From Vulnerability Scan Sprawl to Verified Fixes: Stanford's Agentic AI SecOps with Cogent

Thursday, October 01, 2026 | 9:30AM–10:30AM MT
Session Type: Poster Session
Delivery Format: Poster Session
Information security vulnerability management in higher ed is uniquely hard: messy inventories, ambiguous ownership, and ticket fatigue abound. This is particularly true in complex distributed/federated IT environments with large ecosystems of researcher-owned assets. Stanford’s School of Humanities & Sciences is implementing Cogent, an agentic AI orchestration platform that connects data from our vulnerability management scanners, our homegrown asset registry, and ITSM to normalize findings, resolve ownership, prioritize remediation by contextual risk, automate remediation actions, and verify fixes with evidence. We will share our operating model, governance patterns, and exception process for distributed stakeholders. We will provide a live demo of Cogent and show API-based data ingestion, cross-tool deduplication, risk-based prioritization with explainable rationale, automated owner resolution, action-plan ticket creation, exception workflows, remediation verification, and natural language reporting. Attendees will leave with a blueprint and a concrete view of what “agentic AI for SecOps” looks like in practice.

Presenters

  • Bhavya Gupta

    Manager - Cloud security and Vulnerability Management, Stanford University
  • Andy Miller

    CIO, School of Humanities & Sciences, Stanford University