Skip to content

Astelia Says Vulnerability Prioritization Is Solving the Wrong Problem

CYBR.SEC.CON LaunchPad finalist Astelia uses attack-path reachability to determine which vulnerabilities can actually lead to a breach, helping enterprises cut through millions of findings and focus remediation where it matters.

Five cybersecurity startups. A panel of CISOs, investors, marketing and revenue leaders. And a chance to prove that what they've built can solve a problem security practitioners actually care about.

That's the idea behind LaunchPad, the startup competition making its debut at CYBR.SEC.CON 2026 in Houston Sept. 15-16.

As we outlined when we introduced the five finalists, LaunchPad is designed to give promising early-stage cybersecurity companies something they don't always get: direct exposure to the people who buy, use, evaluate, fund and help bring security products to market.

Full LaunchPad coverage:

CYBR.SEC.CON LaunchPad: 5 Cybersecurity Startups to Watch
Five early-stage cybersecurity companies will pitch before CISOs, investors, marketing and revenue leaders at the CYBR.SEC.CON 2026 LaunchPad competition in Houston.

Full CYBR.SEC.CON coverage:

CYBR.SEC.CON 2026: News, Speakers, Agenda & Coverage
Follow CYBR.SEC.CON 2026 in Houston with the latest news, speakers, keynotes, agenda, cybersecurity tracks, AI.SEC.CON highlights, interviews and event coverage.

The five finalists will pitch their companies during CYBR.SEC.CON, where they'll be evaluated on the problem they're solving, the strength of the technology, market opportunity, differentiation and their ability to turn an idea into a sustainable cybersecurity business.

But a pitch can only tell you so much.

So ahead of CYBR.SEC.CON, CYBR.SEC.Media is profiling each of the five LaunchPad finalists individually. We're asking the founders what problem pushed them to build their companies, who they're building for, what separates their approach from what's already on the market and what success looks like from the perspective of the security practitioner.

Next up is Astelia, where Co-Founder and CEO Alon Noy is challenging one of the fundamental assumptions behind modern vulnerability management: that security teams need a better way to prioritize their vulnerabilities.

Noy thinks they're asking the wrong question.

Most vulnerability-management programs start with enormous numbers of findings and then try to whittle them down. CVSS scores, exploitability, asset criticality, business context and other signals can all be used to decide which vulnerabilities deserve attention first.

Astelia takes a different approach. Instead of asking how high a vulnerability should rank, the company asks whether an attacker can actually reach it in that organization's environment.

The answer, Noy says, should ultimately be binary: yes or no.

That distinction matters because enterprise vulnerability teams aren't suffering from a shortage of findings. Large organizations can be managing millions of assets and tens or even hundreds of millions of vulnerabilities across cloud, hybrid, on-premises and OT environments. The challenge is figuring out which ones can realistically become part of an attack path leading to a breach.

For one early Astelia customer, the difference was dramatic. A global telecommunications company entered the process with roughly 3 million vulnerabilities. Astelia's reachability analysis reduced that universe to 32 vulnerabilities requiring immediate attention.

And Noy argues AI is making that distinction increasingly important. As AI accelerates vulnerability analysis and exploitation, organizations have less time to wait for public exploitability data before deciding what to fix. His argument is that defenders should increasingly assume meaningful vulnerabilities will eventually become exploitable and instead concentrate on the question specific to their own environment: Can an attacker reach it?

Here's our Q&A with Astelia Co-Founder and CEO Alon Noy.

What problem did you see in the market that convinced you this company needed to exist?

Alon Noy: Vulnerability management has always been a difficult problem. The challenge is determining which vulnerabilities can actually lead to a breach and remediating them before attackers exploit them.

After spending 15 years leading the Israeli National Red Team, I saw firsthand how difficult this problem was even before AI. Today, AI has dramatically accelerated attackers' capabilities. Vulnerabilities can be analyzed and exploited in seconds, and the volume continues to grow.

The traditional approaches to vulnerability management are no longer sufficient. Organizations need a way to determine which vulnerabilities truly matter in their specific environments and focus remediation efforts accordingly.

Who is the ideal customer for your solution?

Alon Noy: Every organization has this problem, but Astelia delivers the greatest value to large enterprises operating at massive scale.

