When AI identifies vulnerabilities more quickly: How CANCOM Austria keeps your networks secure
The way in which organisations need to identify, assess and remediate security vulnerabilities is undergoing a fundamental change. What was previously often organised as a reactive process based on individual security advisories is increasingly evolving into a continuous, data-driven and highly automated operational model. The reason for this is the massive increase in the speed at which vulnerabilities can be identified today.
The speed at which security vulnerabilities can now be discovered, assessed and potentially exploited is fundamentally transforming vulnerability and risk management. AI models such as Claude Mythos, GPT Cyber or specialised agent-based analysis tools are now capable of analysing even highly complex software with millions of lines of source code with a depth and speed that is increasingly putting traditional security processes under pressure. This development is also reflected in the official CVE figures. CVE stands for Common Vulnerabilities and Exposures and refers to globally standardised identifiers for publicly known security vulnerabilities. According to the CVE programme, 35,872 CVE records were published in the first half of 2026. In the same period the previous year, the figure was 23,710. This represents an increase of around 51 per cent in just one year. [cve.org]
“We are talking about what is known as the ‘post-myth era’, because AI is changing the rules of the game in vulnerability management,” says Thomas Gerbafczits, Senior Director of Network Solutions at CANCOM Austria. “This development is only just beginning, but its momentum is already clearly visible. In future, companies will be faced with more security advisories and software releases and, as a result, will have to make operational decisions more frequently.”
The term‘post-Mythos era’refers to Claude Mythos, a frontier model developed by Anthropic that was used in the context of defensive cybersecurity research. This gave rise to Project Glasswing, a cross-vendor initiative to secure critical software in the AI era. Partners from day one included, amongst others, Anthropic, Amazon, Apple, Google, Microsoft and Cisco – the only end-to-end provider for critical infrastructure. Cisco is thus part of an industry-leading initiative that views AI not only as a risk, but also as a tool for securing critical software more quickly and systematically. [anthropic.com]
This development is particularly relevant for Cisco. Cisco operates significant parts of the global network infrastructure and, through its technologies, serves campus networks, data centre infrastructures, WAN environments, security platforms, service provider networks and critical infrastructure. Cisco has therefore further developed its PSIRT process and is providing customers with more predictable security bulletins. [sec.clouda....cisco.com], [blogs.cisco.com]
Hans Greiner, General Manager of Cisco Systems Austria, also sees this development as highlighting the need for close partnerships between manufacturers, integrators and customers: “The new pace of AI-powered vulnerability analysis requires predictable, scalable and collaborative approaches to vulnerability management. Particularly when it comes to critical infrastructure, it is crucial to closely align manufacturer innovations, automation and qualified implementation expertise.”
PSIRT stands for Product Security Incident Response Team. This refers to the organisation within a manufacturer that identifies, assesses and documents security vulnerabilities and publishes corresponding security advisories. Since July 2026, Cisco has been following a more predictable, risk-based disclosure model, with publications generally issued twice a month and advance notice of affected technologies and platforms provided seven days in advance. [sec.clouda....cisco.com], [blogs.cisco.com]
“For operators of large network infrastructures, this predictability is hugely important,” explains Gerbafczits. “It makes it easier to integrate security patching into existing change, testing and release processes. Customers can prepare maintenance windows, lab validations and internal approvals in good time. This is a key difference from a reactive ‘firefighting’ model.”
Another change concerns the handling of CVEs. A CVE is the unique reference number for a specific security issue, enabling manufacturers, customers, security teams and tools to refer to the same risk.
Cisco is partially transitioning to so-called ‘bundled CVEs ’. This involves addressing several vulnerabilities of the same error class collectively. Such classes of vulnerabilities are described using CWEs, or Common Weakness Enumerations. Whilst a CVE describes a specific vulnerability, a CWE refers to the underlying class of vulnerabilities, such as faulty input validation or inadequate access control. Cisco describes this approach as part of a risk-based disclosure model, in which related vulnerabilities can be grouped under overarching CVE IDs. [sec.clouda....cisco.com]
“The focus is thus shifting from the assessment of individual CVEs to the question of how quickly an organisation can bring its infrastructure up to a secure, up-to-date and validated software version,” says Gerbafczits. “In an AI-accelerated world, the crucial question is no longer simply whether a single vulnerability exists. What matters is how quickly and in a controlled manner an organisation can harden its entire affected infrastructure.”
In parallel, Cisco is developing Antares, a set of specialised Small Language Models( SLMs) for security use cases. Unlike very large language models, SLMs are smaller, more focused and optimised for specific tasks, such as identifying known vulnerabilities in large codebases. [newsroom.cisco.com], [securityweek.com]
“This is an important indication of the future direction,” says Gerbafczits. “The future will not consist solely of large, universal LLMs. Specialised models will play a key role, particularly in the security and infrastructure sectors, because they can solve specific tasks more efficiently, in a more transparent manner and, in some cases, with greater data sovereignty.”
