Cyemptive’s platform is designed to keep critical systems clean without waiting for a patch, an alert or a detection.
Cyemptive Technologies launches its Pre-emptive Cyber Defense platform. The launch foundation rests on a premise the security industry rarely acknowledges: for a substantial share of new, unknown real attacks, there could never be a patch available in time to install. Effective patches require detection and the understanding of a new attack. Cyemptive pre-empts the need for patches for new, now known attacks and prevents all unknown and known real attacks.
In brief
- The problem: 23% of exploited vulnerabilities in the first half of 2026 were executed before the day they were published (VulnCheck). For those, no patching speed would have helped.
- The approach: Cyemptive’s controlled forensic state management system
- Availability: in Europe from [August 2026]. Shown live at Cybersec Netherlands, 9–10 September, HSD Meeting Zone, Jaarbeurs Utrecht.
The Arithmetic Behind the Launch
In the first half of 2026, 23% of all known exploited vulnerabilities were used on or before the day the CVE was published, according to VulnCheck’s State of Exploitation report. For that quarter of cases, no patching speed would have helped — there was nothing to install.
At the same time the volume keeps climbing. FIRST, the global forum of incident response teams, forecasts 59,427 new vulnerabilities for 2026: roughly one every nine minutes, and the first year above fifty thousand.
“You cannot patch what has not been published yet,” says Rob Pike, CEO and founder of Cyemptive Technologies. “The industry has spent twenty years optimising the speed of a response that, for a quarter of real attacks, was never available at all. That is why we make the system itself the control, instead of the knowledge about the attack.”
This is not an argument for patching faster. It is an argument that detection and then speed is the wrong axis.
Cyemptive’s perspective is that if cyber defense depends on knowing what to has to be fixed, then by definition, unknown attacks cannot be pre-empted. Cyemptive’s solution: stop all known and unknown cyber-attacks by making the system itself the control: continuously return it to a validated, clean state, so that a compromise does not persist whether or not anyone recognised it i.e. whether it is known or unknown.
And then came the Agents
Enterprises are now deploying AI agents that access data, make decisions and act at machine speed. The security market has moved quickly: in the second quarter of 2026 alone, seed investors put around $360 million into securing, managing and authenticating AI agents, and non-human identity was the most acquired category of the quarter, according to Omdia.
That work answers one question — what is this agent allowed to do. Cyemptive highlights that a second, key question is missing, and that it sits underneath the first: what is the agent running on, and is that still what it is supposed to be?
“An AI agent on a compromised host will follow every policy you gave it, and still work for someone else,” says Pike. “Permissions, scopes, short-lived credentials — all of it is handed out and enforced by a system. If that system is not clean, your governance layer answers politely and lies.” The key is managing the system, not the attack.
Manage the System, Not the Attack
The Pre-emptive Cyber Defense platform brings Cyemptive’s CyberSlice® technology together with its cyber-resilient computing foundation, CyOS™, into a single platform with one security model, one management line and one evaluation path where pre-emptive security is now a property of the foundation itself.
CyberSlice® continuously renews the operating environment an attacker would have to work in, continuously returning systems to a pre-validated, clean state. Previously used or compromised conditions therefore do not persist by default — including when nobody observed that anything had happened.
Renew continuously, and you do not have to recognise an attack before you can act on it.
Resilience, Continuity and Control are Fundamental Goals
Cyemptive is built for all environments where continuity, integrity and resilience are essential: critical infrastructure, industrial environments, defense, and embedded and edge computing. Rather than generating more alerts, the platform delivers three outcomes:
- Continuity: Critical systems keep operating during cyber incidents.
- Control: Organisations retain control of their own environment and data.
- Resilience: A smaller, more manageable attack surface.
Cyemptive does not need to collect, own or analyse customer data centrally in order to deliver the security function. Customers keep their data, decide where it sits, and retain the chain of custody.
“In European boardrooms the question has shifted from ‘did we see it?’ to ‘can we demonstrate that we keep running?‘,” says Wessel Graatsma, Senior Vice President Europe at Cyemptive. “That is what NIS2 and the Cyber Resilience Act are really asking for. Cyemptive can deliver pre-emptive cyber security without a single byte of customer data leaving the organisation — which in this market is not a detail, it is a key, deciding factor.”
Resilience by Design, not by Detection
Regulatory frameworks including NIS2 and the EU Cyber Resilience Act are moving the burden of proof. NIS2 requires demonstrable continuity and incident management; the CRA sets resilience requirements for products with digital elements themselves, not only for the security layers around them.
Cyemptive’s solution that continuously enables recovery to a known, good state and structurally reduces the attack surface maps directly onto those critical obligations. Furthermore, no customer data has to leave the organisation for Cyemptive’s solution to work, which positively addresses questions of transfer, storage and data sovereignty.
From Security Claims to Measurable Results
Cyemptive’s insistence on providing customer and partner testing and validation is at the centre of its approach. Organisations are encouraged and challenged to evaluate Cyemptive’s technology under controlled conditions against criteria agreed in advance, with the customer doing the measuring:
- Constant recovery to a validated state, demonstrating fundamental resilience;
- System integrity under attack conditions;
- attack surface and exposed functionality; and
- continuity of trusted operation.
Cyemptive publishes the evaluation protocol and measurement criteria up front, so results are reproducible and comparable.
See it. Test it. Validate it.
Cyemptive is demonstrating the Pre-emptive Cyber Defense platform on 9 and 10 September at the Jaarbeurs in Utrecht, as one of eight partners selected by HSD Security Delta for the HSD Meeting Zone, where next-generation cybersecurity capabilities are shown to decision-makers from security, technology and business.
Rob Pike will speak at the conference on why continuity should no longer depend on how fast a team spots an attacker, but rather on how to stop all known and unknown cyber-attacks by making the system itself the focus of control: continuously returning the system to a validated, clean state and negating any need as to whether or not attacks are known or unknown.
During the conference Cyemptive will show the technology in operation and demonstrate how organisations can evaluate the approach through controlled testing.
Practical information
Event: Cybersec Netherlands 2026 Dates: 9–10 September 2026 Location: Jaarbeurs Utrecht: HSD Meeting Zone Session: Book a meeting or request an evaluation: info@cyemptive.com
About Cyemptive Technologies
Cyemptive Technologies has been advancing cybersecurity since 2014, developing award-winning Pre-emptive Cyber Defense technology that reduces the attack surface while strengthening the resilience, continuity and control of critical systems. From its European headquarters in The Hague, Cyemptive serves businesses and government organizations worldwide.
Note to editors
Press contact:
Ann Greene, Director of Marketing
+1 425 341 9800
agreene@cyemptive.com
www.cyemptive.com
Dutch-language Press Contact:
Wessel Graatsma, Senior Vice President Europe
wgraatsma@cyemptive.com
www.cyemptive.com
Sources cited: VulnCheck, State of Exploitation 1H-2026. FIRST, 2026 Vulnerability Forecast. Omdia, Emerging Cybersecurity Funding Tracker 2Q26 (as reported by Dutch IT Channel, 25 August 2026).