Analyze·Advanced·60 min·Updated Sep 30, 2026

Run a multi-cloud vulnerability impact assessment

Use Security Copilot to evaluate exposure across cloud platforms and summarize the blast radius of a given vulnerability.

Download PDF

Microsoft 365

Business Outcome

A faster, clearer answer to "how exposed are we?" the moment a new vulnerability is disclosed.

Handle with care

Security vulnerability exposure

A list of exactly which systems are vulnerable and internet-facing is a roadmap for an attacker if it leaks. Keep step 3's leadership brief and the underlying exposure list restricted to the security team and named leadership recipients, not a broadly-shared channel.

Workflow Overview

Word
Security Copilot

Step 1: Identify the vulnerabilityScSecurity Copilot

Pull the exact CVE identifier and the affected software/version range straight from the advisory, and paste both into the prompt along with a one-line description of the exploit vector.

Security Copilot needs a specific, named target to correlate against your environment, not a general "check for vulnerabilities" request.

Step 2: Ask Security Copilot to assess exposureScSecurity Copilot

Point it at your connected cloud environments and ask specifically for blast radius, not just a yes/no on whether you're affected.

Prompt idea:

Assess our exposure to CVE-2026-XXXXX across our connected Azure, AWS and GCP environments. List every affected system, its criticality, and whether it's internet-facing. Prioritize the list by exposure severity.

Step 3: Draft the impact summary for leadershipWord

Turn the technical exposure list into a short written brief — what's affected, how bad, and what's being done — before this reaches anyone outside the security team.

Step 4: Route remediation by priorityWord

Send the highest-severity, internet-facing systems to remediation first; the rest can follow the normal patch cycle.

Check the work

  • Confirm the list of affected systems matches your actual asset inventory, not a generic assumption.
  • Verify internet-facing status on the highest-priority items before allocating urgent remediation effort.
  • Re-run the assessment after initial remediation to confirm the exposure actually closed.

Source: Microsoft Copilot Scenario Library — IT (2026)

Expected Outcome

A written impact assessment identifying affected systems across cloud platforms, prioritized by exposure severity.

✓

AI is the right call here

Judging a CVE's blast radius means correlating the vulnerability's specific conditions against each system's actual configuration across three different cloud platforms — not a simple "is this version affected" lookup.

Related Workflows

WORK WITH LIMINALS

Ready to roll this out beyond one person?

Workflows like this tend to raise real governance and licensing questions once more than one person is using them — that's exactly what we help with.