NetFoundry Vulnerability Cloaking

A Compensating Control That Makes Vulnerabilities Unreachable.
Patch on Your Schedule.

  • Make difficult to patch assets and crown-jewel systems invisible to attackers
  • Eliminate your zero-day risks and your concerns while waiting for patches
  • End your emergency-patch fire drill and move to a planned remediation schedule
The Challenge

Patching Alone Will Never Get You There

1

You Have an Intractable Backlog

Patching devours your team.

+
2

With a Flood of New CVEs

Disclosures keep outpacing your capacity to patch.

+
3

And Unpatchable Assets

Some systems you simply can't patch.

=
4

You Accept Too Much Risk

Waivers and exceptions keep piling up.

Attackers have automated discovery and exploitation. Your patch cycle has not gotten faster. You can patch it, wrap it in filters, or accept the risk.

You Need More Options

The Missing Option

Attackers and Their AI Can't Exploit What They Can't Reach

Vulnerability Cloaking removes the inbound path entirely: workloads connect outbound to a private, dedicated Zero Trust fabric, and identity-based policy keeps authorized users and services connected.

Two workloads dial outbound to a private Zero Trust fabric governed by identity-based policy, with no inbound ports, so an attacker scanning IP ranges finds both workloads cloaked. Workload A Cryptographic identity No inbound ports Workload B Cryptographic identity No inbound ports Private Fabric Identity-Based Policy Identity verified IP address ignored Outbound dial IP 10.10.4.12 Outbound dial IP 10.20.7.33 Attacker Scanning IP Ranges CLOAKED CLOAKED
The NetFoundry Solution

Cloak the Vulnerable, Shield the Valuable

Take Control of Your Backlog

Once an asset is unreachable, a new vulnerability is no longer an emergency, however it surfaced. Cloaking mitigates the risk in minutes; you patch later, on your own schedule, maintaining uptime.

The next critical CVE becomes a non-event.

Secure the Unpatchable

Vulnerability Cloaking makes your unpatchable assets invisible to attackers. A flaw you can't fix stops being a vulnerability anyone can reach, and your systems stay in production.

The unpatchable stops being your weak point.

Protect Anything, Inside and Out

One control covers the systems you cannot patch and the systems you cannot lose: legacy & end-of-life apps; OT & IoT; third-party & embedded; cloud & on-premises; AI agents & services. On any network, with no exclusions.

Cloak a single asset or your entire estate.

Eliminate Accepted Risk

Your most critical systems collect the most waivers, because criticality is exactly what blocks the patch window. Once the asset is unreachable, the exception has nothing left to cover, and the risk you approved on paper disappears in practice.

There's no risk left to accept.

Why It's Different

Move From Emergency Patching to Planned Remediation

Vulnerability management, virtual patching, and CTEM attempt to defend vulnerable assets while leaving them connected. Vulnerability Cloaking removes the target instead. The same control that hides an unpatchable asset hides a crown-jewel system with no currently-known vulnerabilities.

Legacy Vulnerability Management

Patch under pressure, accept what you can't.

  • Every new CVE forces an unplanned, emergency change window
  • Assets you can't patch pile up as risk exceptions and waivers
  • AI-driven discovery grows the backlog faster than any team can clear it
  • Emergency patches carry their own outage and rollback risk

Virtual Patching

Defend a live target, and keep firefighting.

  • The vulnerable asset stays connected and reachable
  • A detection and filtering layer sits in front of a still-vulnerable asset
  • Signatures, WAF policies, and IDS/IPS rules need constant updating as new CVEs land
  • Monitor for whatever slips through

NetFoundry Vulnerability Cloaking

Remove the target. Stop firefighting.

  • The asset is lifted off the network, invisible to attackers
  • Nothing to confirm: there is no reachable flaw to exploit
  • Nothing to filter: no inbound path exists
  • Nothing to update: no signatures or rules to chase
  • Authorized identities still connect, exactly as before
What Changes

Lower Risk, Steadier Operations, Lower Cost

Nothing left to exploit

No zero-day panic, no race against time-to-exploitation, however fast the flaw was found.

Lateral movement stops at the boundary

An attacker who gains a foothold elsewhere in the environment finds no path to a cloaked asset.

The daily fire drill ends

Emergency patching and unplanned change windows give way to centralized, identity-based policy.

Cloaked in minutes, not change windows

No new hardware, no VLAN changes, no firewall rule sprawl, and no network re-architecture.

Policy follows the asset, not the address

Cloaking is managed by identity, so it doesn't break when topology, IP addresses, or subnets change.

No emergency re-platforming

You avoid costly emergency fixes and rebuilds undertaken only to make a patch possible.

