Breaking COGNNA raises $9.2 million to take its agentic SOC beyond the region • Nexus moves from discovery to response • Human Guardians remain on call 24/7 •
Company profile / Cybersecurity

COGNNA Is Teaching the Security Operations Center to Think Before It Pings

The Saudi cybersecurity company is betting that the next useful AI agent will not write an email. It will decide which of 10,000 security alerts deserves a human being.

By YesPress Editors9 min read

The modern security operations center has a peculiar productivity problem. Its instruments work. They work so eagerly that they can turn every odd login, strange process and misconfigured device into an alert. A large organization may collect thousands in a day. Most will be harmless. Each still asks for a sliver of human judgment, and those slivers become a queue large enough to hide the one signal that matters.

COGNNA was built around that queue. Founded in Riyadh in 2022 by chief executive Ibrahim Alshamrani and chief technology officer Ziyad Alshehri, the company sells software and managed services that discover assets, examine alerts, hunt for threats, investigate incidents and coordinate a response. Its central product, Nexus, is described as an agentic AI SOC platform. Its people are called Guardians. Together, they promise to return something more useful than another warning: a decision with context, an audit trail and, when appropriate, an action.

That positioning puts COGNNA in an increasingly busy part of cybersecurity. Global vendors sell XDR platforms, SIEM data lakes, automated playbooks and managed detection. COGNNA's argument is not that all those tools must go. The company says Nexus can connect to more than 300 products and begin producing value for a cloud-native customer in as little as 48 hours. The existing stack supplies telemetry; COGNNA tries to supply judgment.

Abstract network of geometric nodes, scanning arcs and a human oversight symbol
The orange dot has been acting suspiciously. The cream-colored Guardian would like a little context before waking the whole office.

The operating ideaFour verbs instead of forty tabs

Nexus reduces the security-operations lifecycle to four verbs: discover, detect, investigate and respond. Discovery maps assets, users, vulnerabilities and shadow IT. Detection adds context to raw signals, clusters related threats and processes alerts. Investigation combines hunting, artifact analysis, logs and post-incident forensics. Response brings endpoint containment, playbooks, recommendations and case management into the same path.

This is what “agentic” means in COGNNA's version of the term. Instead of using a model to summarize an analyst's work after the fact, software agents perform bounded pieces of the workflow: gathering evidence, connecting events, testing a hypothesis, recommending a next step and documenting why. The appeal is economic as much as technical. Entry-level triage is repetitive, around-the-clock and difficult to staff. Automating more of it can let senior analysts spend time on adversaries rather than inbox housekeeping.

“Our mission at COGNNA is to detect the undetectable and defeat the unpredictable.”Ibrahim Alshamrani, co-founder and CEO

The limit matters. A security platform that can isolate an endpoint or disable an account carries more consequence than a chatbot that mangles a memo. COGNNA's managed offering keeps human Guardians available around the clock. They monitor, hunt and support response while Nexus handles scale. The result is neither fully autonomous defense nor conventional outsourcing. It is a blended service in which software does more of the first pass and humans retain responsibility for escalations.

The customerFor teams that cannot hire their way out

COGNNA's likely buyer is easy to picture: a CISO with a lean team, a growing cloud estate, several security products and a regulator asking for proof. Public customer material names Saudi fintech Wadaie, HR and spend platform Jisr, SIFI and Tweeq. The company also describes a Riyadh hospital without naming it. These are organizations for which a breach is dangerous and an incomplete audit can be damaging even when no breach occurs.

Wadaie, which connects customers to deposit products at Saudi banks, needed to protect financial information while meeting Saudi Central Bank expectations. Jisr handles workforce and payroll data across thousands of businesses. The hospital had sensitive patient records, a small security staff and obligations spanning the National Cybersecurity Authority, the health ministry and CBAHI. In each case, security operations and compliance were not separate procurement exercises. They were one operational problem.

120K+Threats neutralized, company-reported
~2 minMean time to detect, company-reported
96%AI triage accuracy, company-reported

COGNNA says the hospital deployment cut false positives by 46 percent, detection time by 52 percent, response time by 64 percent and security-operations costs by 29 percent. The figures come from COGNNA's own anonymized case study, not an independent benchmark, but they reveal what the company believes customers will buy: less noise, faster action and fewer analyst hours spent proving that nothing happened.

The wedgeCompliance is not paperwork at the end

A global security vendor can localize a website. Localizing compliance is harder. Saudi organizations may need to map controls and evidence to NCA requirements, the Saudi Central Bank's SAMA framework and Capital Market Authority rules, while keeping data in the country. COGNNA makes that regional knowledge part of the product. It advertises local data residency, explainable AI reports and native mapping to Saudi frameworks alongside global standards such as PCI DSS, HIPAA and SOC 2.

This is the company's clearest difference from a long list of larger alternatives, including CrowdStrike, SentinelOne, Microsoft, Palo Alto Networks, Arctic Wolf and Rapid7. Those companies have broader footprints and deeper balance sheets. COGNNA has proximity: to local regulators, to regional buyers and to the specific evidence an auditor expects. Its early participation in the Saudi National Cybersecurity Authority's first accelerator program gave the founders a useful vantage point. KAUST's TAQADAM accelerator supplied another.

