Vega Brings AI Reasoning to Cyber Defense
AI Reasoning Changes the Cyber Defense Model
Alan Shimel speaks with Eli Rozen, co-founder and CTO of Vega, during Techstrong TV’s Black Hat coverage. Their conversation focuses on large language models and frontier AI reasoning. These tools are changing the balance between attackers and defenders. As adversaries adopt AI, security teams need a faster response. Vega is working to make AI reasoning for cyber defense more useful for those teams.
Rozen says Vega was created to address a growing gap in modern cybersecurity. Attackers can now use AI to speed up research, automation and campaign development. Defenders often still depend on legacy systems. Many of those tools were not built for today’s volume of security data. They also struggle with the speed and variety of modern signals. That gap adds pressure to teams that already have limited time and resources.
Security Data Must Be Accessible Where It Lives
A major theme is the future of the SIEM and SOC. Rozen says legacy SIEM platforms can limit visibility. They often depend on selected data being ingested into one central system. Vega takes a different path. Its approach uses federation to reach security data where it already lives. That can include cloud telemetry, EDR logs and other enterprise sources.
This model gives AI systems the context they need. Without that context, even advanced AI tools may miss important signals. Broader access can improve investigations and support better judgment. It can also help teams connect activity across more parts of the enterprise. In that model, AI reasoning for cyber defense becomes more practical and more complete.
The SOC Moves Toward Agentic Workflows
Rozen also discusses the idea of an agentic SOC. In that model, AI agents help scale the judgment of security professionals. They can review large amounts of data and help teams understand what is happening. The goal is not just to automate isolated tasks. It is to give defenders better context during detection, investigation and response.
For security leaders, this shift could change how teams use AI in daily operations. Vega’s approach points toward a SOC where human expertise and AI reasoning work together. Black Hat shows that AI is becoming a larger part of cybersecurity. This conversation explains why data access, context and trust will shape the next phase of cyber defense.
Transcript
Hey everyone. Welcome back here to Techstrong TV on Black Hat Week. Appreciate you joining us.
My next guest is Eli Rosen. Eli is the co-founder and CTO of Vega. Eli, welcome to Techstrong TV.
It's great to have you on. Thank you, Alan. It's great to be here.
Super exciting. Yes. So of course, we recorded this last week, the week before Black Hat on a Friday, so it's literally just a couple of days ago, and it's part of our Black Hat coverage.
We'll mention Vega is here at Black Hat. If you're watching this, go check them out. But before we get into all that, Eli, let's talk about you.
You're, as I mentioned, a co-founder and CTO at Vega. Give us your path, what made you co-found Vega? Yeah.
Awesome. I started my cyber career at Unit 8200 in Israel, just like all the other cyber Israeli entrepreneurs. Very surprising here.
All right. No, but I've been doing software development and product building, and doing cyber for basically as long as I know myself, since the age of 18, and I love it. I'm super passionate about it.
And yeah, we started Vega, my co-founder, Shai and I, two and a half years ago in this moment of AI change, together with all that's happening in the world. And, yeah, super exciting to go forward with what we build here. So look, I started four or five different companies in my life, venture backed.
Not this one, this was not venture backed, but all the others were. Except the first one wasn't either, and I sold that one. But no-one just starts a company because they feel like it.
Everyone starts a company because they feel it in their gut, in their soul, that they got to do this. That there's somehow, some way, there's this problem they're solving. It may be a problem they had and said, "I can't be the only one with the problem.
" What was that passion for you and Shai in Vega? What was it that you saw and said, "This needs to be solved. This needs to be better"?
Yeah. First of all, as people, I think both Shai and I are builders in heart. I love to build.
I'm very passionate about building great products, and together with the expertise that I got in the cyber career, I'm also very passionate about cyber. And I think when we started Vega, and clearly, the moment is even much more clear today, Mythos and large language models and all the AI frontier reasoning has changed the game for the adversaries. And all of the adversaries are using AI, and I think we got to a point where defenders are asymmetrical in their defense, and that keeps me super passionate about what we do in Vega.
Because we wake up every day, and we can help cyber defense engineers across the United States and the world protect their enterprises. And it's a very, I would say, compelling mission because the fact that we can wake up every morning and actually help enterprises secure their company and be successful at what they do, and leverage AI to defend against everything that's going on, I think it's very exciting. It gives purpose to what we do in Vega, and it gives much more excitement to the day-to-day life of an entrepreneur because, as you know, entrepreneurs, we always face challenges, and there is always something that's going to be on the way.
But staying super humble and connected with the people that you're supposed to serve as customers, it's just super exciting. It's a very exciting time to build. Very, very exciting time to build.
And, yeah, I'm super passionate about it- So let me dig in a little deeper then, Eli. So I understand the problem that Vega's looking to help with. How do you do it?
What exactly is Vega? What does it do that helps people with this? Yeah.
Our mission at Vega is to help fix the asymmetrical moment in cyber defense. We help organizations put frontier models to work on the full potential of security data. And if you look at the security operations or the cyber defense industry for the last 20 years, legacy SIEM has not scaled with all the changes in AI.
And to be able to scale AI reasoning across all of the security data, you need to be able to access data where it lives, and therefore, it's time for a completely new approach that's completely changing what the SIEM means and what the SOC looks like. Because when I speak with customers and our partners about what is the nirvana of agentic SOC, what is that moment of this is agentic SOC, people understand that they want to use the best judgment and to be able to scale it across AI agents. But in order to do so, you first have to solve the data problem, because if you're constrained and you're limiting the data access to the AI, then it doesn't have all the context.
