Cloud Security · Agentic AI Product Launch

Upwind Launches AI Agentic Pack — An Agentic Security Workforce Built on Runtime Context to Investigate, Validate and Remediate Cloud Threats

iTech360Hub | 5 min read | Runtime-First Cloud Security

Cloud security has a well-documented problem that more visibility alone cannot solve. Security teams already have access to large volumes of alerts, findings, and telemetry — the challenge is determining which risks are actually meaningful, which vulnerabilities are genuinely reachable in production, and what action to take next, quickly enough to reduce real exposure. Static analysis flags potential vulnerabilities. The question that matters is which of those vulnerabilities are actively running and exposed right now — and that question requires runtime context to answer. Upwind, the runtime-first cloud security leader backed by $430 million in funding, has launched the AI Agentic Pack — a new set of specialised AI agents built into its Cloud & AI Security Platform to support investigation, risk validation, and remediation across cloud and AI environments.

The AI Agentic Pack addresses the gap that defines modern cloud security operations — not a lack of data, but the inability to interpret risk and respond quickly enough at the scale and pace that AI-driven threat environments demand. Gartner predicts AI applications will drive 50% of cybersecurity incident response efforts by 2028. Upwind's launch positions the company at the forefront of that shift — moving from AI-assisted prioritisation to genuine agentic agency, where specialised agents autonomously investigate, validate real exposure, and guide remediation grounded in the live reality of what is actually happening across the environment.

50%
Of cybersecurity incident response efforts predicted to be AI-driven by 2028 (Gartner) — the market shift that Upwind's AI Agentic Pack is built to lead
$430M
Total funding backing Upwind's runtime-first cloud security platform — founded in 2022 by the team behind Spot.io and growing rapidly across enterprise cloud environments
4 Agents
Specialised AI agents in the initial AI Agentic Pack — Investigate, Validate, Solve, and Guide — each addressing a distinct dimension of cloud threat investigation and response

"AI is transforming how security teams operate. We are shifting from prioritization to agency and AI-driven security workforces. The future of cloud security will be driven by AI agents that can investigate, validate, solve, and guide action in real time, grounded in the reality of what's happening across the environment. With the AI Agentic Pack, we're turning runtime context into an agentic security workforce that gives security teams high agency and capabilities never seen before, helping them move faster, prioritize real risk and stay in control of the decisions that matter most."

— Moshe Hassan, VP Product & Research, Upwind

The Runtime-First Difference — Why Context Is the Core Advantage

The defining characteristic of Upwind's approach is its runtime-first philosophy — and it is what makes the AI Agentic Pack qualitatively different from conventional cloud security automation. Traditional cloud security tools, including most CNAPP platforms, perform static analysis: they scan configurations, code, and infrastructure definitions to identify potential vulnerabilities. This is useful. It is also fundamentally limited — because static analysis cannot distinguish between a vulnerability that is actively running and exposed in production and one that exists in code that never executes.

Runtime context involves analysing the live behaviour of cloud services — application interactions, identity activity, network communication patterns, and the actual execution of code in production. This real-time, evidence-based view of the environment is what allows Upwind's agents to answer the question that matters: not "does this vulnerability exist?" but "is this vulnerability actively reachable and exploitable right now?" The difference between those two questions determines whether a security team spends its limited capacity on real risk or on noise.

The AI Agentic Pack connects findings to live cloud activity, service relationships, identity behaviour, and execution context — enabling teams to focus investigation and remediation effort on what is actually running and exposed in production, rather than working through an undifferentiated backlog of potential issues that may have no material risk in the current operating environment.

The Four AI Agents — Investigate, Validate, Solve, and Guide

The AI Agentic Pack is structured as a set of four specialised agents — each designed to address a distinct phase of the cloud threat investigation and response lifecycle. Together, they form what Upwind describes as an agentic security workforce: a team of AI-driven capabilities that can operate at the speed and scale that human-only security operations cannot sustain.

Investigate Agent — Autonomous Deep Investigation of Cloud Security Events

The Investigate Agent autonomously researches security events and alerts — performing the deep investigation work that would otherwise require hours of analyst time. By combining runtime telemetry with threat intelligence and environmental context, it surfaces the full picture of what happened, what was affected, and how the event connects to broader activity patterns across the cloud environment. This transforms the investigation phase from a manual, time-consuming process into a rapid, automated workflow that keeps pace with the volume of modern cloud security signals.

Validate Agent — Confirming Real Exposure with Runtime Evidence

The Validate Agent addresses the fundamental challenge of cloud vulnerability management: determining which findings represent genuine, active risk versus theoretical vulnerabilities in code or configurations that are not reachable in the current production environment. Using runtime context — actual service behaviour, network reachability, and execution patterns — the Validate Agent confirms real exposure with evidence rather than assumption, dramatically reducing the false positive burden that has historically made cloud security prioritisation so difficult to execute effectively.

