The Lab
Is any vulnerability management tool actually autonomous?
Frank De Pasquale ·
Every vulnerability management vendor now claims some version of autonomous remediation. Almost none of them mean the same thing by it, and most don't mean it at all.
Attackers have started automating the work that used to take skill and time: reading a fresh disclosure, finding the exploitable path, generating working attack code. Buyers have understandably started reaching for the same promise on the defensive side, a system that decides and acts on its own, fast enough to keep up. The question worth asking before paying for that promise is simple: does the software actually decide anything, or does a human still write every rule it follows?
Picture the difference between an alarm clock and a robot. An alarm clock is useful. It reliably rings at the same time every day, and you can set complicated rules for it: ring louder on weekdays, stay silent on holidays. But it never decides anything. It just executes what you told it to do, when you told it to do it. A genuinely autonomous system looks at the situation itself: this vulnerability is more dangerous than that one, so it fixes the dangerous one first, picks the method itself, and checks its own work afterwards, without a human pre-setting the order, the tool, or the check.
The market is selling a well-dressed alarm clock
Only three vendors in this assessment carry a public claim strong enough to test against that bar at all: ManageEngine Endpoint Central, NinjaOne and Qualys. Two more are worth checking specifically because buyers keep asking about them: Vicarius and Adaptiva. Read closely, neither actually makes the full claim in its own documentation.
What we actually found
ManageEngine's own explanatory material describes self-healing as a structured loop, but every stage is explicitly admin-configured. Baselines, thresholds and the remediation action itself are pre-set by IT; the vendor's own documentation says an issue is either remediated automatically or surfaced for administrator review against a pre-configured, rule-based workflow. That is sophisticated rule automation with AI-assisted detection layered on top, not independent decision-making.
NinjaOne's own docs and blog draw the automation-versus-autonomy line more explicitly than most, then describe their own product mostly on the automation side of it. Schedules, approval rules and severity thresholds are admin-set; the AI layer only adds a safety override, pausing a risky patch, rather than running the whole loop independently. NinjaOne's own blog post defines autonomy almost exactly the way this assessment does, then describes its own product using the automation definition instead.
Qualys is the strongest of the three, and the only one where the vendor's own material describes the AI choosing the remediation path and independently re-confirming closure. Its TruRisk Eliminate stack pairs two named AI agents, one interpreting each exposure and mapping it to a remediation path, the other continuously evaluating what is truly exploitable in production, described using nearly the same detect, validate, prioritise, remediate, confirm language this assessment uses. Qualys reports 40 million of 150 million patches executed fully autonomously, with rollback under 0.1 per cent. That confident language sits ahead of the more conservative framing in Qualys's own formal release notes, which describe the same layer as advisory, worth knowing before citing it externally.
None of the three are lying, exactly. What almost every vendor in this market has actually built is a real, distinct middle tier that sits between plain scheduling and genuine autonomy: AI-assisted rule automation with safety overrides. The system still runs on admin-set schedules and rules, but a layer on top flags risk, pauses a bad deployment, or re-ranks priority, without ever taking full end-to-end authority. That is meaningfully more sophisticated than a bare calendar, and meaningfully short of the autonomous bar these vendors are marketing against. NinjaOne's Patch Intelligence AI pausing a risky patch is one example. So is Adaptiva's own set of controls letting an admin block or roll back an in-flight wave. ManageEngine layers a diagnostic AI on top of its rule-based self-healing the same way. Qualys's own Patch Reliability Score, even setting aside the stronger autonomy claim elsewhere in its stack, is itself an instance of exactly this pattern: AI-assisted, not autonomous.
| Vendor | Decides what to fix | Decides how to fix | Confirms its own fix | Verdict |
|---|---|---|---|---|
| ManageEngine Endpoint Central | Admin-configured | Admin-configured | Partial | Rule automation, not autonomous |
| NinjaOne | Admin-configured | Admin-configured (AI pause override only) | No | Rule automation, not autonomous |
| Qualys | AI agent (Agent Sara) | AI agent (Agent Val + Sara) | Yes | Closest to genuine autonomy |
| Vicarius | Automated ranking | Admin policy rule | Yes | Strong validation, not autonomous action |
| Adaptiva | Admin-configured | Admin-configured | Partial | Rule automation, not autonomous |
The two vendors buyers ask about most
Vicarius is genuinely strong at two of the three steps that matter here. It ranks vulnerabilities automatically, and it verifies a fix actually closed the gap, which is exactly why it is one of only a handful of vendors we credit for closed-loop remediation validation elsewhere in this assessment. But Vicarius's own documentation is explicit that deployment itself still runs on demand, on a schedule, or by an admin-written policy rule, with the security team approving the workflow. Ranking well and confirming well is not the same claim as deciding and acting independently, and the evidence supports the first, not the second.
Adaptiva markets itself as autonomous patch management at the brand level. Its own technical documentation tells a narrower story: admins configure deployment waves and business-unit-specific strategies, and a set of controls lets them block, roll back or pause the process at will. That is the same pattern as the rest of the market, real automation, AI-assisted in places, with decision authority sitting in the admin-configured policy rather than the system itself.
Where this leaves the market
None of this makes the automation on offer today useless. A system that pauses a risky patch on its own, or re-ranks priority the moment a new exploit appears, is a real improvement over a dumb, fixed schedule, and every vendor here has built exactly that. What it is not yet, on the vendors' own published evidence, is a system that decides for itself what to fix, how to fix it, and checks its own work without a human writing every rule in advance.
This matters more than it would have two years ago. ASD's Essential Eight now expects a critical, internet-facing vulnerability patched within 48 hours of a fix existing, and that clock doesn't pause for an approval queue. A tool that pauses a bad patch on its own, or re-prioritises the moment a new exploit lands, genuinely helps a team hit that window. A tool that only looks autonomous in the pitch deck doesn't, and the gap between the two only shows up at 2am, when the alert nobody configured a rule for actually fires.
The useful question to put to a shortlisted vendor is not whether its remediation is autonomous. Nearly every vendor will say yes. The narrower question is what the system decides on its own, versus what an administrator configured in advance, and what happens the day a situation arrives that nobody wrote a rule for. On the evidence we found, only one vendor's own material comes close to answering that the way the word autonomous actually implies, and even there the formal documentation is more cautious than the pitch.
None of this is a knock on the vendors named here. Building even the AI-assisted override layer most of them ship today is genuine engineering, and it beats the plain scheduling it replaced. The point is narrower: a category-wide marketing word and a strict technical bar are two different things, and a buyer who conflates them ends up assuming a capability nobody has actually shipped yet.
Keep reading
The rest of this analysis
Enter your email to unlock the full report — we’ll send you a copy too.
Prefer not to? Emailhello@tekspace.com.au