Site Search

ANTERAS

Antelace

In an era of AI-driven vulnerability explosions, how can we prepare for threats? "Preventive Security 'ROC': A New Norm"

In an era of AI-driven vulnerability explosions, how can we prepare for threats? "Preventive Security 'ROC': A New Norm"
Cyberattacks, including ransomware, continue to cause widespread damage. Many of these attacks begin with intrusions exploiting system vulnerabilities, and while the importance of countermeasures is widely emphasized, the number of vulnerabilities is exponentially increasing due to advancements in AI (artificial intelligence), making it impossible to address them all. With "reactive response," such as rapid detection after an intrusion, reaching its limits, a new preventative concept called "ROC (Risk Operation Center)," which focuses on identifying risks "before" an attack occurs, is attracting attention. We spoke with a key figure at Macnica, a company that provides cybersecurity measures utilizing ROC, to learn about its effectiveness and importance.
Daiki Kasai

Macnica
Networks Company
Security Services Division, Technology Department Manager
Daiki Kasai

Masashi Kanda

Macnica
Networks Company
Security Services Division, Sales Department, Deputy Manager
Masashi Kanda

"Addressing all risks" is no longer possible.

With the surge in cyberattacks, including ransomware, security personnel are scrambling to find solutions. How do you view the current situation and what the ideal state of affairs should be?

Daiki Kasai
Security Services Division, Technology Department Manager
Daiki Kasai

Kasai: As digital transformation (DX) initiatives lead to a rapid increase in digital assets, so does the number of "system vulnerabilities" that serve as entry points for cyberattacks. The threats that need to be addressed are constantly increasing, while corporate IT departments are busy and understaffed. It is necessary to correctly prioritize risks and respond effectively, but the reality is that there are so many risks that it is difficult to know where to start, and as a result, many companies are unable to protect themselves.

Kanda: There is already an international index called "CVSS (Common Vulnerability Scoring System)" that evaluates the severity of vulnerabilities, but the reality is that companies are not effectively utilizing such information. One reason for this is that scores have remained high recently, resulting in a situation where most vulnerabilities have a high priority. Another reason is that there are vulnerabilities that have high scores but are not realistically used in attacks, and vice versa. In other words, companies must identify the "true risks" that take their own situation into consideration and respond with priorities that are truly appropriate for their company.

Many companies already operate Security Operation Centers (SOCs), but reports of attacks continue unabated. Does this mean that the measures taken by previous SOCs are insufficient?

Masashi Kanda
Security Services Division, Sales Department, Deputy Manager
Masashi Kanda

Kasai: Cyberattacks are becoming increasingly difficult to stop at the "entry point," and nowadays, approaches such as EDR (Endpoint Detection and Response) that "quickly detect and respond to intrusions to prevent damage" are being emphasized. SOCs (Security Operations Centers) are also primarily responsible for responding after an incident occurs. However, with the current enormous amount of vulnerability information, it is already impossible to process it all, and the time between the disclosure of a vulnerability and the actual intrusion by an attacker has also shortened, so detection and response after the fact are insufficient. That is why it is necessary to "understand and address risks before an attack occurs."

Kanda: The American research firm Gartner also advocates "Preemptive Cybersecurity," and predicts that by 2030, more than 50% of companies' IT security spending will be focused on prevention*. Against this backdrop, the concept of ROC (Risk Operation Center) has emerged as a complement to the traditional SOC.

*Source: “Gartner Says That in the Age of GenAI, Preemptive Capabilities, Not Detection and Response, Are the Future of Cybersecurity”

A methodology for proactive security called "ROC" that acts "before the attack."

What exactly is ROC?

Kasai: While a SOC is a "reactive" system that handles detection and response after an incident occurs, ROC is a framework that manages risk proactively as a prerequisite. It is a methodology for correctly identifying threats that need to be addressed before they can be exploited in attacks, and for continuously reducing risk across the entire organization. Although it is often contrasted with SOC due to the sound of the words, it does not refer to any specific organization like SOC does.

Kanda: To explain the specific operational flow, first in step 1 we identify the risks in the world, then in step 2 we grasp the asset situation and confirm whether it is a risk related to our company. If it is a risk, in step 3 we prioritize it, and in step 4 we address the risk. Since the asset situation changes constantly, we continue the process of prioritizing and addressing risks again as vulnerabilities arise in the latest situation.

A methodology for proactive security called "ROC" that acts "before the attack."

Macnica 's proposed ROC-based operational model

From "understanding" to "addressing": What ANTERAS is responsible for.

So, ROC is a methodology, not a specific product or organization. How can companies implement ROC?

Kasai: It's important to have a mindset that aims to comprehensively understand risks. However, the most difficult part is properly narrowing down and prioritizing risks, and this has been the biggest obstacle preventing companies from adopting ROC until now. That's why Macnica has launched a new service called "ANTERAS" that implements the ROC concept.

Our company already provides "Macnica ASM" as a solution that continuously visualizes the attack surface and identifies and evaluates risks that could become entry points for threats. We have accumulated knowledge for correctly understanding and controlling risks and have received high praise from the market. ANTERAS is based on Macnica ASM, with added functions such as dark web monitoring, web vulnerability assessment, CSPM (Cloud Security Posture Management), and threat hunting, configured as a platform that supports the entire ROC process.

ANTERAS examines all risks, prioritizes them, determines whether they are relevant to the customer, notifies them through a dedicated portal for managing customer assets and risks, and provides ongoing support until actual countermeasures are taken. Even against ransomware attacks, we anticipate where attackers will target and add features based on that, so countermeasures are naturally implemented.

From "understanding" to "addressing": What ANTERAS is responsible for.

Overview of the ANTERAS platform

There are other similar services out there, but what are ANTERAS's advantages?

Kanda: One is the intelligence (information gathering and analysis) of our "Security Research Center." In addition to the knowledge we have accumulated since its establishment in 2013, we research threat countermeasures specifically for Japanese organizations, so we can prioritize risks in a way that is optimal for Japanese companies. Another is that we can support the entire process until the system is fully implemented. Information systems departments, in particular, are burdened with communication tasks such as notification and confirmation, so we believe there is great value in us taking over that part for them.

Finally, please give us a message.

Kasai: The reason vulnerability response isn't working is that there's an obsession with the idea of having to address everything, resulting in half-hearted countermeasures. Given limited human resources, prioritization is crucial, and the first step in that is understanding the risks. The speed of response will differ depending on whether you were aware of the risks beforehand or if you were unaware of them when an alert is raised by a security product. Let's adopt the ROC (Recovery of Control) approach and build a system that allows us to act quickly.

Kanda: Recently, the AI model "Claude Mythos," which has an astonishing ability to discover vulnerabilities, has been frequently featured in the media. With the spread of generative AI, there will undoubtedly be a "big explosion" of vulnerability information within two years. Now is the time to change our way of thinking and prepare with courageous, preventative security measures that focus on specific risks. In that case, our company will provide thorough support from implementation and establishment to remediation.

*Copyright and production by Nikkei Inc. (Nikkei Digital Edition Advertising Special Feature 2026). Unauthorized copying, reproduction, public transmission, etc., of all content, including articles, photographs, and illustrations, is prohibited.

Inquiry/Document request

Macnica ANTERAS Department

Weekdays: 9:00-17:00