Solve Agent — Automated Remediation for Validated Cloud Risks

The Solve Agent takes validated risks and automates the remediation actions required to address them — executing fixes within defined guardrails and maintaining a full audit trail of actions taken. By automating the remediation layer for confirmed, active risks, the Solve Agent collapses the time between detection and resolution that has historically been the most dangerous window in cloud security operations. Human oversight remains central — teams set the boundaries within which the agent operates, maintaining accountability without sacrificing response speed.

Guide Agent — Actionable Remediation Guidance Grounded in Real Context

The Guide Agent provides contextual, step-by-step remediation guidance for risks that require human decision-making or engineering involvement — translating complex cloud security findings into clear, actionable instructions that development and operations teams can execute without requiring deep security expertise. Rather than flagging a vulnerability and leaving teams to research the fix independently, the Guide Agent delivers the specific remediation path grounded in the actual structure of the affected environment, accelerating resolution even for the most technically complex cloud risks.

The Broader Market Shift — From Prioritisation to Agency in Cloud Security

The launch of the AI Agentic Pack reflects a structural shift in how cloud security must evolve. The first generation of AI-assisted security tools improved prioritisation — surfacing the most critical findings from a sea of alerts and helping teams decide where to focus. That was meaningful progress. But prioritisation still leaves the work of investigation, validation, and remediation to human operators who are already stretched beyond capacity by the volume and velocity of modern cloud security signals.

The next generation — what Upwind is building with the AI Agentic Pack — moves from prioritisation to agency. Rather than recommending what to do and leaving execution to an overloaded human team, agentic systems take on the investigation and remediation work directly, operating continuously within defined guardrails and maintaining human accountability for the decisions that matter most. For MSPs, this model also opens a path to scaling managed security services at higher volumes of telemetry without proportionally increasing headcount.

Cloud Threat Investigation

Autonomous, deep investigation of cloud security events — connecting runtime telemetry, service relationships, identity activity, and execution context to surface the full picture of what happened and what was affected.

Real Exposure Validation

Runtime-grounded confirmation of which vulnerabilities are actively reachable and exploitable in production — eliminating the false positive burden that makes prioritisation ineffective and erodes security team trust in static analysis outputs.

AI System Security

Security coverage purpose-built for AI environments — covering the models, agents, pipelines, and data flows that conventional cloud security platforms were not designed to address, as AI workloads become an increasingly critical part of the enterprise attack surface.

Upwind Cloud & AI Security Platform Capabilities
AI Agentic Pack Runtime Context Security Real Exposure Validation Automated Remediation CNAPP Platform Cloud Threat Investigation AI Environment Security Identity & Workload Behaviour

Key Takeaways

1

Upwind has launched the AI Agentic Pack — a set of four specialised AI agents (Investigate, Validate, Solve, Guide) built into its Cloud & AI Security Platform — shifting cloud security from AI-assisted prioritisation to genuine agentic agency across investigation, risk validation, and remediation.

2

Upwind's runtime-first philosophy is the core differentiator — analysing live cloud behaviour, service relationships, identity activity, and actual code execution to confirm which vulnerabilities are genuinely reachable in production, rather than flooding teams with static analysis findings that may carry no real risk in the current environment.

3

The launch directly targets the defining operational gap in cloud security — not a lack of visibility, but the inability to interpret risk and act fast enough — as Gartner predicts AI will drive 50% of cybersecurity incident response by 2028 and attackers leverage AI to accelerate vulnerability discovery and exploitation.

4

Founded in 2022 and backed by $430 million in funding, Upwind's AI Agentic Pack enables security teams of all sizes — from startups to global enterprises and MSPs — to operate at the speed and scale of AI-driven threats without proportionally expanding headcount, keeping humans in control of the decisions that matter most. Learn more at upwind.io.

The AI Agentic Pack launch marks a meaningful moment in the evolution of cloud security — from tools that help human analysts decide where to focus, to agents that do the investigative and remediation work themselves, grounded in the runtime truth of what is actually happening in production. Upwind's runtime-first architecture provides exactly the contextual foundation that agentic security requires to operate with confidence: not static analysis of potential risks, but live evidence of actual exposure, service behaviour, and identity activity that gives AI agents the grounding to act accurately and at scale. As the pace of cloud threat environments continues to accelerate, the organisations that will manage risk most effectively will be those whose security operations are no longer constrained by human bandwidth alone.

To learn more about the AI Agentic Pack and Upwind's runtime-first Cloud & AI Security Platform, visit upwind.io.

Tags
Cloud Security Agentic AI Security Runtime Context CNAPP Real Exposure Validation Automated Remediation AI Environment Security Cloud Threat Investigation