Clone Systems rebuilds CloneGuard to scan behind logins and prioritize fixes

Founder George Nianios's Clone Systems launched a rebuilt CloneGuard on September 15th, expanding the security platform from perimeter and compliance scans into authenticated application testing, remote endpoint coverage and AI-assisted remediation.

Clone Systems said in its launch announcement that the new version has four times as many vulnerability detections as its predecessor. That figure is a company-supplied comparison. The consequential change is where CloneGuard can look: inside logged-in web applications and APIs, and across employee computers that may rarely connect to a corporate network.

Nianios founded Clone Systems in 1998, according to a TAG Cyber vendor profile, building around managed security, compliance scanning and continuous monitoring years before vulnerability management became a crowded software category. Clone Systems has been a PCI Security Standards Council Approved Scanning Vendor since 2007, according to the announcement, giving the rebuild a customer base rooted in payment-card compliance rather than venture-funded security experimentation.

The PCI Security Standards Council tests ASV scanning solutions and requires vendors to be reapproved annually. CloneGuard's latest expansion moves beyond the external scans associated with that designation and toward continuous exposure management.

Scanning moves behind the login

Traditional unauthenticated scanning tests what an outsider can reach without valid credentials. CloneGuard can now sign into a customer's web applications and APIs using test accounts, allowing it to inspect authenticated workflows, privileged functions and role-based permissions.

That distinction matters because account dashboards, administrative controls, payment workflows and internal APIs frequently sit beyond a login page. A perimeter scan can establish that an application is reachable and identify exposed software. It cannot exercise the same functions available to a customer, employee or administrator after authentication.

Clone Systems has extended the authenticated approach to web application penetration testing. CloneGuard can operate from within an active session and test workflows associated with different permissions. That pushes the product closer to application-security testing while keeping the results inside the same interface used for infrastructure scanning and compliance work.

The tradeoff is volume. Deeper testing produces more findings, leaving smaller security teams with another prioritization problem. Elyse Hamilton, Clone Systems' vice president of business development, described that constraint directly: "A longer list only helps if someone tells you which three things to fix on Monday."

Endpoint agents fill the remote-work gap

CloneGuard also adds lightweight Windows, macOS and Linux agents that collect software inventories from internal and remote computers. Clone Systems says the inventory lets CloneGuard check endpoints for newly published vulnerabilities in seconds and run those checks daily, including on work-from-home machines that conventional network scans may miss.

This changes the cadence of the product. Periodic network scans capture the assets visible during a scheduled window. An endpoint inventory gives CloneGuard a standing record of installed software that can be checked again when a new vulnerability becomes relevant, without waiting for each machine to return to the network.

CloneGuard tags findings against CISA's Known Exploited Vulnerabilities catalog, which tracks vulnerabilities with evidence of exploitation in the wild. Each scan also produces an interactive attack-path view intended to show how separate weaknesses could be chained together.

CISA recommends using the KEV catalog as an input to vulnerability-management prioritization. Clone Systems is combining that exploitation data with attack paths and endpoint inventory to move customers away from sorting vulnerabilities by severity scores alone.

Private AI becomes the prioritization layer

Every CloneGuard report now begins with a "fix-these-first" section. Clone Systems says its AI assistant identifies the affected software, recommends a specific remediation action, answers questions about the customer's environment and compares scans to separate new findings from completed fixes.

Clone Systems hosts the assistant inside its own environment. According to the announcement, customers do not provide an external large language model API key, vulnerability data is not transferred to an outside AI provider, and customer information is not used for model training.

That architecture is central to the pitch. Vulnerability reports can expose software versions, internal systems, attack paths and unresolved weaknesses. Routing that material through another provider creates an additional data-governance decision for security teams. Clone Systems is offering AI remediation without asking customers or white-label partners to manage that connection themselves.

The assistant also gives Clone Systems a way to make the broader detection library usable. Quadrupling a library is valuable only when the additional coverage produces relevant findings and customers can act on them. CloneGuard's rebuild pairs collection with prioritization rather than treating the size of the findings list as the outcome.

Self-serve pricing targets the channel

Clone Systems sells CloneGuard through published online plans, allowing customers to buy scanning without first entering a sales process. External vulnerability scanning starts at $185 a year for one IP address. Clone Systems says subscriptions include access to its U.S.-based security operations center, staffed around the clock by certified analysts.

The low entry price supports a distribution model built around smaller organizations and intermediaries. Clone Systems says more than 100 managed service providers, payment processors, hosting providers and Qualified Security Assessors sell CloneGuard under their own brands. Clone Systems also markets white-label delivery and API integrations for partners that want to embed scanning and compliance workflows in their own portals.

For those resellers, the rebuild creates a broader product without forcing them to assemble separate tools for PCI scanning, authenticated application assessment, endpoint inventory and remediation guidance. Clone Systems gets distribution through providers that already manage customer relationships, while the providers gain a larger security catalog under their own branding.

CloneGuard's release is the product of a 28-year-old managed-security operator widening its original compliance foothold. Clone Systems is betting that smaller security teams will buy continuous scanning when the service reaches authenticated applications and remote endpoints, ranks the results and still arrives with a checkout button.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论