Partnering with Corma: Closing the Defensive Cybersecurity Gap
Sequoia sbarry ● Covered by 3 sources
Corma is training an AI model for defense, not offense. Sequoia says today’s frontier models help attackers more, and Corma is trying to flip that.
Based on reporting by Sequoia, sbarry — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Sequoia is backing Corma on a simple but uncomfortable thesis: AI has made cyber offense easier faster than cyber defense. The firm says agentic AI and large models have pushed the advantage toward attackers, while defensive teams are still stuck trying to spot trouble in logs, events, traces and telemetry that don’t look much like the text most models are trained on.
That mismatch is the whole pitch. Corma’s team argues defensive security is out of distribution for general-purpose frontier models, because defense isn’t about one clear target. It’s open-ended work, constantly hunting for anomalies in a sea of normal activity. Sequoia says you can’t just hope frontier labs will rework their training pipelines for that use case.
So Corma is training a foundation model specifically for defensive cybersecurity. The company uses large-scale reinforcement learning across environments that mirror real enterprise networks, including the tools, telemetry and noise security teams deal with every day. Sequoia says that approach beats general-purpose foundation models and does it with lower per-token inference costs, which matters because always-on protection can get expensive quickly.
The company is already productizing that model as an agentic Security Workforce. These agents work across security tools and cover roles from security operations and identity management to cloud and network security. Sequoia says they’re already running inside Fortune 500 companies and large enterprises in healthcare, finance, critical infrastructure, retail and other sectors.
The pitch gets more concrete with two examples. One CISO got an alert on a Garmin watch while walking his dog in the evening, confirmed it, and the agent shut the attacker down. In another case, Corma says it found, contained and fixed an active attacker campaign within its first hour at a customer, after the customer’s own security team had missed it for 52 days.
Sequoia frames this as a rare mix of deep technical talent and a very specific market. It says training this kind of model takes world-class hackers and researchers, and calls founder and CEO Alon Pluda one of the most elite hackers in the world. The firm is clearly betting that specialization, speed and control of the model weights will matter more here than the usual frontier-model bragging rights.
My take — AI-written commentary, not fact-checked reporting
This is the rare AI security story that sounds less like a demo and more like a necessity. General models are great at sounding smart; attackers need only be right once, and defenders have to be right all the time. Closed labs will happily sell the sizzle, but if the model can’t live inside messy enterprise telemetry, it’s just another expensive parlor trick.
Read more about this at: Sequoia
Related stories
Cogent AI Team Releases VR-1: A Frontier Cyber Reasoning Model That Composes and Verifies Enterprise Attack Paths
MarkTechPost · 1 month ago ·
6
Breakout time hits zero as CrowdStrike unveils autonomous red teaming: theCUBE’s Fal.Con 2026 day one keynote analysis
SiliconANGLE · 1 week ago ·
15