
Financial Services
How a Fortune 500 Insurer Automated Risk Tracing into a Board-Ready Exposure Map
This is the default text value
A global manufacturing leader operates across continents, with a workforce in the tens of thousands. Its security team is responsible for a vast digital estate that spans cloud workloads, application code, and infrastructure across a large portfolio of business applications. The organization wanted to replace a traditional, high-volume vulnerability management process with one that could tell hundreds of engineers what actually mattered, give them AI assistance to act on it, and defensibly prove exposure reduction to leadership.
The company's vulnerability management program consumed significant engineering time and carried recurring licensing costs the team wanted to retire.
But the deeper problem was signal. Across cloud, application, and infrastructure scanners, the organization was uncovering vulnerabilities at a volume in the millions. Ranking by CVSS alone gave remediation teams no reliable way to know which of those vulns were genuinely exploitable in their environment, and product teams pushed back when handed long lists without that context.
Tracking was manual, spread across spreadsheets and chat threads, with no single source of truth that product owners, developers, security, and leadership could share. That created friction between security and the IT and development teams who owned the fixes. With growing regulatory demands, the company also needed a defensible way to analyze and route application security vulnerabilities, and executives wanted reporting framed around exposure reduced rather than raw vulnerability counts.
The organization deployed Zafran as the central platform for its CTEM program, ingesting and correlating vulnerabilities from across its stack and mapping each one to assets and owners using CMDB data, so every vuln carried the business context teams needed to act. To cut through the volume, Zafran assesses what is actually exploitable in the environment. It ingests compensating controls from the tools the company already runs, including cloud security groups, firewalls, and endpoint protection, and lowers a CVE’s applicable risk score when a control already neutralizes it, such as a security group that blocks the affected port.
Most of the engineers receiving that work are product and application owners, not security specialists, so the company leaned heavily on Zafran's Agentic AI to close the knowledge gap. Zafran's AI assistant is available on every page and inside each work item, so an engineer can open a ticket in Jira, jump to Zafran, and ask in plain language what a specific CVE means, why it matters, and how to fix it, without waiting on the security team or starting a fresh investigation. The company set out to make this assistant the go-to tool for its remediation teams, guiding people straight to the fix with pre-populated prompts. The team is also rolling out autonomous agents that run scheduled workflows, such as watching threat intelligence for new zero-days against its environment, and ran hands-on enablement sessions to put these capabilities in front of its wider cyber division. On top of this, executive dashboards tie all of this activity to exposure reduction over time, giving the CISO and leadership a clear view of exposure removed.
The company moved from a custom-maintained, high-volume process to a single, exploitability-driven platform, going live across the organization almost immediately. After the deployment, the organization:

These outcomes gave the company a scalable, evidence-based foundation for vulnerability management across a large and distributed environment. They reduced friction between security and remediation teams, put AI-assisted guidance in the hands of the engineers doing the fixing, and shifted the executive conversation from how many vulnerabilities exist to how much exposure has been removed.
Zafran is the only end-to-end AI-native Threat Exposure Management platform that combines continuous vulnerability detection with deep mapping of vulnerabilities to compensating controls to determine what is actually exploitable in your environment.
See why leading enterprises trust Zafran to focus on what actually matters. Discover the new operating model for vulnerability management.
Hours per Month Saved Via Agentic AI
See Zafran in action
See Zafran in Action
Prioritize and fix what is truly exploitable using risk context from your existing security tools