Briefing
01Founded 202402$38m disclosed funding03Browser-native SOC automation04Google Cloud Marketplace
Company profile / Cybersecurity

The Security Analyst in the Next Tab

Legion Security wants to learn a SOC's habits before it takes over its chores. A browser extension watches the work, draws the map, and asks for the keys only when the team is ready.

At a security operations center, the most valuable instruction may be the one nobody has written down. An alert arrives. An experienced analyst opens one console, ignores a misleading field, checks a second tool, remembers what happened last Tuesday, and decides whether the machine is crying wolf. The ticket records the verdict. The route to it often disappears.

The short version
  • Legion Security observes analysts through a browser extension and turns their investigations into visible workflows.
  • Teams can let the software learn, assist under supervision, then automate approved cases.
  • Its public customer story says Virgin Money cut an alert backlog from roughly 50,000 to 20,000 in under two months.

Legion Security built a business around that missing route. Its software sits in the browser where analysts already use their security tools. It observes how they move through an investigation, gathers context from past cases and playbooks, and draws a process that can be edited, tested and eventually run by an AI agent. The company sells the platform to enterprise security teams. The proposition is specific: make the local knowledge of a SOC repeatable without asking that SOC to abandon its familiar tools.

The pile of alerts

Virgin Money supplies the kind of number that makes this story tangible. According to a case study published by Legion, the bank had a backlog of about 50,000 security alerts. Its security organization, roughly 200 people in Legion's account, could not simply wish away the queue. In less than two months after deploying Legion, the company says that backlog fell by more than 60%, to around 20,000. These are customer and vendor reported figures, not a controlled comparison, but the scale of the queue explains why even a modest improvement in routine work would matter.

The first obstacle was not a lack of automation in the abstract. Security teams have had scripts and orchestration tools for years. The problem was the labor needed to encode an actual team's process across a tangle of commercial products, old internal systems and exceptional cases. An impressive demo can stumble at its first unfamiliar console. Legion's wager is that the browser, already the common doorway to much of this work, can cut through some of that integration work.

The map hiding in the tabs

The founding trio knew the territory. Ely Abramovitch, Legion's CEO, and Michael Gladishev, its VP of R&D, held senior roles around Microsoft Sentinel; CTO Eyal Fisher brought an AI research background from Cambridge. They founded Legion in 2024. Accel's account of its investment describes an early conversation with Abramovitch in Tel Aviv in 2023 and mentions an unexpected earlier chapter: he once worked as a jazz musician in New York. The connection is more useful than cute. A good SOC has a score, but its best people also know when to improvise.

Legion Security co-founders Michael Gladishev, Eyal Fisher and Ely Abramovitch standing together
Founders From left: Michael Gladishev, Eyal Fisher and Ely Abramovitch. Three people betting that the most useful security manual has been walking around the office all along.

Legion starts in Learning Mode. Its extension watches browser-based investigations and turns repeated actions, choices and pivots into a process graph. A manager can see which steps recur, where analysts branch, and where an old runbook is more aspiration than practice. This is the product's unusual move. Many tools ask a team to write a playbook first. Legion attempts to infer one from the work itself, then gives the team a chance to correct it.

Legion Security process graph showing steps in an email investigation across security tools
Inside the product The investigation is no longer a private tour of browser tabs. Here, Legion makes the route visible as a process graph, with checks, branches and a triage point.

The browser strategy gives Legion a sharper position than a generic chatbot draped over a SIEM. If an analyst can reach a tool in a Chromium browser, the platform says it can observe and work there without an API connector just to get started. That can be valuable for an enterprise with legacy tools. It also defines a boundary: browser access does not magically make every application, credential policy or messy exception simple. Security leaders still have to decide what the extension may see, what the agent may touch, and how to review its conclusions.

Permission is the product

Legion calls its next step Guided Mode. The software executes a workflow in the analyst's browser while a person watches, corrects and approves. Once a team is comfortable with particular cases, Autonomous Mode can take on approved investigations and call for human input where needed. This progression is less theatrical than a promise of instant autonomy. It is also closer to how a cautious security department actually buys trust.

01 / WATCH

Learn

Observe real investigations and map the team's decisions.

02 / ASSIST

Guide

Run steps in the browser with an analyst supervising.

03 / ACT

Automate

Handle approved cases and escalate sensitive calls.

That visibility helped change minds at Virgin Money. Neil Robinson, the bank's security leader, describes the workflow diagram as a way to see what the system is doing. In Legion's case study, he says initial concern about replacement gave way to a view of the tool as augmentation. His point is practical, not sentimental: a bank has little use for an opaque colleague who closes tickets quickly and cannot explain why.

“Legion gives you this really nice workflow diagram so you can see exactly what it's doing.”Neil Robinson / Virgin Money

Legion's trust page says customers control what the extension records, can mask sensitive data, and can see the actions an agent takes. Its newer DragonClaw layer brings the accumulated knowledge into a conversational interface that can route tasks to agents; the company says response actions require explicit permissions and run within approved tool boundaries. AI Investigator, introduced in March 2026, addresses cases that refuse to fit a fixed decision tree. These additions widen the product beyond routine alert triage, but they also increase the importance of those controls.

The economics of doing less by hand

Legion's customers are security teams with enough alerts, tools and institutional memory to make the learning exercise worthwhile. Public examples include Virgin Money, WELL Health Technologies, IQ-EQ and the University of Tulsa. The company reports that WELL cut investigation times by 81% in common use cases; it says Tulsa halved investigation time. Those results may differ by alert type, baseline and deployment. The product's strongest fit is a team that already has repeatable work and experienced analysts whose choices are worth studying.

The alternative is familiar: hire more analysts, write more rules, maintain more SOAR playbooks, or buy another AI SOC product. Legion's distinction is the source of its instructions. It tries to learn the customer's own process from observation, then offers a staged path from assistance to automation. That approach cannot rescue a process whose judgments are inconsistent or poorly supervised. The organization still has to choose good examples, check the map, define escalation rules and measure whether the resulting work is correct. The reader can copy that discipline even without buying the software: record a frequent investigation, compare how skilled analysts actually handle it, make the decisions visible, and automate only the stable parts.

Its business model is enterprise SaaS, sold through demos and contracts; public pricing is unavailable. An $8 million seed round in 2024 and a $30 million Series A in July 2025 put disclosed funding at $38 million. The Series A was led by Coatue, with Accel and Picture Capital participating. In 2026, a Google Cloud Marketplace listing gave buyers another procurement path, while an Optiv partnership added an enterprise channel. Google also supplies cloud infrastructure and Gemini models used in Legion's platform.

There is an irony in the name. A legion suggests a crowd. The product begins with one analyst, one alert, and a sequence of small choices that may never have made it into the manual. If Legion succeeds, the clever part will be less the number of agents it can summon than the care with which it learned what the first one ought to do.