Images are used to safeguarding machines by assessing vulnerabilities in the image. Where assessing vulnerabilities includes both detection and repair, vulnerabilities are detected, a security definition/update is determined for use in repairing the vulnerability, which may include elimination, patching, fixing, writing data to a file or file system associated with the image, or modifying configuration settings. The security definition/update is tested to determine whether to implement the definition and, if test criteria are successfully passed, to permit a system application of the image such as a system restoration following a catastrophic system failure (i.e., disk or drive crash, reboot, etc.).