So federation is a key part of what we do in Vega, which is very different than a legacy SIEM, because a legacy SIEM limits what you see by default because it can only see what you ingest into that SIEM. On top of that, now that we have access to all of the data, and we access it where it lives, whether it's cloud telemetries, where we connect directly within the same cloud and within the same region, or your EDR logs or any other heavy telemetry, even AI telemetry, now we can give the AI access to all of the context of the organization, and we can scale AI reasoning across all of the data Got it. I want to, if you don't mind, Eli, I'm going to kind of pivot a little bit.
You guys are introducing, I guess maybe at Black Hat, or this came out before Black Hat, these detection skills. Detection skills is launching this Monday on Black Hat. Well, by the time people see this, it'll be- Exactly.
Yeah ... it'll be Tuesday already. So it's launched at Black Hat.
Yes. If you're watching this while you're in Vegas, you can go check out the Vega booth and get to see it firsthand. But what exactly is it?
So detection skills solves a fundamental problem in cyber defense and security operations. If you think about what does detection look like five years ago in a legacy SIEM, it was just a static detection rule that a detection engineer would author, and then it had no reasoning or real playbook as for what to do next. And the triage process, and escalation, and investigation process would be delegated into another team.
In order to really scale AI reasoning and to put AI in the work of the nirvana agentic cell that we all want, we need to be able to scale that reasoning. And that's why we are introducing detection skills. Detection skills is an open standard that puts the reasoning and the thought inside the detection itself, meaning that it allows cyber defense engineers to scale judgment and to scale the reasoning of what needs to happen after a detection fires.
As for what are the triage steps, what are the investigation steps, what are the steps to tune this detection so that you significantly reduce the time to detect and respond to actually leverage AI and do it at AI pace. That's why we're launching it also as an open standard, because we want all of the cyber defense community to use it together. Love it.
So, the world used to be very simple when it was open source or not. Now we have open source, we have open weights, we have open standards. What exactly do you mean by open standard?
It's a great question, Alan. So, it is very similar to Anthropic's MCP standard or- Okay ... agent skills standard, for example.
They have invented an open standard, meaning it's an open protocol that a lot of companies and players agreed to speak in that way, like an API. And we have came up with this standard together with design partners, like really big companies, Fortune 200, Fortune 50s, large financial institutions. And the reason we're publishing it as an open standard, and not just a closed standard, is, well, first of all, today, there is an open standard for detection engineering, but it didn't keep up with pace of AI.
It's called Sigma. Sigma was great before AI, but it's time for something that will leverage AI at scale and in a transparent, controllable, and auditable way. Those are the key things in order to really adopt AI at the security operations center.
So we designed this standard together with our partners and customers, and we released it as an open source together also with the skills that we use because that's important for the community to be able to use those skills together. And again, it's very similar to Anthropic's MCP, and it's built on Anthropic's Agent Skills open standard. I love it.
So I would imagine then what you're looking for other companies, not just the design partners you launched here with, but other cybersecurity companies, the whole industry, to kind of get behind this as the standard. Yeah, absolutely. We invite everyone to come build with us.
We will share all of Vega's skills. Our customers, they can share their skills. They can watch the community grow with that.
io. Okay, that's what I was going to ask next. Where can they get this?
Yeah. io. io, it's a nice domain, easy name.
And everything is there available for everyone to consume, review, leave comments. And hopefully together, we can compound the defenders with that ability. I love it.
I got one more question for you. Yeah. So by the time people see this, we're already at Black Hat, but I'm asking you this before Black Hat.
Yep. What do you think the big theme is? Don't say AI.
Of course, it's AI. But beyond digging deeper, go back a layer deeper. What do you think the big stories are?
In Black Hat? In Black Hat. Yeah.
I think people want transparency and controllability. They don't want a black box magic. They want to be able to be accountable for the AI.
They don't want just to delegate everything to the AI because we know it's not going to work, right? We know that AI makes mistakes. We know that there needs to be a human in the loop, and we know that we cannot just blame the AI if we got hacked.
That's not going to go easily. So I think transparency and controllability. Everything that was going on with the large language models, frontier labs.
People want to be in control of their own alpha. People want to be in control of their own destiny. They don't want to hand over that alpha, but also the accountability to someone else because that's our job as defenders, to be accountable.
And I think that's a great theme because everybody's going to talk about AI. But to really adopt AI, you want to be confident about its ability to execute well. I don't disagree.
io. People can go get that. The Vega website- Yes ...
is Vega what? io, and we also launched a very brand new website. It's beautiful.
I think it's the best website I've ever seen in cybersecurity, so I'm excited to get everyone's thoughts. There's going to be people that- I'm sure there are going to be some haters on both of them. It's an open standard, so a lot of- There's always haters.
Exactly. But we're welcoming the feedback because we want to build together. Yeah.
But yeah, it's going to be great. Fantastic. Eli, safe travels.
See you in Vegas. It's going to be hot there. Bring T-shirts, shorts.
It's hot. Yeah, I know. You know what the good news is, is they keep the air conditioning really low there, so inside it'll be nice.
Yeah. Anyway. I'm used to it from Tel Aviv, but thank you.
Thank you for having me on. Yeah. Well, no, Tel Aviv's not dry.
Tel Aviv's like where I live here in Florida. Humid. I know, man.
Vegas is a dry heat. You feel like a piece of meat. Yeah.
But anyway, safe travels. We'll see you there. Be well.
Thanks for coming here on Techstrong TV. Thank you, sir. Have a nice day.
Bye-bye. Thank you. Eli Rosen, co-founder, CTO of Vega, here on our Black Hat coverage.
If you're watching this in Vegas, go check them out. io. They got a beautiful new website.
We're going to take a break. You're watching Techstrong TV.