Corma CEO Discusses AI Security Innovations Amid Dog Walk Incident
Corma's CEO Alon Pluda shares insights on the company's AI security technology and a recent incident where a cyberattack was thwarted while a security executive was walking his dog
By The Register
Alon Pluda, co-founder and CEO of Corma, has revealed that his AI security startup is focused on addressing the 'defense gap' in cybersecurity, where offensive models currently outperform defensive ones. In an interview with The Register, Pluda recounted an incident involving a security executive who received a notification from a Corma agent while walking his dog. The message read, 'I just caught a live attack. I need your permission to block it.' The executive granted permission, allowing the agent to block malware and prevent the attacker from moving across the company's network in under 10 minutes.
Pluda described the moment as 'one of the most magical moments of his year,' highlighting the effectiveness of Corma's technology. Founded approximately a year ago, Corma derives its name from the Elven word for 'ring,' with Pluda stating, 'We’re building the one ring to rule them all, but this time for the defenders to have this power.'
Recently, Corma announced it had secured $60 million in seed funding, led by Sequoia Capital, with participation from Khosla Ventures and Coatue. The company is collaborating with Fortune 100 companies to develop models aimed at achieving 'superintelligence for defensive cybersecurity.'
Pluda noted that while models from OpenAI, Anthropic, and Google excel in coding and language tasks, including identifying and fixing bugs, they struggle with defensive security tasks that do not involve code scanning. He explained that the majority of defensive security tasks require analysing logs, events, and configurations, which are often not well-represented in the training data for these models.
Corma recently conducted tests using four advanced models—Claude Opus 4.8, GPT-5.5, Grok 4.3, and DeepSeek V4—acting as both attackers and defenders in a simulated multi-business environment. The results showed that while the models successfully implanted a persistent backdoor in 85 percent of their attempts, they only detected 19 percent of the attacks, indicating a significant imbalance in capabilities.
Pluda emphasised that Corma's mission is to close this defensive gap, ensuring that defenders can effectively counteract the growing sophistication of offensive security models. He stated, 'Defensive security is about finding needles in the haystack,' and Corma's AI agents are designed to operate as a workforce across various defensive security tasks.
The deployment of Corma's AI technology in Fortune 100 and 500 organisations across sectors such as healthcare, finance, and energy has reportedly led to a reduction in threat response times by over 94 percent and an expansion of security coverage by 15 times across different functions. Pluda concluded that with sufficiently intelligent AI, organisations could significantly enhance their security capabilities beyond what is achievable through human intelligence alone.