Innovation
Cyemptive launched Pre-emptive Cyber Defense-platform
Cyemptive Technologies launched its Pre-emptive Cyber Defense platform and demonstrated it during Cybersec Netherlands 2026. The reason for the launch was an issue that was rarely addressed within the security sector: in a significant proportion of new, unknown attacks in practice, there could simply never have been a patch available in time to install it.
Effective patching required a new attack to be detected and understood. Cyemptive made patches for new attacks redundant as soon as they became known and prevented both unknown and known attacks in practice.
The problem: 23% of the vulnerabilities that were actually exploited in the first half of 2026 had already been exploited before or on the day of publication (VulnCheck). No speed of patching could have helped in these cases.
The approach: Cyemptive's controlled forensic state management system.
Availability: live demonstration during Cybersec Netherlands, 9–10 September, HSD Meeting Zone, Jaarbeurs Utrecht.
The figures behind the launch
According to VulnCheck's State of Exploitation report, in the first half of 2026, 23% of all known vulnerabilities that were actually exploited had been exploited before or on the day the relevant CVE was published. In approximately a quarter of cases, even faster patching would have made no difference, because there simply was no patch available to install.
At the same time, the number of vulnerabilities continued to rise. FIRST, the global forum for incident response teams, forecast that 59,427 new vulnerabilities would be registered in 2026, approximately one new vulnerability every nine minutes. This would make 2026 the first year in which the number of new vulnerabilities exceeded 50,000.
"You cannot patch what has not yet been published,” said Rob Pike, CEO and founder of Cyemptive Technologies. “For twenty years, the sector had invested in optimising the speed of a response that, in practice, was never available for a quarter of attacks. That was why we made the system itself the control point, rather than our knowledge of the attack."
Cyemptive's perspective
If cyber defence depended on knowledge of what needed to be remediated, unknown attacks could not be stopped proactively. Cyemptive's solution was to stop all known and unknown cyber attacks by using the system itself as the control point. The system was continuously returned to a validated, clean state. As a result, a breach could not persist, regardless of whether anyone had recognised it and regardless of whether it involved a known or unknown attack.
Organisations were already deploying AI agents with access to data, the ability to make decisions and the capacity to act at machine speed. The security market had developed rapidly: in the second quarter of 2026 alone, seed investors had invested approximately $360 million in securing, managing and authenticating AI agents, according to Omdia. In that same quarter, non-human identity was the most widely adopted category.
These developments addressed one question: what was this agent allowed to do?
According to Cyemptive, however, a second, crucial question was missing, one that underpinned the first: what was the agent running on, and was that system still what it was supposed to be?
“An AI agent running on a compromised host would continue to follow every policy you had put in place, while simultaneously working for someone else,” said Pike. “Permissions, scopes, short-lived credentials, all of these things were issued and enforced by a system. If that system was not clean, your governance layer would politely tell you that everything was in order, when it was not.”
The key was controlling the system, not the attack.