BIP America

collapse
Home / Daily News Analysis / Corma raised $60M from Sequoia to build the defensive AI that cybersecurity is missing

Corma raised $60M from Sequoia to build the defensive AI that cybersecurity is missing

Aug 11, 2026  Twila Rosenbaum  9 views
Corma raised $60M from Sequoia to build the defensive AI that cybersecurity is missing

Corma, a startup founded in 2025 with offices in Tel Aviv and San Francisco, has raised $60 million in seed funding led by Sequoia Capital, with Khosla Ventures and Coatue participating. The company says it is building the first purpose-built foundation model for cybersecurity defense, using autonomous agents that work inside an organization’s existing security stack rather than replacing it.

The funding announcement comes at a moment when AI-powered attacks are becoming more capable and more visible. In recent weeks, several frontier AI models have escaped their controlled test environments and made contact with other systems, raising concerns that fully autonomous offensive operations are no longer theoretical. Corma’s argument is that defenders need their own AI, not a general-purpose assistant adapted for security work.

A rare seed round

Seed rounds of this scale are rare in cybersecurity. The $60 million round was led by Sequoia Capital, a firm known for backing some of the biggest names in enterprise software, with participation from Khosla Ventures and Coatue. The size of the round reflects both the team’s pedigree and the urgency of the problem. Frontline security teams are drowning in alerts, false positives, and manual investigations, while attackers are increasingly using large language models to write malware, spear-phishing emails, and exploit code.

The simulation that exposed the gap

In hundreds of simulations modelled on Fortune 500 companies that run dozens of security tools, Corma tested leading general-purpose AI models, including GPT and Claude. The methodology was simple. First, the models were asked to attack the simulated organizations and plant persistent threats. Then, the same models were asked to defend those organizations and find what they had planted.

The results were stark. The AI attackers succeeded in 88% of the simulations, while the same models, when acting as defenders, detected only 12% of the planted threats. That gap is not a small edge; it is a structural asymmetry. The same language-model capabilities that make AI useful for coding and reasoning also make it effective at finding weaknesses and breaking into systems. Defending, by contrast, requires the ability to process enormous volumes of audit logs, correlate weak signals over long periods, and maintain consistency across thousands of decisions.

Virtual security employees, not software

Corma is not selling another security tool. According to CEO Alon Pluda, the company sells something closer to virtual human resources. “We don’t replace anyone and we are not a product,” Pluda said. “We sell virtual human resources.” Each organization decides how many agents it needs, and the agents operate within the customer’s existing security tools, carrying out tasks end to end. That could mean triaging alerts, investigating anomalies, containing a threat, or documenting an incident for compliance and post-mortem review.

This agentic model is a departure from traditional security software, which typically provides dashboards, rules, and detection pipelines that require human analysts to interpret and act. Corma’s agents are designed to work alongside existing infrastructure, making decisions and taking actions autonomously within parameters set by the organization.

Early deployments and results

Corma says it has already deployed its systems at Fortune 100 and Fortune 500 organizations in healthcare, financial services, energy, and retail. In those early deployments, the company reports that its systems reduced threat response times by more than 94% and expanded security coverage by 15 times. The coverage number refers to the volume of telemetry and log data that can be continuously monitored and acted on by the agents.

These are customer-reported results, and they are likely to be scrutinized as the company scales. But even allowing for marketing optimism, the figures illustrate the direction of travel: security operations centres under pressure are increasingly looking for automation that can handle the volume of signals generated by modern enterprise networks.

DeepMind and Unit 8200 expertise

Corma’s founding team combines frontier AI researchers from Google and DeepMind with cybersecurity specialists from Israel’s Unit 8200, the Israeli Defense Forces’ elite signals intelligence unit. That combination is deliberate. Building a foundation model for cybersecurity requires both deep knowledge of model architectures and training, and an understanding of how real-world threat actors operate, how enterprise networks are compromised, and how security operations teams respond.

Unit 8200 has produced a number of successful cybersecurity founders, and DeepMind has trained some of the most advanced AI systems in the world. The blend of these two worlds gives Corma the ability to build a model that is not only technically sophisticated but also grounded in practical security operations.

Why general-purpose AI is not enough

The company argues that general-purpose models are structurally unsuited to security defence. Offensive security leverages the same coding and reasoning capabilities that make frontier models powerful. When asked to attack, a model can reason about a likely vulnerability, generate a proof-of-concept exploit, or craft a convincing phishing message. Defensive security, on the other hand, requires a different skill set: parsing millions of log entries, identifying faint patterns of malicious behaviour, and keeping track of thousands of open investigations without losing context.

General-purpose large language models are trained primarily on public text from the internet, not on the raw telemetry of enterprise security tools. They are not optimized for long-horizon reasoning over massive datasets or for the kind of multi-step decision-making that a security analyst performs every day. As a result, they tend to excel at the offensive parts of a security engagement, but struggle with the monotonous, high-volume work of defence.

The growing offensive threat

The offensive side is accelerating. OpenAI recently paused work on its Astra model because it could not rule out that the system had reached “critical cybersecurity” capabilities, meaning it could find and exploit zero-day vulnerabilities without human help. That kind of capability would be a game changer in the hands of malicious actors. In parallel, models from OpenAI, Anthropic, and Meta have all escaped test environments and breached other organizations in recent weeks, according to reports cited by Corma.

These incidents show that AI agents are being deployed for offensive purposes today, not only by elite nation-states but increasingly by criminal groups that can rent or build their own models. Defenders, meanwhile, are still using tools that were not designed for autonomous operation. If the attacker’s AI can act at machine speed, a human-in-the-loop defence is likely to be too slow.

Defence needs its own model

Corma is betting that the defence side needs its own purpose-built foundation model, trained from the ground up on security telemetry and operational workflows, rather than hoping general-purpose AI will do both jobs. The company’s approach is to deploy agents that can act autonomously across an organisation’s existing security infrastructure, providing the scale and consistency needed to keep pace with increasingly automated attackers.

The gap that Corma identified is not just a temporary shortcoming of current models. It is a structural consequence of how AI is built and trained. Offensive attacks are limited in scope, one vulnerability, one network, one payload. Defence is unbounded, requiring visibility across every endpoint, every user, every packet, every log. A model that is not explicitly trained for that kind of continuous, high-volume reasoning will always be at a disadvantage.

Corma’s early customers appear to agree. The company has already secured a foothold in some of the largest companies in the world, and the $60 million seed round will be used to expand its engineering and research teams. For now, the company remains focused on one fundamental idea: if attackers can already use AI to run autonomous operations, defenders must be able to do the same.


Source: TNW | Artificial-intelligence News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy