Corma says AI agents can help defenders stop attacks in real time
Cybersecurity startup Corma is developing AI agents intended to carry out defensive security work, including investigating active intrusions and responding to threats with limited human intervention.C...
Cybersecurity startup Corma is developing AI agents intended to carry out defensive security work, including investigating active intrusions and responding to threats with limited human intervention.
CEO Alon Pluda told The Register that one customer approved a response to a live attack through a notification delivered to a smartwatch while the executive was walking a dog. According to Pluda, the Corma agent blocked malware and prevented the attacker from moving through the organization’s network, containing the incident in less than 10 minutes. The account was not independently verified.
Corma, founded roughly a year ago, says it is focused on what it calls the “defensive gap”: the difference between AI systems’ ability to conduct offensive security operations and their performance when detecting and containing attacks. The company announced $60 million in seed funding led by Sequoia Capital, with participation from Khosla Ventures and Coatue.
Testing attackers and defenders
The startup said it evaluated Claude Opus 4.8, GPT-5.5, Grok 4.3 and DeepSeek V4 in a simulated enterprise environment. In the exercise, one model attempted to install a persistent backdoor while another was tasked with discovering and stopping it. Across 241 scored engagements, the models reportedly planted a backdoor in 85% of attempts but detected attacks in only 19%.
Corma attributes the disparity partly to the kinds of information used to train foundation models. Offensive tasks often have clear objectives and measurable outcomes, while defensive work requires interpreting logs, alerts, configurations, audit records and system state. That data is more structured and, the company argues, less represented in common training material.
AI agents for security operations
The company describes its products as a flexible AI workforce that can assist with multiple security functions. Corma says early deployments at large organizations in sectors including healthcare, finance, energy and retail have cut response times by more than 94%, increased coverage fifteenfold and identified multistage campaigns. Those figures are company claims and were not supported by detailed customer evidence in the report.
Pluda said broad adoption will depend on making agents reliable and trustworthy enough to take action during real incidents, while keeping people involved in high-impact decisions.
