Skip to main content

Partnering with Corma: Closing the Defensive Cybersecurity Gap

Alon and team are training a foundation model for defensive cybersecurity, for enterprises to defend themselves against AI’s scaling offensive capabilities.

Team Corma.

Cybersecurity is a perpetual fight between the good guys and the bad. The age of agentic AI and Mythos-class models has tipped the scales in favor of the bad guys, opening a Pandora’s box for offensive capabilities. An explosion in CVEs has since ensued

Cyberattacks are about technical exploitation, which requires coding and reasoning prowess. Anthropic’s Mythos can discover and exploit zero-day vulnerabilities. Any model paired with a harness brings the cost of social engineering attacks down to near zero, unleashing them at unprecedented scale. The danger is heightened with every new model release. 

Defensive security isn’t improving in parallel. The relevant data lives in logs, events, traces and telemetry, a fundamentally different modality than the bodies of text LLMs usually train on, which barely show up in pretraining. Unlike offensive cybersecurity, which involves goal-directed reasoning towards a defined objective, defense requires open-ended reasoning, continually finding anomalies across vast amounts of normal-looking activity, a distinct capability that typically demands extensive domain-specific training. In short, defense is out of distribution for general-purpose frontier models: neither the data nor the intuition it requires is well-represented in training. In the race toward AGI, we cannot expect the frontier labs to take the detour of overhauling their training pipelines for defensive cybersecurity. And we certainly can’t afford to bet our security on a hope that they do.

Corma has illustrated this “defense gap” in testing. They ran red/blue team simulations where an attacker plants a hidden backdoor and a defender tries to find it. The defender failed to find the backdoor 78% of the time, even when the defender was an identical copy of the very same model that planted it. Holding model quality constant, attackers will always have an advantage.

The only answer to scaling laws on offense is better scaling laws on defense. Recent events have shown that frontier AI for defensive cybersecurity is one of the crucial unsolved problems of the AI age. Solving it is the generational mission Corma was founded on.

Corma founder and CEO Alon Pluda and his team are training a foundation model to power defensive cybersecurity agents. Cybersecurity, like Go or chess, is a two-player, zero-sum game with a clean reward (were you breached or not?) and an endless supply of games to play. Reinforcement learning and self-play have produced superhuman results before in this kind of paradigm. We are seeing history repeat itself. Corma pushes this further with large-scale reinforcement learning across cybersecurity environments that replicate real enterprise networks, with all their tools, telemetry and noise – as part of a training pipeline that produces frontier defensive capabilities, outperforming general-purpose foundation models, with much lower per-token inference costs. 

In the cat-and-mouse game of cybersecurity, we believe Corma’s vertical integration and “sovereign AI” approach will win. Cost matters (always-on inference costs can rack up quickly). Owning the model weights matters (they aren’t subject to restrictions on cybersecurity-related usage set by the closed model labs). And specialization and inference speed really matter (fastest to protect against a new threat wins). 

Corma’s foundation model is deployed and productized as an agentic Security Workforce. These workers operate across different security tools and take on roles spanning the entire security organization: from security operations and identity management to cloud and network security and beyond. They are on the job at Fortune 500 companies and large enterprises across healthcare, finance, critical infrastructure, retail and more.

Corma’s foundation model powers agents that complete defensive work end to end. We spoke to one CISO whose Corma agent notified him of a pending attack through his Garmin watch while he was on a walk with his dog in the evening; with one confirmation, the agent was able to shut the attacker down, all while he was still walking. In another instance, within its first hour on the job, Corma uncovered, contained and remediated an active attacker campaign inside a customer’s network that their security team had missed for 52 days. 

Training frontier foundation models for defensive cybersecurity requires world-class hackers and world-class researchers – almost no company on earth has both. Alon is personally one of the most elite hackers in the world, and has assembled a cohesive and interdisciplinary team of hackers and researchers that is hill-climbing on technical challenges and building impressive commercial momentum. 

We are thrilled to lead Corma’s seed round and to be their partner as they chart new territory in what is sure to be one of the most dynamic races in AI.