NEC is starting a managed service that takes on the whole job of finding vulnerabilities in a company's IT assets, judging how dangerous they are, and actually fixing them. It is called BluStellar Intelligent Managed Service, and it becomes available at the end of September 2026 for financial institutions, manufacturers, and distribution and service companies. NEC is targeting 30 billion yen in revenue over three years. With attackers already using AI to work faster, the idea is to move the defender's judgment onto AI as well.

Vulnerability Response Has Outgrown Manual Work

What system administrators face every day is a pile of newly disclosed vulnerabilities. Which ones actually affect us, which servers are exposed to the outside, and which business lines stop if something goes wrong. Cross-referencing all of that to decide what to fix first is genuinely time-consuming investigative work.

The spread of AI has made it harder. Attackers now use AI to hunt for vulnerabilities, generate exploit code, and research their targets, and the gap between disclosure and exploitation keeps shrinking. At the same time, wider cloud adoption and increasingly distributed systems mean the number of IT and network assets a company has to manage keeps growing. The denominator is rising while the grace period shrinks.

NEC frames this as a situation that monitoring-and-detection operations alone can no longer support. The core of the new service is to bring AI analysis and execution into what comes after detection: which item to fix first, how to fix it, and whether the fixed state is holding.

Connecting Asset Inventory Through Patch Deployment Without Gaps

The service covers discovery of IT and network assets, vulnerability detection, risk analysis, prioritization, planning and carrying out the response, and operational improvement. Areas that used to be split across different owners and tools are handled as a single flow.

Three inputs feed it: asset information, vulnerability information, and business impact. AI analyzes them together and identifies the risks that this particular customer should address first. Even after a response is complete, the service keeps reading vulnerability handling status and system operations data, feeding that into risk assessment and improvement planning. Rather than a one-time fix, the goal is to keep an improvement cycle running so the organization stays ahead of threats, a state usually described as cyber resilience.

Priorities Are Not Decided by CVSS Scores Alone

The prioritization method is the technically interesting part.

CVSS (Common Vulnerability Scoring System) is the widely used international measure of vulnerability severity, but this service does not rely on it by itself. It also weighs how exposed a device is to the internet, whether real-world exploitation has been observed, and how much the business would be affected. The reference framework is BOD26-04, the binding operational directive issued in June 2026 by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). That directive asks federal agencies to shift from CVSS-score-centered handling to risk-based prioritization that factors in actual exploitation and asset importance.

There is a second point about vulnerabilities that look minor on their own. Individually low-priority issues can combine into a path that reaches critical assets. The service identifies and evaluates those combinations and re-ranks priorities according to the real attack risk. The analysis uses cotomi Security for Industry, the security-oriented AI technology behind NEC's next-generation cybersecurity service CyIOC, in combination with partner company products.

Three Menus, With Google Cloud and ServiceNow as Partners

Three services become available at the end of September:

  • IT and network asset management service
  • Vulnerability management service
  • Vulnerability remediation service

Understanding the assets, managing the vulnerabilities, and doing the actual work are each offered as a separate menu item.

Partners also published comments. Tomoko Mikami, President of Google Cloud Japan, described NEC as an important and pioneering launch partner for Google AI Threat Defense and said the two companies would build an AI-native defense strategy together. Masatoshi Suzuki, President and Representative Director of ServiceNow Japan, spoke about the significance of joining as a partner supporting more advanced vulnerability remediation. On the user side, Sumitomo Mitsui Trust Bank said it expects the effort to help strengthen cybersecurity in the financial industry.

Turning What Was Tested Under Client Zero Into a Product

NEC runs an initiative called Client Zero, in which it positions itself as its own zeroth customer and operates new systems internally first. The company says practical knowledge from that program, along with expertise built up in social infrastructure and mission-critical work, will be folded into the service on an ongoing basis. For companies that struggle to hire specialists of their own, borrowing that accumulated operational know-how is likely the real value.

Looking ahead, NEC plans to add proactive vulnerability detection and AI agents that plan and carry out defensive measures. The current service centers on analysis and support, but the stated direction is autonomous response to changing threats.

Summary

BluStellar Intelligent Managed Service uses AI to connect asset discovery, vulnerability detection, prioritization, remediation, and operational improvement. Its distinguishing feature is that priorities are set not by CVSS scores alone but by exposure, observed exploitation, business impact, and even combinations of vulnerabilities. It launches at the end of September 2026 with three menu items, and NEC has set a target of 30 billion yen in revenue over three years while previewing AI agents that will act autonomously. How far defensive operations can actually be automated is worth watching in real deployments.