AI-Powered 'Scan for Good' Initiative Finds and Fixes Hundreds of Public Sector Security Gaps
Security firm Wiz Research has launched a new initiative called Scan for Good, which pairs artificial intelligence with human security researchers to find dangerous exposures and attack paths in public services, critical infrastructure, and nonprofit organisations. The goal is simple: find weaknesses before criminals do. The project has already helped identify and fix hundreds of public exposures by working directly with affected organisations on remediation.
The initiative is backed by Google DeepMind and has engaged with the US Cybersecurity and Infrastructure Security Agency (CISA) for guidance and collaboration, aligning with broader efforts to responsibly use AI for cybersecurity resilience. Rather than hunting for single software bugs, Scan for Good focuses on how combinations of everyday configurations, permissions, identities, APIs, and application behaviours can create serious attack paths when connected, even if each element looks harmless on its own.
This approach reflects a growing trend in cybersecurity: real-world risk is often less about one flaw in code and more about how systems interact once exposed to the internet. While this project targets large public and critical infrastructure organisations, the underlying lesson applies broadly to any organisation with internet-facing systems.
Key Takeaway: Small businesses should regularly review how their internet-facing systems, accounts, and permissions interact, since combined weaknesses can be just as dangerous as a single software flaw.