AIToday
Top Companies' AI MovesAI Business & IndustryAI Safety & AlignmentTop Companies AIPublished: Sep 3, 2026, 06:31 JST2 min read

NEC launches AI-driven managed vulnerability service

NEC launches AI-driven managed vulnerability service

Key takeaway

  • NEC has launched an AI-powered managed security service.

  • It automates vulnerability checks, prioritization, and patch proposals.

  • The service starts at the end of September with three menus.

3 Key Points

  1. What happened

    NEC announced BluStellar Intelligent Managed Service on September 2. It covers vulnerability scanning through automated patch application, with three service menus available from the end of September. The company targets ¥30 billion in sales over the next three years.

  2. Why it matters

    The service combines NEC's security expertise with AI from partners including Anthropic, OpenAI, and Google to shift security operations from manual, people-centered work toward AI-centered automation. NEC aims to reduce the burden on IT and security teams and improve threat defense and business continuity for customers.

  3. What to watch

    The core offering, vulnerability management, uses NEC's cotomi Security for Industry AI. New features include Threat-Driven Security Assessment and an expanded CyIOC system risk diagnosis starting in late September. From December, options include scans within Japan's cloud environment and a 'zero data retention' contract that deletes source code after diagnosis.

Ask the AI about this article →

Context & Analysis

NEC's announcement reflects a broader push to apply frontier AI models to cybersecurity operations, a field traditionally dependent on manual analysis by experts. By partnering with major AI vendors like Anthropic, OpenAI, and Google, NEC aims to augment its proprietary security technology with external innovation. The company's plan to evolve toward autonomous AI agents for vulnerability response signals a long-term strategic direction, though the current services still combine AI with human expert verification.

The service structure shows a phased approach: initial offerings focus on visualization, triage suggestions, and defense planning. NEC has scheduled expansions for the second half of 2026, including faster detection-to-response processes and automated defense measures, with further advanced managed services planned from fiscal 2027 onward. The use of CISA's BOD 26-04 framework for triage and the inclusion of Pre-CVE information, which covers vulnerabilities not yet assigned a CVE identifier, indicates an intent to move beyond conventional CVE-based response methods. The projected ¥30 billion in sales over three years suggests NEC sees managed security services as a significant growth area.

FAQ

When will NEC's new service become available?
The three service menus will be offered starting at the end of September. The Threat-Driven Security Assessment and the expanded CyIOC system risk diagnosis will also be provided from the end of September, with additional options from December.
What is the 'zero data retention' option?
Starting in December, NEC will offer an option to completely delete source code after a vulnerability diagnosis. This contract is designed to maintain customer confidentiality by limiting the diagnosis to Japan-based cloud environments.
Top Companies AIRead Original Article

Get the latest Top Companies' AI Moves news every morning

For example, today's edition would include:

  • Vertiv to Buy UtilityInnovation for $1.45BTop Companies AI · 2h ago
  • Interactive Brokers bets on AI-assisted investingTop Companies AI · 2h ago
  • MBody AI Orchestrator Named Finalist for AI Deployment of the YearTop Companies AI · 2h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleMicrosoft IQ and Copilot Cowork/Scout: AI agents move from chat to autonomous execution