, security logs, asset and vulnerability inventory, threat intelligence — to a common time series backbone. It forecasts each series forward and combines the deviation between forecast and actual, the forecast itself and external intelligence signals into three outputs.

  • Asset and attack surfaceCMDB, asset graph, exposure score
  • Vulnerability managementCVE, KEV/EPSS, patch campaigns
  • Threat intelligenceSTIX/TAXII, actor, campaign, TTP
  • Time series catalogueSeries definition, frequency, quality
  • Forecasting engineEnsemble, conformal, backtest
  • Exploit forecastingCVE → exploit probability curve
  • Early warning (EWS)Signal generation, correlation, suppression
  • Risk scoringAsset, service and organisation level
  • Scenario and what-ifSimulation, counterfactual analysis
  • Playbooks and actionApproval flow, execution, rollback
  • SOC capacityLoad forecasting, shift recommendation
  • Audit and complianceImmutable audit trail, evidence bundle

PASI is under development; contact us about the pilot and early access programme.

Three outputs

From forecast to action.

FORECAST

Forecast

“DMZ ingress traffic will reach 240% of the P90 band within the next 6 hours.”

EARLY WARNING

Early warning

“This rise matches a DDoS precursor pattern at 87%; confidence interval [0.71, 0.94], horizon 2h 40m.”

PRESCRIPTIVE ACTION

Prescription

“Apply the WAF rate-limit profile, greylist the ASN, call +1 engineer to on-call.”

Eight differentiating capabilities

What it does

Horizon-based forecasting

From one hour to 30 days from a single model; seasonality and long trend handled together.

Conformal prediction intervals

Not a point estimate but a calibrated probability band — false alarms stay under control.

Exploit weather forecast

A survival-analysis curve for the probability that a CVE will be exploited within 30 days.

Attack surface drift

Forecasting the rate of change of the attack surface; newly opened ports, services and subdomains.

SOC capacity forecasting

Incident load forecasting and a staffing recommendation engine for shift planning.

What-if simulator

“If I patch these 12 servers, how does my 30-day risk curve change?”

Prescriptive playbooks

From forecast to action; approved and automatic modes, with full rollback.

Backtest and scorecard

A transparent, auditable performance ledger comparing every forecast against what happened.

A

Product-level success metrics

  • Target improvement in mean time to detect (MTTD): ≥ 30%
  • Patch prioritisation accuracy on critical CVEs: Precision@20 ≥ 0.65
  • sMAPE ≤ 18% on traffic and incident volume forecasting at a 24-hour horizon
  • False early warning rate ≤ 10% at the calibrated threshold
  • Actions closed per analyst per day ≥ 12
B

Deployment and governance

  • Multi-tenant architecture; on-premise deployment and SaaS compatible
  • SSO/OIDC/SAML, MFA, RBAC and ABAC authorisation
  • Connector framework to attach to the existing security stack
  • Transparent model governance in which every forecast is verified retrospectively
  • Approval gates and full rollback for automated actions

Module family

  • Asset and attack surface
    CMDB, asset graph, exposure score
  • Vulnerability management
    CVE, KEV/EPSS, patch campaigns
  • Threat intelligence
    STIX/TAXII, actor, campaign, TTP
  • Time series catalogue
    Series definition, frequency, quality
  • Forecasting engine
    Ensemble, conformal, backtest
  • Exploit forecasting
    CVE → exploit probability curve

Request a demo

We can run a short evaluation in your own environment.

Request a demo

Get started

Let us talk about your project.

The first meeting is a discovery session, not a sales pitch. You are also welcome to evaluate our capability directly through a short pilot or proof of concept (PoC) in your own environment.

Fill in the enquiry form

WhatsApp