This is precisely where CANCOM Austria comes in with a unique end-to-end solution approach. This combines transparency, intelligent analysis, AI-supported planning and automated implementation into a seamless process.
The starting point is the CANCOM Inventory Engine. It provides a continuously updated view of the installed network landscape and shows which components are actually in use, such as switches, routers, firewalls, Wi-Fi systems and data centre components.
The solution identifies technical details such as hardware types, serial numbers, operating system versions, and lifecycle and support information. A comparison with relevant manufacturer databases is carried out via APIs. Through intelligent analysis and processing based on CANCOM Austria’s many years of experience, it becomes clear which systems are affected by security advisories, which CVEs are relevant, whether there are end-of-support risks, and which software versions are recommended.
The information collected is then consolidated in the CANCOM Data Analytics Platform and analysed intelligently. The platform identifies lifecycle risks, end-of-life hardware models, compliance deviations, security advisories, specific vulnerabilities, non-standard software versions and potential upgrade risks.
“Distributed technical data is transformed into a usable basis for decision-making,” says Gerbafczits. “Customers don’t just see that a vulnerability exists somewhere. They see whether and where they are affected within their specific infrastructure, which systems need to be prioritised, and what measures need to be taken as a result.”
Once a vulnerability is identified, the most difficult part begins: implementation. An operating system upgrade within an enterprise network infrastructure is no ordinary software update. It involves maintenance windows, high availability, redundancies, application dependencies, rollback plans, change documentation and post-installation tests. This is particularly relevant when operating critical infrastructure, in hospitals, at energy suppliers, in industry, in the financial sector and in the public sector. These organisations cannot afford to accept downtime at will.
Cisco addresses these dynamic challenges with solutions such as Cisco Live Protect and Cisco Cloud Control. These technologies and platforms help to reduce the risk between the time a vulnerability is disclosed and the actual patch deployment. Cisco describes Live Protect as a way of mitigating CVE-related threats in real time, including through eBPF-based Security Shields and without the need for reboots or disruptive maintenance windows. eBPF stands for extended Berkeley Packet Filter and enables deep visibility and control within the Linux kernel of network components. [cisco.com], [networkworld.com]
“Live Protect is no substitute for a permanent software upgrade, but it can buy valuable time. On supported Cisco platforms, validated Security Shields can be activated without a reboot or disruptive maintenance windows,” says Greiner. “Particularly in the case of large-scale infrastructures, this can be crucial for reducing risks in the short term, maintaining ongoing operations, whilst still carefully planning, testing and implementing the necessary upgrade. With this approach, Cisco is therefore setting new standards for securing critical network infrastructures.”
For the specific assessment and planning of software upgrades, CANCOM Austria relies on AIOps, i.e. the use of artificial intelligence in IT operations. The CANCOM Software Upgrade AI, developed specifically for this purpose, automatically correlates information from various sources, including hardware models, current software versions, configurations, Cisco release notes, bug databases, security advisories, lifecycle information, known incompatibilities and best-practice recommendations.
The benefit is immediate: engineers no longer have to spend hours manually sifting through documentation, release notes, bug IDs, compatibility matrices and security advisories. The AI processes this information in a structured manner, establishes relevant connections and assists in identifying suitable upgrade paths. Initial deployments show that the time and effort required for analysis and preparation can be reduced by around 50 to 90 per cent, depending on the initial situation.
“CANCOM Software Upgrade AI helps us to automatically correlate large volumes of technical information, identify upgrade risks at an early stage and create a robust basis for decision-making,” explains Paul Freitag, Senior Network System Engineer at CANCOM Austria. “AI does not replace technical expertise, but rather enhances it. Particularly in critical infrastructures, the results must be technically validated, prioritised and contextualised within the specific operational environment. That is why we consistently rely on a ‘human-in-the-loop’ approach.”
Implementation in large network environments presents a further challenge. Major clients rarely operate just one platform or a single central management system. Typically, such environments consist of several domains such as campus LAN, Wi-Fi, data centre networking, WAN and OT networks. Added to these are platforms such as Catalyst, Nexus, Meraki, Industrial Ethernet and ASR, as well as various software families such as IOS XE, IOS XR and NX-OS.
Cisco provides powerful management platforms for these domains, such as Cisco Catalyst Centre for campus LAN and Wi-Fi, Cisco Catalyst SD-WAN Manager for WAN and SD-WAN environments, and Cisco Nexus Dashboard and Cisco ACI or APIC for data centre networks.
In practice, however, customer environments are often heterogeneous. Alongside Cisco, there are other manufacturers, historically evolved sub-areas, different operating models and multiple levels of automation. This is precisely why CANCOM Austria uses the CANCOM Management Platform, or CMP for short. CMP enables cross-domain network management and automation.