The familiar SOC

  • Tools produce separate queues
  • Analysts add context manually
  • Compliance evidence is assembled later
  • Capacity grows by adding people

COGNNA's pitch

  • Agents correlate before escalation
  • One loop connects hunt to response
  • Decisions remain explainable
  • Guardians add supervised 24/7 capacity

The advantage is also a constraint. Regional depth can win a Saudi fintech and still be hard to translate into a global category. COGNNA must prove that its agents generalize across messy customer environments, that integrations survive product updates and that explainability remains useful when an investigation becomes complicated. It must also show that an “agentic SOC” is more than a new label attached to automation security teams already use.

How it gets paidSoftware, service or the blend

COGNNA operates a B2B recurring-revenue model. A customer can buy Nexus as SaaS, use Smart MDR for managed detection and response, or engage broader managed SOC, threat-hunting, compromise-assessment and compliance services. That flexibility widens the market. A mature enterprise may want software that its own SOC operates. A midmarket company may want COGNNA to supply both the platform and the people.

The company is also building a channel around resellers, value-added distributors, referral partners, systems integrators and marketplaces. That is a conventional route for enterprise security, where a trusted local integrator can matter as much as a clever product demo. COGNNA's public material describes recurring subscription offerings for channel partners, but it does not publish prices. In practice, cost is likely to vary with data volume, endpoints, integrations, service level and how much operational responsibility the Guardians assume.

Funding has arrived in two disclosed steps. Impact46 led a $2.25 million seed round in November 2023, joined by Vision Ventures, Faith Capital and others. In December 2025, COGNNA announced a $9.2 million Series A led by Impact46 and co-led by BNVT Capital, with Vision Ventures and Tali Ventures participating. The combined $11.45 million is intended for product development, hiring, regional expansion and entry into markets beyond MENA. No public valuation or reliable revenue figure has been disclosed.

What the software knowsThreat hunting without the scavenger hunt

A SOC platform earns its place less through a polished home screen than through the evidence it can connect. COGNNA's product material points to threat intelligence, asset and vulnerability context, identity data, endpoint signals and cloud telemetry. Hunters can work with indicators of compromise and rules written in formats such as Sigma and YARA, then map behavior to the MITRE ATT&CK framework. Release 2.2.0, published in late 2024, expanded that rule support and added user discovery, richer alert detail and a marketplace for installing sensors.

Asset discovery supplies a less dramatic but equally important layer. Security teams cannot protect a server, cloud workload or employee account they do not know exists. Nexus is designed to maintain that inventory continuously, identify shadow IT and connect vulnerabilities to the assets on which they appear. That context helps turn a generic severity score into an operational priority. A flaw on an isolated test machine and the same flaw on an internet-facing payment system should not occupy the same place in the queue.

The platform's case-management and reporting functions complete the loop. An investigation can preserve the artifacts examined, the recommendation made and the response taken. Explainability is a practical requirement here, not a philosophical decoration. An analyst needs to review the machine's reasoning before containment; a manager needs to reconstruct an incident afterward; an auditor needs evidence that a control operated. COGNNA's compliance pitch works only if the same record can serve all three without being rewritten by hand.

People in the loopThe Guardians and the founders

Alshamrani arrived at the company with roughly 15 years in cybersecurity and information technology, according to COGNNA's public founder profile. His experience spans information-security management, risk assessment, digital forensics and ISO 27001 implementation - a résumé that helps explain why the product treats technical response and governance as adjacent work. Alshehri leads the engineering side as CTO. Together they have described COGNNA's culture through three less theatrical ideas: continuous learning, transparency and collaboration.

The hard partPermission is more valuable than prediction

Security AI is evaluated under an unforgiving asymmetry. Missing a genuine attack can be catastrophic. Acting too aggressively on harmless behavior can interrupt a business. A false positive that reaches a dashboard is irritating; one that automatically suspends the chief financial officer during a closing is memorable. COGNNA therefore has to tune not only what its agents can do but what they may do at each confidence level. Recommendation, approval and automatic execution are three different products even when they share the same model.

Then there is the competitive clock. Microsoft, Google, CrowdStrike, Palo Alto Networks and other vendors can place AI assistance beside data they already collect. Managed providers can add similar language to analyst services. COGNNA cannot win merely by being early to the phrase “agentic SOC.” Its defensible assets are more specific: regional regulatory knowledge, customer workflows encoded into the product, a local service operation and accumulated feedback about which machine decisions experts accept. Each gets stronger through use, but none is automatic.

The market testCan judgment become a product?

Cybersecurity has spent years centralizing data and automating response. Generative and agentic AI now make it possible to automate more of the investigation between those points. Every major platform vendor sees the opening. The market question is not whether AI will appear in the SOC; it already has. The question is which systems earn permission to act, and which can show their work when a regulator, customer or tired analyst asks why.

COGNNA fits between the platform and the service provider. It owns software, but it also employs the humans who watch that software operate. It begins in a region where sovereignty and compliance can decide a sale, then aims outward with a workflow that any overloaded security team will recognize. The founders' combined product is not merely an algorithm. It is a particular division of labor between machine speed and human accountability.

There is something refreshingly plain beneath the agentic vocabulary. Alerts are abundant. Experienced attention is scarce. COGNNA's business depends on using the first to conserve the second. If Nexus can reliably decide what deserves a person, the company will have made the least glamorous part of cybersecurity - sorting the queue - into its most valuable feature.