Governance & Compliance

A Compensating Control, Not a Standing Exception

An exception documents a risk you decided to live with. A compensating control documents a risk you did something about. Vulnerability Cloaking gives security and IT leaders identity-based, auditable proof of which vulnerable and high-value assets are reachable, and by whom.

Identity-based visibility

Policy defines exactly which vulnerable and high-value assets are cloaked and who may reach them, with a historical record of what was exposed, and when.

Exceptions close, they don't accumulate

As scanners and AI-driven analysis flag new assets, cloaking policy follows automatically, and when an asset is finally patched or retired, the exception it carried retires with it.

Compliance evidence

A smaller, cleaner audit surface maps to industry and regulatory requirements. Where governance demands separation between OT and IT, policy can enforce it.

In Production

Trusted Where Failure Isn't an Option

The organizations that can least afford downtime also can't afford delay. NetFoundry delivers production-grade security and connectivity that clears review instead of stalling in it.

3,000companies use NetFoundry
2 of 5largest US companies connect with NetFoundry
8 of 10largest US banks connect with NetFoundry
1B+sessions per month across global infrastructure
#1most widely deployed open source Zero Trust networking platform
"NetFoundry presented us with the opportunity to reset the old clichés and to disrupt long-standing operating models" Damir Jaksic, Chief Information Officer, KEO International Consultants
Get Started

Start With One Workload

Cloak a single unpatchable system or a fresh KEV first, prove the outcome, then expand at your own pace. There is no months-long project to map flows, IP addresses, routes, and firewalls, no rip-and-replace, no forced backhaul, and no big-bang rollout.

Value in days, not quarters.

Questions

Vulnerability Cloaking, Answered

What is vulnerability cloaking?

Vulnerability cloaking is a network-isolating compensating control that removes the inbound path to an asset. The asset dials outbound to a private Zero Trust fabric instead of listening for inbound connections, so it has no open ports for an attacker to find and never appears in attacker-visible scans.

Is vulnerability cloaking a compensating control?

Yes. It gives security and IT leaders a documented, identity-based control over which vulnerable and high-value assets are reachable, and by whom. Because the exposure is removed rather than accepted, the risk exception a vulnerable asset would otherwise carry has nothing left to cover.

How is vulnerability cloaking different from virtual patching?

Virtual patching leaves the vulnerable asset connected and puts a detection and filtering layer in front of it, which needs constant signature and rule updates. Cloaking removes the target instead. No inbound path exists, so there is nothing to confirm, nothing to filter, and no rules to chase.

Can you cloak an asset that cannot be patched?

Yes. Legacy and end-of-life applications, OT and IoT systems, third-party and embedded software, cloud and on-premises workloads, and AI agents and services can all be cloaked. A flaw you cannot fix stops being a vulnerability anyone can reach, and the system stays in production.

Does cloaking block authorized users?

No. Authorized identities connect exactly as before. Access is governed by identity-based policy rather than by IP address or subnet, so the policy follows the asset and does not break when topology, IP addresses, or subnets change.

How long does it take to cloak a vulnerable asset?

Cloaking mitigates the risk in minutes rather than through an emergency change window. There is no new hardware, no VLAN changes, no firewall rule sprawl, and no network re-architecture. You can start with a single workload, prove the outcome, and expand from there.

What if a vulnerability's time-to-exploit is shorter than my patch cycle?

Vulnerability Cloaking closes that gap by removing the inbound path to the asset rather than racing the patch. The asset dials outbound to a private Zero Trust fabric and exposes no inbound ports, so an attacker has nothing to reach even before a patch exists. Cloaking mitigates the exposure in minutes, and you apply the vendor patch later, on your own schedule.

How does Vulnerability Cloaking help with the explosion of CVEs, sometimes called the vulnpocalypse?

AI-assisted discovery is surfacing vulnerabilities faster than any team can patch them, which turns raw CVE volume into a losing race. Cloaking changes the terms: once an asset is unreachable, a newly disclosed vulnerability on it is no longer an emergency, however it surfaced. You cloak the asset in minutes, and the next critical CVE becomes a non-event rather than another unplanned change window.

Can Vulnerability Cloaking defend against AI-powered cyberattacks?

Automated and AI-driven attackers still have to find and reach a target before they can exploit it. Cloaking removes both steps: the asset has no open inbound ports and never appears in attacker-visible scans, so there is nothing for an attacker or its AI to discover or exploit. Authorized identities connect as before, governed by identity-based policy.

Make Your Vulnerable Assets Unreachable

See Vulnerability Cloaking take a vulnerable workload off the attackers' map in minutes.