A Compensating Control That Makes Vulnerabilities Unreachable.
Patch on Your Schedule.
- Make difficult to patch assets and crown-jewel systems invisible to attackers
- Eliminate your zero-day risks and your concerns while waiting for patches
- End your emergency-patch fire drill and move to a planned remediation schedule
Patching Alone Will Never Get You There
You Have an Intractable Backlog
Patching devours your team.
With a Flood of New CVEs
Disclosures keep outpacing your capacity to patch.
And Unpatchable Assets
Some systems you simply can't patch.
You Accept Too Much Risk
Waivers and exceptions keep piling up.
Attackers have automated discovery and exploitation. Your patch cycle has not gotten faster. You can patch it, wrap it in filters, or accept the risk.
You Need More Options
Attackers and Their AI Can't Exploit What They Can't Reach
Vulnerability Cloaking removes the inbound path entirely: workloads connect outbound to a private, dedicated Zero Trust fabric, and identity-based policy keeps authorized users and services connected.
Cloak the Vulnerable, Shield the Valuable
Take Control of Your Backlog
Once an asset is unreachable, a new vulnerability is no longer an emergency, however it surfaced. Cloaking mitigates the risk in minutes; you patch later, on your own schedule, maintaining uptime.
The next critical CVE becomes a non-event.
Secure the Unpatchable
Vulnerability Cloaking makes your unpatchable assets invisible to attackers. A flaw you can't fix stops being a vulnerability anyone can reach, and your systems stay in production.
The unpatchable stops being your weak point.
Protect Anything, Inside and Out
One control covers the systems you cannot patch and the systems you cannot lose: legacy & end-of-life apps; OT & IoT; third-party & embedded; cloud & on-premises; AI agents & services. On any network, with no exclusions.
Cloak a single asset or your entire estate.
Eliminate Accepted Risk
Your most critical systems collect the most waivers, because criticality is exactly what blocks the patch window. Once the asset is unreachable, the exception has nothing left to cover, and the risk you approved on paper disappears in practice.
There's no risk left to accept.
Move From Emergency Patching to Planned Remediation
Vulnerability management, virtual patching, and CTEM attempt to defend vulnerable assets while leaving them connected. Vulnerability Cloaking removes the target instead. The same control that hides an unpatchable asset hides a crown-jewel system with no currently-known vulnerabilities.
Legacy Vulnerability Management
Patch under pressure, accept what you can't.
- Every new CVE forces an unplanned, emergency change window
- Assets you can't patch pile up as risk exceptions and waivers
- AI-driven discovery grows the backlog faster than any team can clear it
- Emergency patches carry their own outage and rollback risk
Virtual Patching
Defend a live target, and keep firefighting.
- The vulnerable asset stays connected and reachable
- A detection and filtering layer sits in front of a still-vulnerable asset
- Signatures, WAF policies, and IDS/IPS rules need constant updating as new CVEs land
- Monitor for whatever slips through
NetFoundry Vulnerability Cloaking
Remove the target. Stop firefighting.
- The asset is lifted off the network, invisible to attackers
- Nothing to confirm: there is no reachable flaw to exploit
- Nothing to filter: no inbound path exists
- Nothing to update: no signatures or rules to chase
- Authorized identities still connect, exactly as before
Lower Risk, Steadier Operations, Lower Cost
Nothing left to exploit
No zero-day panic, no race against time-to-exploitation, however fast the flaw was found.
Lateral movement stops at the boundary
An attacker who gains a foothold elsewhere in the environment finds no path to a cloaked asset.
The daily fire drill ends
Emergency patching and unplanned change windows give way to centralized, identity-based policy.
Cloaked in minutes, not change windows
No new hardware, no VLAN changes, no firewall rule sprawl, and no network re-architecture.
Policy follows the asset, not the address
Cloaking is managed by identity, so it doesn't break when topology, IP addresses, or subnets change.
No emergency re-platforming
You avoid costly emergency fixes and rebuilds undertaken only to make a patch possible.
