Full Report
Traditional attack surface management helps organizations discover exposed assets, but visibility alone is not enough to address threats. Criminal IP introduces AITEM, an AI-powered approach that connects exposure discovery with investigation, risk prioritization, and response. [...]
Analysis Summary
# Industry News: Criminal IP Launches AITEM to Bridge the Gap Between Exposure Discovery and Response
## Summary
AI SPERA has announced the launch of **AITEM** (AI-Powered Threat Exposure Management), a significant expansion of its Criminal IP platform. The solution shifts the focus from traditional Attack Surface Management (ASM) discovery to a broader lifecycle that integrates threat intelligence with AI-driven investigation, risk prioritization, and automated response.
## Key Details
- **Date:** October 10, 2026
- **Companies Involved:** AI SPERA (Parent company of Criminal IP)
- **Category:** Product Launch / Strategic Pivot
## The Story
The cybersecurity industry is currently grappling with "visibility fatigue," where organizations can see their exposed assets but lack the resources to remediate them before attackers exploit them. To address this, Criminal IP has introduced AITEM.
AITEM moves beyond the standard external asset inventory. It leverages AI to analyze data across a wide spectrum, including the dark web, open-source intelligence (OSINT), internal infrastructure, and "Shadow AI." The platform is designed to guide security teams through four distinct phases: **Detect** (linking vulnerabilities to actual assets), **Investigate** (using natural language queries), **Prioritize** (using exploitability data over generic scores), and **Automate** (routing findings to ticketing systems).
## Business Impact
### For the Companies Involved
- **AI SPERA/Criminal IP:** Transitions from being a Threat Intelligence (TI) data provider to a comprehensive security operations platform vendor, potentially increasing their Average Revenue Per User (ARPU).
### For Competitors
- **ASM Vendors:** Traditional players (e.g., Palo Alto Networks’ Cortex Xpanse, Censys) face increased pressure to integrate more sophisticated AI-driven prioritization and "Shadow AI" discovery to remain competitive.
- **Vulnerability Management (VM):** The lines are blurring between ASM and VM; AITEM’s focus on "exploitability" directly challenges legacy VM vendors.
### For Customers
- **Security Teams:** Reduces the manual "noise" of security alerts by providing natural language investigation tools and context-heavy risk scores.
- **Resource Efficiency:** Allows smaller teams to operate at a higher velocity by automating the path from discovery to a Jira/service ticket.
### For the Market
- **Evolution of Categories:** This signals the market’s transition from Attack Surface Management (ASM) to the broader **Continuous Threat Exposure Management (CTEM)** framework championed by Gartner.
## Technical Implications
AITEM utilizes **Natural Language Processing (NLP)** to allow security analysts to query complex datasets. By integrating "Shadow AI" discovery, it addresses a modern technical debt where employees utilize unsanctioned AI tools that create new data leak vectors. The core innovation lies in the platform's ability to correlate external threat actor activity (who is scanning for what) with the internal asset inventory in real-time.
## Strategic Analysis
- **Market Positioning:** Criminal IP is positioning itself as a "decision-ready" platform rather than a "data-heavy" one.
- **Competitive Advantage:** Their foundation in raw threat intelligence data (IP/Domain reputation) provides a more granular context than competitors who only "scan" for assets without the underlying reputation data.
- **Challenges:** Entering the "Automate/Response" space requires deep integration with third-party tools (SOAR, ITSM). Building and maintaining these integrations is a significant engineering hurdle.
## Industry Reactions
- **Analyst Perspective:** The move reflects a broader 2026 industry trend—seen at RSAC 2026—of "Agentic AI" and "AI SOC" becoming the standard for modernizing security operations.
- **Market Response:** There is high interest in "Shadow AI" discovery as organizations struggle with the rapid adoption of generative AI tools.
## Future Outlook
- **The Speed War:** Expect the "time-to-remediate" to become the primary metric for ASM success, moving away from "number of assets found."
- **Watch For:** Look for AI SPERA to potentially pursue partnerships with Cyber Insurance firms, who are increasingly interested in real-time exposure management to price premiums.
## For Security Professionals
Practitioners should view this as part of a trend toward **consolidated security stacks**. If your current ASM tool only gives you a list of IPs without telling you which ones are being actively targeted by ransomware groups, it is becoming obsolete. AITEM suggests that the future of the role is less about "finding" and more about "orchestrating" the fix.