top of page

Withnetworks Presents Integrated Continuous Management Framework at ‘2026 Next-Generation IT Strategy Exhibition for Local Governments’

21 hours ago
4 min read
Introduces CTEM-based asset and vulnerability management to help local governments respond to N2SF and ISMS-P regulatory requirements Real-time visualization of assets and vulnerabilities through a 3D security digital twin, with asset management extended to SBOM components

2026 지자체 차세대 정보화 전략 IT 전시회'에서 참관객들이 'withVTM'을 살펴보고 있다
2026 지자체 차세대 정보화 전략 IT 전시회'에서 참관객들이 'withVTM'을 살펴보고 있다

 

Withnetworks (CEO Ahn Jong-up) announced on the 11th that it presented withVTM, an integrated asset and vulnerability management platform based on Continuous Threat Exposure Management (CTEM), at the ‘2026 Next-Generation IT Strategy Exhibition for Local Governments’ held at Jeju Sun Hotel on the 10th. The platform is designed to help organizations respond to the National Network Security Framework (N2SF) and revisions to the ISMS and ISMS-P certification requirements.


The exhibition, hosted by the Korea Internet & Security Professionals Association (KISPA), was attended by approximately 300 information technology officials from local governments across the country.


Withnetworks focused on regulatory compliance. Following the implementation of N2SF in September last year, which classifies assets into three levels—C, S, and O—and requires controls according to each level, the government-wide Comprehensive Information Security Measures announced in October last year also specified the need to conduct a comprehensive survey and inventory of IT assets. The revised ISMS and ISMS-P requirements scheduled to take effect next year will likewise expand the certification scope to assets exposed to external interfaces and require continuous inspections from initial certification through renewal. While the specific requirements differ, they share a common foundation: starting with an asset inventory, continuously monitoring its status, and ultimately accumulating evidence of compliance.


withVTM implements this structure as a continuous operational workflow consisting of six stages: identification, analysis, assessment, remediation, verification, and evidence collection. The process begins with an asset inventory. By integrating three proprietary scanners with existing scanners, CMDBs, and ITSM systems, the platform consolidates unidentified IP addresses, open ports, shadow IT, and shadow APIs into a single view. It can also comprehensively identify assets in network-segmented environments where external connections are blocked. Based on the resulting inventory, withVTM calculates the C, S, and O classification for each asset and links it to N2SF-based asset classification management.


CTEM 기반 자산 및 취약점 통합 관리 플랫폼 withVTM
CTEM 기반 자산 및 취약점 통합 관리 플랫폼 withVTM

This workflow is visualized through a 3D security digital twin.

The system reproduces actual assets and network configurations in a virtual environment, allowing administrators to see on a single screen which vulnerabilities affect each asset and what other systems or services the asset is connected to. Unlike static lists that are recreated whenever an inspection is conducted, the digital twin remains continuously synchronized, meaning previously unidentified shadow IT and newly disclosed vulnerabilities are reflected on the screen as soon as they are detected. The scope of visualization also extends beyond servers and IP addresses to include services, APIs, containers, and SBOM components.


withVTM has expanded its management scope to include SBOMs (Software Bills of Materials). It collects SBOMs based on the international CycloneDX and SPDX standards, registers packages, libraries, and dependencies as individual assets, and verifies their integrity using hashes and signatures. With incidents such as the supply-chain compromises involving axios and LiteLLM in March demonstrating that malicious code can remain exposed for only a matter of minutes yet still spread through deployment pipelines, Withnetworks emphasized the need to immediately identify which assets and responsible teams are using an affected package whenever a new vulnerability is disclosed.


Risk is assessed using an AI-generated Real Vulnerability Score (VRS) rather than a single CVSS score. This approach is based on the premise that real-world attacks typically arise from combinations of threats rather than from a single vulnerability. When an externally exposed API, unnecessarily open ports, vulnerable libraries listed in an SBOM, default accounts or excessive privileges, and sensitive-data access paths overlap on the same asset, the likelihood of exploitation can increase significantly even if the individual vulnerability scores are relatively low. Accordingly, withVTM combines asset criticality, external exposure, exploitation signals such as EPSS and CISA KEV, configuration weaknesses, and privilege status at the asset level to produce a score between 0 and 10. Unlike CVSS, which calculates risk at the individual vulnerability level, this approach is designed to reveal such combinations of risk factors.


Withnetworks explained that inspection and remediation histories are accumulated as evidence that can be used to respond to information security assessments and security audits conducted by the National Intelligence Service (NIS). The company said that this normalized asset, vulnerability, exposure, and threat data ultimately forms an “AI defense foundational dataset.”


AI 기반 위협 노출 진단 서비스 withREX
AI 기반 위협 노출 진단 서비스 withREX

withREX is a threat exposure assessment service. It can assess an organization’s attack surface across the enterprise over a short period without installing agents or disrupting operations. The service identifies assets missing from existing inventories as well as externally exposed APIs and classifies their levels of exposure.


withVTM and withREX are both registered on the Public Procurement Service’s Digital Service Mall, and Withnetworks supports public-sector customers in regional areas through its headquarters in Seoul and branches in Daejeon, Daegu, Honam, and Busan.

Ahn Jong-up, CEO of Withnetworks, said, “What all three systems have in common is the requirement to ensure that every asset owned by an organization is fully inventoried and continuously monitored.”


He added, “withVTM’s role is to identify assets that were missing from the inventory, along with the services, APIs, and SBOM components built on top of those assets, and show the remediation priorities on a single screen.”


He further emphasized, “We will continue to provide implementation support tailored to the needs of local governments through our headquarters in Seoul and four regional branches.”



전자신문


 
 
 

Comments


bottom of page