A Compensating Control, Not a Standing Exception
An exception documents a risk you decided to live with. A compensating control documents a risk you did something about. Vulnerability Cloaking gives security and IT leaders identity-based, auditable proof of which vulnerable and high-value assets are reachable, and by whom.
Identity-based visibility
Policy defines exactly which vulnerable and high-value assets are cloaked and who may reach them, with a historical record of what was exposed, and when.
Exceptions close, they don't accumulate
As scanners and AI-driven analysis flag new assets, cloaking policy follows automatically, and when an asset is finally patched or retired, the exception it carried retires with it.
Compliance evidence
A smaller, cleaner audit surface maps to industry and regulatory requirements. Where governance demands separation between OT and IT, policy can enforce it.
Start With One Workload
Cloak a single unpatchable system or a fresh KEV first, prove the outcome, then expand at your own pace. There is no months-long project to map flows, IP addresses, routes, and firewalls, no rip-and-replace, no forced backhaul, and no big-bang rollout.
Value in days, not quarters.
Vulnerability Cloaking, Answered
What is vulnerability cloaking?
Vulnerability cloaking is a network-isolating compensating control that removes the inbound path to an asset. The asset dials outbound to a private Zero Trust fabric instead of listening for inbound connections, so it has no open ports for an attacker to find and never appears in attacker-visible scans.
Is vulnerability cloaking a compensating control?
Yes. It gives security and IT leaders a documented, identity-based control over which vulnerable and high-value assets are reachable, and by whom. Because the exposure is removed rather than accepted, the risk exception a vulnerable asset would otherwise carry has nothing left to cover.
How is vulnerability cloaking different from virtual patching?
Virtual patching leaves the vulnerable asset connected and puts a detection and filtering layer in front of it, which needs constant signature and rule updates. Cloaking removes the target instead. No inbound path exists, so there is nothing to confirm, nothing to filter, and no rules to chase.
Can you cloak an asset that cannot be patched?
Yes. Legacy and end-of-life applications, OT and IoT systems, third-party and embedded software, cloud and on-premises workloads, and AI agents and services can all be cloaked. A flaw you cannot fix stops being a vulnerability anyone can reach, and the system stays in production.
Does cloaking block authorized users?
No. Authorized identities connect exactly as before. Access is governed by identity-based policy rather than by IP address or subnet, so the policy follows the asset and does not break when topology, IP addresses, or subnets change.
How long does it take to cloak a vulnerable asset?
Cloaking mitigates the risk in minutes rather than through an emergency change window. There is no new hardware, no VLAN changes, no firewall rule sprawl, and no network re-architecture. You can start with a single workload, prove the outcome, and expand from there.
What if a vulnerability's time-to-exploit is shorter than my patch cycle?
Vulnerability Cloaking closes that gap by removing the inbound path to the asset rather than racing the patch. The asset dials outbound to a private Zero Trust fabric and exposes no inbound ports, so an attacker has nothing to reach even before a patch exists. Cloaking mitigates the exposure in minutes, and you apply the vendor patch later, on your own schedule.
How does Vulnerability Cloaking help with the explosion of CVEs, sometimes called the vulnpocalypse?
AI-assisted discovery is surfacing vulnerabilities faster than any team can patch them, which turns raw CVE volume into a losing race. Cloaking changes the terms: once an asset is unreachable, a newly disclosed vulnerability on it is no longer an emergency, however it surfaced. You cloak the asset in minutes, and the next critical CVE becomes a non-event rather than another unplanned change window.
Can Vulnerability Cloaking defend against AI-powered cyberattacks?
Automated and AI-driven attackers still have to find and reach a target before they can exploit it. Cloaking removes both steps: the asset has no open inbound ports and never appears in attacker-visible scans, so there is nothing for an attacker or its AI to discover or exploit. Authorized identities connect as before, governed by identity-based policy.
Make Your Vulnerable Assets Unreachable
See Vulnerability Cloaking take a vulnerable workload off the attackers' map in minutes.