Corma raises $60M to build a defensive cybersecurity AI foundation model
thenextweb.com

Corma raises $60M to build a defensive cybersecurity AI foundation model

Tech News
3 min read

Published by AINave Editorial • Reviewed by Ramit

TL;DRCorma raised $60M from Sequoia, Khosla, and Coatue to build a foundation model purpose-built for defensive cybersecurity, deploying AI agents that cut threat response times by over 94% in early enterprise deployments.

Corma, a Tel Aviv and San Francisco startup, raised $60 million in seed funding led by Sequoia Capital, with Khosla Ventures and Coatue participating, to build what it calls the first foundation model purpose-built for defensive cybersecurity. The company's AI agents operate across existing security tools, and early deployments at Fortune 100 and 500 companies report threat response times cut by over 94% and coverage expanded roughly 15x. For AI builders, this signals a shift toward specialized models for security operations rather than relying on general-purpose AI.

Why a defensive cybersecurity AI foundation model matters

The core argument from Corma is that offensive AI and defensive AI require different capabilities. Offensive security leverages the coding and reasoning strengths of frontier models, which is why attackers succeed. Defensive security, by contrast, requires processing enormous volumes of audit logs, identifying weak signals over long periods, and maintaining consistency across thousands of decisions. As CEO Alon Pluda told Fortune, defensive work is less about coding and more about "looking at logs, audits, [and] finding the needle in a haystack." General-purpose models are not trained for this, which is why Corma is building a foundation model from the ground up for defense.

The simulation gap: attackers win 88% of the time

In hundreds of simulations modeled on Fortune 500 environments with dozens of security tools, Corma tested leading AI models including GPT and Claude. The models first attacked the simulated organizations and planted persistent threats, then were asked to defend and find what they had planted. Attackers succeeded in 88% of simulations, while defenders caught only 12%. This asymmetry is the structural gap Corma aims to close with its defensive cybersecurity AI foundation model.

How Corma deploys AI agents for security

Rather than selling a traditional product, Corma deploys AI agents that work across an organization's existing security tools and carry out tasks end to end. "We don't replace anyone and we are not a product," Pluda told Calcalist. "We sell virtual human resources." Each organization determines how many agents it needs. The team combines frontier AI researchers from Google and DeepMind with cybersecurity specialists from Israel's Unit 8200, and early deployments span healthcare, financial services, energy, and retail.

What this means for AI builders

For teams building AI agents or security tools, Corma's approach highlights the value of domain-specific training. General-purpose models excel at reasoning and coding, but security operations demand sustained log analysis and multi-tool orchestration. The $60M seed round, one of the largest for a security AI startup, signals investor confidence in this specialization. Sequoia partner Shaun Maguire said Corma "has trained its model for the complexity of real-world attacks and is building the intelligence layer defense actually needs."

Caveats and open questions

The performance claims come from Corma's own early deployments and simulations, not independent benchmarks. The 88% attacker success rate and 94% response time reduction are vendor-reported figures that need external validation. Concrete details on model architecture, training data, pricing, and long-term deployment results are not yet public. Builders should treat these as directional signals rather than verified outcomes.

The bottom line

Corma's funding and early traction suggest that defensive cybersecurity AI is becoming a distinct category. For builders, the lesson is that specialized foundation models can outperform general-purpose ones in narrow, high-stakes domains. The question is whether Corma can deliver on its claims at scale, and whether the defensive model can keep pace with the offensive AI it is designed to counter.

Sources

Latest Tech News