Full Report
Corma CEO tells The Reg it's building 'One ring to rule them all, for the defenders to have this power'
Analysis Summary
# Industry News: Corma Emerges with $60M Seed Funding to Bridge the AI "Defense Gap"
## Summary
Corma, a cybersecurity startup led by Alon Pluda, has emerged from stealth with $60 million in seed funding to develop agentic AI "coworkers" designed for defensive security. The company aims to close the "defense gap"—a phenomenon where frontier AI models are significantly more effective at offensive exploitation than defensive detection and response.
## Key Details
- **Date:** August 16, 2026
- **Companies Involved:** Corma (Startup), Sequoia Capital (Lead investor), Khosla Ventures, Coatue
- **Category:** Product Launch / VC Funding / AI Research
## The Story
Corma is positioning itself as the "one ring to rule them all" for cybersecurity defenders. The company’s core thesis is based on proprietary research showing a massive disparity in AI capabilities: while frontier models (like GPT-5.5 and Claude 4.8) succeed in offensive tasks 85% of the time, they only detect attacks in 19% of cases.
Corma argues that general foundation models are naturally biased toward offense because they are trained on code and prose, whereas defense requires interpreting "structured machine data" (logs, audit trails, and on-disk states). To solve this, Corma has developed "superintelligent" defensive models and AI agents that act as a generalized workforce. These agents can autonomously identify threats and request human permission via mobile or wearable devices to execute blocks, reportedly reducing threat response times by 94%.
## Business Impact
### For the Companies Involved
- **Corma:** Secures a massive $60M seed round, providing a significant runway to scale its AI workforce across Fortune 100 clients.
- **Investors:** Sequoia and Khosla Ventures are doubling down on "Agentic AI," betting that the next wave of security value lies in autonomous action rather than just alerts.
### For Competitors
- **Legacy SIEM/SOAR Providers:** Face a direct threat from "agentic" security that bypasses traditional, manual playbook-heavy workflows.
- **AI Security Startups:** Corma’s high-profile backing and focus on the "defense gap" sets a new benchmark for technical validation in the AI-native security market.
### For Customers
- **Resource Efficiency:** Enables small security teams to achieve the coverage of a much larger SOC.
- **Operational Agility:** The "human-in-the-loop" mobile approval model allows executives to manage high-stakes security events without being tethered to a desk.
### For the Market
- **Shift to Autonomous SOC:** The narrative is shifting from "AI-assisted" to "AI-led" security operations.
- **Validation of Specialist Models:** The market is recognizing that general-purpose LLMs are insufficient for specialized defensive telemetry without domain-specific training.
## Technical Implications
Corma’s research highlights a critical technical bottleneck: LLMs struggle with "structured machine data" that isn't prose or source code. Their innovation lies in training models specifically to reason through logs and configurations. The "agentic" nature allows these models to move from vulnerability research (scanning) to active orchestration (mitigation and blocking across a network).
## Strategic Analysis
- **Market Positioning:** Corma is positioning itself as the elite "Defensive AI" layer, specifically targeting complex, multi-business enterprises (Fortune 100).
- **Competitive Advantage:** Early access to high-fidelity attack/defense data and a head start on the "agentic" workflow gives them a moat against general LLM providers.
- **Challenges:** Establishing "trust" is the primary hurdle. Organizations may be hesitant to grant autonomous agents the power to block traffic or change configurations in production environments.
## Industry Reactions
- **Analyst Sentiment:** The "defense gap" research is likely to become a key talking point in the industry, highlighting the danger of lopsided AI development.
- **Market Response:** The participation of top-tier VC firms like Sequoia suggests high confidence in Corma’s ability to disrupt the traditional SOC model.
## Future Outlook
- **Predictions:** We can expect a "cat-and-mouse" game where offensive AI agents and defensive agents like Corma’s engage in high-speed, automated skirmishes.
- **What to watch for:** Whether Corma moves toward "full autonomy" (removing the human-in-the-loop) or stays as a "co-pilot" for security leaders.
## For Security Professionals
Practitioners should note the transition from "scanning for bugs" to "managing AI agents." The skill set required is shifting from manual log analysis to "agent orchestration"—assigning tasks to AI workers and serving as the final decision-maker for high-impact mitigation actions. This technology promises to alleviate burnout by handling the "needle in the haystack" search tasks.