Our ideal customers manage millions of assets, tens or hundreds of millions of vulnerabilities and complex environments that span cloud, hybrid, on-premises and even OT infrastructure. These organizations struggle with both prioritization and remediation because of the sheer volume of exposure data they must manage.

Those are the environments where Astelia shines because we help cut through overwhelming amounts of noise and focus teams on what truly matters.

What makes your approach fundamentally different from other security vendors?

Alon Noy: Most vendors focus on prioritization. Some rely on CVSS scores. Others incorporate additional context such as asset criticality, business impact or data sensitivity.

We take a different approach.

Rather than prioritizing vulnerabilities, we determine whether each vulnerability is actually reachable within the customer's environment. The answer is binary: yes or no.

There is sophisticated technology behind that determination, but the outcome is simple. By proving which vulnerabilities are reachable and which are not, we dramatically reduce noise and help organizations focus only on exposures that can realistically be exploited.

Can you share a customer story or proof point?

Alon Noy: One of our earliest customers was Syniverse, a large global telecommunications company.

When they started, they were dealing with roughly three million vulnerabilities. Traditional approaches reduced that number somewhat, but not enough to create meaningful focus.

Using Astelia's reachability analysis, we reduced that universe to just 32 vulnerabilities that actually required immediate attention.

The key difference is that every conclusion is backed by evidence. We show customers the attack path proving why a vulnerability is reachable. For vulnerabilities that are not reachable, we provide evidence explaining why they can confidently defer remediation.

That creates trust between security and IT teams while significantly improving operational efficiency.

What is the biggest misconception buyers have about the problem you're solving?

Alon Noy: Many organizations still rely heavily on public exploitability as a filtering mechanism.

That approach is becoming less effective. AI has dramatically reduced the time between vulnerability disclosure and exploitation. In some cases, vulnerabilities are being exploited almost immediately after they become public.

We believe organizations should assume that nearly every meaningful vulnerability will become exploitable. The more important question is whether that vulnerability is actually reachable within your environment.

Reachability is what matters. It is the factor most relevant to the specific conditions of each organization and the most effective way to reduce noise.

What has been the hardest challenge in building the company?

Alon Noy: From a business perspective, one of the biggest challenges has been transitioning from founder-led sales to building a scalable go-to-market organization.

In the early stages, I personally drove much of the revenue generation. As the company grows, you have to build repeatable processes, develop a strong sales organization and transfer credibility beyond the founders themselves.

From a product perspective, scaling to support the world's largest enterprises has been equally challenging. Our platform must analyze enormous volumes of vulnerability data while maintaining speed, responsiveness and reliability. Building that level of scalability required significant effort from the engineering team.

If we were having this conversation a year from now, what milestone would tell you the company is succeeding?

Alon Noy: Success would mean broad adoption among the largest enterprises in the world.

We're seeing strong momentum with Fortune 500 organizations and even some of the world's largest companies. A year from now, I want Astelia deployed across many Fortune 10, Fortune 50 and Fortune 100 organizations as a core part of their vulnerability management and remediation programs.

That level of adoption would validate both the market need and our approach.

Why is now the right time for this company and solution to exist?

Alon Noy: AI has fundamentally changed the threat landscape.

Even before the latest advances in AI, attackers were becoming faster and more effective. AI has accelerated that trend dramatically and exposed the limitations of traditional vulnerability-management approaches.

What was once a technical challenge for security teams has become a board-level issue. Organizations urgently need a better way to identify the vulnerabilities that truly matter and focus resources where they will have the greatest impact.

The timing could not be more relevant.

What does success look like for the security practitioner using your product every day?

Alon Noy: For years, vulnerability-management teams have been overwhelmed by endless lists of findings and constant battles over prioritization.

Success means reversing that experience.

Astelia users should begin each day knowing exactly which vulnerabilities can realistically lead to a breach. They should have confidence in the data, credibility with leadership and a clear path toward remediation.

Instead of being viewed as the team constantly raising alarms, they become trusted advisors who help the organization focus on the risks that truly matter. That saves time, reduces costs and improves security outcomes across the business.

HOU.SEC.CON CTA

Latest