This is supported by the recently enhanced CANCOM Synaptic OS Upgrade Automation Assistant. This is an automation software solution that intelligently guides the entire upgrade process. This begins before the actual implementation with pre-checks, such as verifying redundancies, cluster statuses, reachability, version statuses, dependencies, maintenance windows and potential downtime risks. During implementation, the solution supports standardised upgrade steps. Following the upgrade, automated post-checks are carried out to verify that systems are correctly accessible, services are functioning as expected, redundancies have been restored and defined technical tests have been successfully completed.
“Particularly with very large infrastructures, it is no longer possible to carry out such processes exclusively by hand,” explains Gerbafczits. “As the number of vulnerabilities rises, maintenance windows remain tight and regulatory compliance requirements increase, intelligent automation is essential.”
CANCOM Austria sees a concrete example of this with major clients in the energy supply sector. These infrastructures have often grown over many years, encompassing numerous platforms, multiple network domains and varying software versions. At the same time, internal resources are limited, whilst requirements for availability, security and documentation are rising.
“For such clients, automation is no longer simply a matter of convenience, but an operational necessity,” says Gerbafczits. “Without a clear overview of assets, intelligent analysis, AI-supported upgrade planning and automated implementation, it will be virtually impossible to meet these requirements economically and securely in future.”
Why is CANCOM Austria needed for this? Couldn’t any Cisco partner achieve this? “In principle, any partner can address individual technical components,” says Gerbafczits. “The challenge, however, lies in the combination. Today’s customers need asset transparency, vulnerability intelligence, lifecycle management, automation, change management expertise, an understanding of compliance and operational experience, all within an integrated model.”
Smaller partners in particular are increasingly reaching their limits here, because these requirements can no longer be covered by a single technical team. It requires Cisco-certified network experts, security specialists, AI consultants, data engineers, automation architects, service managers and experience in operating critical infrastructure.
From Cisco’s perspective, too, this combination of manufacturer expertise, local implementation and in-depth operational understanding is crucial. Greiner points to the long-standing collaboration between Cisco and CANCOM in Austria: “CANCOM has been a reliable and highly competent partner for Cisco in Austria for many years, particularly in the field of sophisticated network and security infrastructures. The combination of in-depth Cisco expertise, local implementation skills, decades of experience and a clear focus on the secure operation of large customer environments based on sovereign infrastructure is particularly valuable in the current market situation.”
The CANCOM Sovereign AI Infrastructure plays a central role in this. CANCOM Austria provides the key elements in Austria on its own infrastructure: compute hardware including GPUs, operating systems, container platforms, LLMs, LLM gateways and routers, performance monitoring, guardrails, and the necessary services required to run its own AI applications.
“Network data, configurations and vulnerability information are particularly sensitive,” emphasises Gerbafczits. “For hospitals, energy suppliers, public institutions and other operators of critical infrastructure, data sovereignty, data protection and compliance with regulatory requirements are crucial.”
Regulatory requirements such as the Austrian NISG 2026 implementing the NIS2 Directive, the EU’s DORA Regulation for the financial sector, sector-specific guidelines and increasing audit requirements are also heightening the pressure to act. Organisations must not only operate their infrastructure securely, but also be able to document and demonstrate the effectiveness of their security measures in a transparent manner. This is precisely why CANCOM Austria is continuously developing its solutions. The rapid pace of development reflects the fact that the threat landscape, manufacturers’ processes, technological capabilities and regulatory requirements are all changing just as rapidly.
What sets CANCOM Austria apart in this environment is the combination of local expertise, Cisco specialisation, in-house products, AI expertise and a robust infrastructure. “In Austria, we have the necessary know-how, certified Cisco experts, many years’ experience in operating large network infrastructures and a complete in-house solution stack,” says Gerbafczits. “This includes the CANCOM Inventory Engine, the CANCOM Data Analytics Platform, the CANCOM Software Upgrade AI, the CANCOM Management Platform and the CANCOM Synaptic OS Upgrade Automation Assistant. Combined with our robust AI infrastructure, we believe this is unique.”
The conclusion is therefore clear: in the post-myth era, large network infrastructures can only be operated securely if transparency, AI, automation and qualified experts work together. For CANCOM Austria, this means not only deploying new technologies, but also creating an end-to-end operational approach, ranging from an overview of assets through risk assessment to automated implementation.
“Our task is to actively support customers during this challenging phase,” says Gerbafczits. “This includes transparency regarding the actual installed base, in-depth risk analysis, AI-supported upgrade planning, automation and expert implementation by experienced engineers. In our view, the combination of Cisco expertise, certified engineers in Austria, CANCOM’s own products, AI expertise and a robust AI infrastructure is unique. This enables us to create the conditions for operating even very large network infrastructures securely, efficiently and in a future-proof manner in the post-Mythos era.”