TLDRocket
Sign in

Partnering with Corma: Closing the Defensive Cybersecurity Gap

Sequoia By Shaun Maguire , Sonya Huang , James Flynn and Carl Eschenbach Covered by 3 sources

Corma says defensive cyber AI is falling behind offensive AI. It’s building a model for security teams because general models miss the weird stuff in logs and telemetry.

Based on reporting by Sequoia, By Shaun Maguire , Sonya Huang , James Flynn and Carl Eschenbach — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Corma’s pitch is simple: offensive AI is moving faster than defensive AI, and that gap is becoming dangerous. Sequoia says new models have made it cheaper to build attacks, from zero-day exploitation to social engineering at scale, while defenders are still stuck with a harder problem that general-purpose models aren’t built for.

The core issue is data. Attack tools can reason toward a clear target. Defense has to sift through logs, events, traces and telemetry, looking for the odd thing hiding inside a mountain of ordinary activity. That kind of work is out of distribution for frontier models, Sequoia argues, because the training data and the intuition needed for it barely show up in pretraining.

Corma tried to show the gap in a red-team, blue-team simulation. An attacker planted a hidden backdoor and a defender tried to find it. The defender missed it 78% of the time, even when it was the same model that had planted the backdoor in the first place. The message is blunt: if the model quality stays the same, the attacker still has the edge.

So Corma is training a foundation model specifically for defensive cybersecurity. Founder and CEO Alon Pluda and his team are using large-scale reinforcement learning in simulated enterprise networks filled with real tools, telemetry and noise. The company says that approach produces better defensive performance than general-purpose models, while keeping per-token inference costs lower.

That model is already packaged as an agentic Security Workforce, with agents that handle work across security operations, identity management, cloud, and network security. Sequoia says these agents are already in use at Fortune 500 companies and large enterprises in healthcare, finance, critical infrastructure, retail and other sectors. In one case, a CISO got an alert on his Garmin watch during an evening walk; in another, Corma says it found and shut down an active attacker in its first hour on the job, after the customer’s own team had missed it for 52 days.

My take — AI-written commentary, not fact-checked reporting

This is the right bet: defensive AI won’t come from general chat models that were trained to sound smart about everything. Security is full of ugly, noisy edge cases, and closed-model labs are not exactly famous for building tools that let customers move fast against fresh attacks. Specialization is boring, which is why it may actually work.

Read more about this at: Sequoia

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.