SecurityBrief Canada - Technology news for CISOs & cybersecurity decision-makers
Canada
eSentire adds email & patch tools to Atlas AI platform

eSentire adds email & patch tools to Atlas AI platform

Fri, 31st Jul 2026 (Today)
Mark Tarre
MARK TARRE News Chief

eSentire has added new response, email and patch management functions to its Atlas AI Platform. The update also includes a partnership with Sublime Security.

The changes bring email detection and response into Atlas alongside threat detection, investigation and remediation.

The additions are intended to connect several stages of security operations that are often handled through separate tools. The platform now includes response orchestration, attack-informed defence and patch management, while the Sublime partnership extends monitoring into email, a common entry point for attacks.

eSentire said the response orchestration feature defines how Atlas should react once a security finding is confirmed. Actions can include notifying staff, isolating hosts and suspending compromised users, with each step logged and reversible.

The process can operate within rules set by customers, with some actions running automatically and others requiring human approval. This is intended to let organisations decide where automation ends and analyst oversight begins.

Email focus

The partnership with Sublime Security brings programmable email detection and response into the platform. eSentire said this allows Atlas to inspect the behaviour and apparent intent of messages to identify phishing attempts, business email compromise and AI-generated lures.

Many managed detection and response services still treat email as a separate or limited category, often relying on sender or domain blocking after an incident has already been identified, according to eSentire. Under the new arrangement, the company said it will be able to create and deploy detections when a new attack pattern appears rather than wait for a vendor update.

Atlas also correlates email signals with endpoint, identity and network activity, according to eSentire. This allows analysts to review a threat as a single attack path rather than as separate alerts from different tools.

The launch follows the recent opening of eSentire's US-based Security Operations Centre. The company says it protects more than 2,000 organisations across more than 35 industries.

In a statement, James C. Foster outlined the company's view of the problem it is trying to address.

"Security teams are tired of stitching together a patchwork of disconnected tools, which only creates gaps for attackers to exploit. Today's announcements make Atlas a single unified pane of glass across a security program from the moment a threat is identified, through investigation, to response and remediation. By giving AI the controlled autonomy to validate and neutralize exposures at machine speed, we let organizations act across their environment from one point of control. The security landscape is shifting, and eSentire is leading the charge," said James C. Foster, Chief Executive Officer, eSentire.

Threat handling

Another part of the update is what eSentire calls attack-informed defence. The company said this function tracks adversary techniques, active campaigns and command-and-control infrastructure, then checks customer environments when its Threat Response Unit confirms a new threat.

According to eSentire, Atlas can then search across its customer base, contain threats proactively and distribute new detections more widely. The company also said the platform uses AI-led penetration testing simulations to identify exploitable weaknesses such as open S3 buckets, vulnerable edge devices and exposed credentials.

Patch management is also being brought into the same workflow. eSentire said Atlas uses information about a customer's environment, attacker behaviour and exposure data to decide which weaknesses are exploitable and which fixes should be prioritised.

Security teams can then push those fixes directly from Atlas or use existing patching systems. This links the identification of a weakness with the operational step needed to address it.

Email remains a central concern for security teams. eSentire cited its own research showing that nearly half of threats originate through email, helping explain the significance of extending Atlas into inbox monitoring rather than treating email as a separate layer.

Sublime Security said the partnership is intended to strengthen how email-borne threats are handled within broader incident response operations.

"Email has been a primary way in for decades, and AI has made the lures faster and more convincing than training alone can counter. That is why we built Sublime's programmable email security into eSentire's Atlas platform: to pair behavior-based detection with elite Managed Detection and Response, shutting down email-borne threats before they land," said Timm Hoyt, Vice President, Worldwide Partner Sales & Alliances, Sublime Security.