Insight launches AI-supported cybersecurity service suite

Insight has launched a managed service suite designed to help companies find and fix cybersecurity risks in their infrastructure.
Nasdaq-listed Insight is one of the world’s largest technology consulting firms. It helps clients with data science projects, AI rollouts and a wide range of other IT initiatives. Insight also provides certain related offerings including financing for large technology purchases.
The company’s new service suite, Insight Managed Exposure Defense, isn’t its first foray into cybersecurity. Insight has teams that help clients with tasks such as finding software vulnerabilities and applying patches. Jeremy Nelson, Insight’s chief information security officer for North America, explained that the new offering is an evolution of the firm’s existing cybersecurity offerings.

“Insight Managed Exposure Defense unifies Insight’s security capabilities that we have delivered for years into a more consumable, outcome-driven managed service model,” Nelson told Boardroom Insight. “Where clients previously accessed these capabilities through point solutions, IMED is modular, so we can meet clients where they are, fill gaps between existing programs and third-party relationships, and run the work through a consistent security workflow with audit-ready tracking from discovery through remediation.”
The offering is designed to accomplish two main tasks for clients. According to Insight, the first is helping them mitigate any hacker activity that may crop up in their systems. The other is fixing weak points that could lead to breaches in the future.
Insight Managed Exposure Defense scans IT assets such as desktops, data center routers and databases for vulnerabilities. When the consultancy discovers cybersecurity issues, it ranks them based on what it calls a risk-ranked exposure map.
“The ‘real-time, risk-ranked exposure map’ starts with asset discovery and a Business Impact Analysis to quantify which systems matter most to the business,” Nelson explained. “From there, we build a vulnerability catalog and run it through Insight-developed AI/ML logic that refines risk based on business context, not just CVSS severity. Our continuous penetration testing then validates real-world exploitability, producing a True Risk Score that drives remediation priority.”
Insight can not only find vulnerabilities but also patch them, which often isn’t as simple as downloading an update. Engineers have to verify that a patch won’t cause technical issues before releasing it to production. Additionally, they need a way to roll back the update if a bug goes unnoticed.
Insight addresses those requirements with a phased approach to implementing cybersecurity patches. The methodology revolves around so-called test rings.
“’Test rings’ refer to the controlled way patches are deployed before broad rollout,” Nelson said. “Planned vulnerabilities move into the weekly patch backlog that deploy patches to predetermined system ‘rings’ based on business impact and fault tolerance, while critical exposures are escalated into a security incident workflow governed by a 24-hour SLA. The goal is simple: reduce real risk quickly without creating unnecessary operational disruption.”
If a vendor-provided patch isn’t available for a vulnerable application, Insight can bring in engineers to write the necessary code. Additionally, Insight Managed Exposure Defense provides access to a managed XDR service. The latter offering helps clients detect and respond to hacker activity in their networks. According to Insight, the XDR service is delivered round-the-clock by a business unit that employs cybersecurity professionals in multiple time zones.
Photo courtesy of Insight