- public-sector
- Safety & Security
- representative
Securing a University's Research Infrastructure
A large public university runs a sprawling IT environment: student portals, research lab servers, faculty intranets, IoT devices in smart buildings, and shared HPC (High-Performance Computing) clusters. The central IT security team of two people is responsible for securing all of it. They have no budget for commercial penetration testing tools and limited time for manual assessments.
Runs onVedha- IT team receives a comprehensive asset inventory
- 1,200+ hostsIT team receives a comprehensive asset inventory
- found running services with known critical CVEs (CVSS ≥ 9.0
- 47 hostsfound running services with known critical CVEs (CVSS ≥ 9.0
How the work runs
The pressure that made this worth automating, the steps the system runs, and what came out the other side.
Pressure & Trigger Points
- The university's network spans hundreds of subnets with thousands of hosts many managed by individual departments with no centralized oversight.
- Research servers often run outdated software (old Linux kernels, unpatched Apache/Tomcat instances) because researchers prioritize experiment continuity over patching.
- A recent ransomware incident at a peer institution has prompted the university's CIO to demand an immediate security posture assessment.
The run · 5 operational steps
Click any step to inspect telemetry signals, model reasoning, and governance gates.
scroll →
Broad Network Reconnaissance
The IT team configures a VEDHA Flow with the goal: \
Real-time operational telemetry & queue
MCP grounded vector inference
Policy constrained with audit write-back
Verified Business Outcomes
- The IT team receives a comprehensive asset inventory and vulnerability report covering 1,200+ hosts in under 72 hours-a task that would have taken months manually.
- 47 hosts are found running services with known critical CVEs (CVSS ≥ 9.0), including 12 instances of a remote code execution vulnerability in an unpatched Tomcat installation.
- The report enables the CIO to present concrete risk metrics to the university board and prioritize a targeted patching campaign.
Capabilities this relies on
- workflow orchestration
- generative design
- root cause reasoning
- risk scoring
- evidence audit trail
- human approval
- in boundary deployment
More in Vedha