TLDRocket
Sign in

Partnering with Corma: Closing the Defensive Cybersecurity Gap

Sequoia sbarry Covered by 3 sources

Corma is training an AI model for defense, not offense. Sequoia says today’s frontier models help attackers more, and Corma is trying to flip that.

Based on reporting by Sequoia, sbarry — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Sequoia is backing Corma on a simple but uncomfortable thesis: AI has made cyber offense easier faster than cyber defense. The firm says agentic AI and large models have pushed the advantage toward attackers, while defensive teams are still stuck trying to spot trouble in logs, events, traces and telemetry that don’t look much like the text most models are trained on.

That mismatch is the whole pitch. Corma’s team argues defensive security is out of distribution for general-purpose frontier models, because defense isn’t about one clear target. It’s open-ended work, constantly hunting for anomalies in a sea of normal activity. Sequoia says you can’t just hope frontier labs will rework their training pipelines for that use case.

So Corma is training a foundation model specifically for defensive cybersecurity. The company uses large-scale reinforcement learning across environments that mirror real enterprise networks, including the tools, telemetry and noise security teams deal with every day. Sequoia says that approach beats general-purpose foundation models and does it with lower per-token inference costs, which matters because always-on protection can get expensive quickly.

The company is already productizing that model as an agentic Security Workforce. These agents work across security tools and cover roles from security operations and identity management to cloud and network security. Sequoia says they’re already running inside Fortune 500 companies and large enterprises in healthcare, finance, critical infrastructure, retail and other sectors.

The pitch gets more concrete with two examples. One CISO got an alert on a Garmin watch while walking his dog in the evening, confirmed it, and the agent shut the attacker down. In another case, Corma says it found, contained and fixed an active attacker campaign within its first hour at a customer, after the customer’s own security team had missed it for 52 days.

Sequoia frames this as a rare mix of deep technical talent and a very specific market. It says training this kind of model takes world-class hackers and researchers, and calls founder and CEO Alon Pluda one of the most elite hackers in the world. The firm is clearly betting that specialization, speed and control of the model weights will matter more here than the usual frontier-model bragging rights.

My take — AI-written commentary, not fact-checked reporting

This is the rare AI security story that sounds less like a demo and more like a necessity. General models are great at sounding smart; attackers need only be right once, and defenders have to be right all the time. Closed labs will happily sell the sizzle, but if the model can’t live inside messy enterprise telemetry, it’s just another expensive parlor trick.

Read more about this at: Sequoia

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.