Vega's cyber defense platform returns 67% of analysts' time with Claude
Vega, an agentic cyber defense platform used by Fortune 200 companies, global banks and healthcare providers, built an agentic detection-triage-investigation-optimization loop that runs Claude directly on security data where it lives, avoiding costly SIEM ingestion, delivered via Amazon Bedrock including an EU-resident deployment in Frankfurt for GDPR compliance. Across production deployments, customers reclaim roughly 67% of analyst time, complete investigations up to 44 times faster at 82% lower cost than legacy SIEMs, and one Fortune 500 insurer cut mean time to triage from 25 minutes to under 3 minutes.
Overview
Vega, an agentic cyber defense platform used by Fortune 200 companies, global banks and healthcare providers, built an agentic detection-triage-investigation-optimization loop that runs Claude directly on security data where it lives, avoiding costly SIEM ingestion, delivered via Amazon Bedrock including an EU-resident deployment in Frankfurt for GDPR compliance. Across production deployments, customers reclaim roughly 67% of analyst time, complete investigations up to 44 times faster at 82% lower cost than legacy SIEMs, and one Fortune 500 insurer cut mean time to triage from 25 minutes to under 3 minutes.
This entry has 14 published fields tied to exact passages in an immutable source capture.
Inspect the highlighted sourceThe challenge
Most large enterprises have security data spread across dozens of tools and cloud environments, but ingesting everything into a SIEM is often too complex and cost-prohibitive at enterprise scale, so security teams typically ingest only the fraction they can afford and everything outside it becomes a blind spot. For one top-four global bank, ingesting visibility into Amazon VPC Flow Logs, AWS CloudTrail, and Microsoft 365 telemetry into a legacy SIEM would have cost an additional $6 million.
The solution
Vega runs an agentic cyber defense loop of detection, triage, investigation, and optimization directly on security data where it lives, without ingestion or centralization, using Claude as the reasoning engine. Vega built on Anthropic's Agent Skills format to create detection skills, an open standard letting cyber defense engineers codify their triage/investigate/optimize judgment for every alert, with engineers signing off on every change. Each pipeline layer is matched to the Claude model tier that fits it, with the deepest reasoning reserved for confirmed alerts and lighter/faster tiers handling high-volume log analysis and summarization. Inference runs through Amazon Bedrock with zero data retention, no training on customer data, and VPC endpoints, including a dedicated EU control plane in Frankfurt for GDPR data-residency requirements.
Reported business value
Across production deployments, customers reclaim roughly 67% of analyst time, complete investigations up to 44 times faster, and pay up to 82% less for data than legacy SIEM ingestion. One Fortune 500 insurer cut mean time to triage from 25 minutes to under 3, and a top-four global bank gained the $6 million worth of telemetry it previously couldn't afford. The platform completes a scan across more than 1 billion CloudTrail logs spanning 17 AWS regions in 41 seconds, against a 30-minute manual baseline.
Sources
Open any source and check the claim yourself — that is the point of the register.
This record was researched and written with AI assistance, and its claims were checked against the sources above. (EU AI Act art. 50 transparency notice.)
Other cybersecurity entries in the register.
CyberArk combines Apache Iceberg and Amazon Bedrock AI agents to cut support case resolution time up to 95%
CyberArk redesigned its technical support pipeline using AWS Fargate, PyIceberg and Amazon Bedrock (Claude 3.7 Sonnet) to auto-generate grok patterns for parsing diverse vendor log formats into Iceberg tables, and built autonomous AI agents that query Athena and CyberArk's knowledge base to perform root-cause analysis from natural-language questions. The system cut case resolution time by up to 95% (complex cases from up to 15 days to 2-4 hours), let engineers handle up to 4x more cases per day (from 2-3 to 8-12), and made logs queryable within minutes instead of hours or days.
Cyera scales agentic AI across 1,500 employees with Claude Enterprise
Cyera, an AI data security platform, rolled out Claude Cowork company-wide to all 1,500 employees in 17 days, connecting it to 40 tools including Slack, Salesforce, Asana, Google Drive and Notion, plus a governed Snowflake semantic layer of 40 documented tables built by its data engineering team. Weekly active usage of Claude reached 88% across the company. A scheduled task now triages Cyera's internal Ask Claude Slack channel, cutting daily triage from five-to-six hours to about 30 minutes, and the legal team launched a Cowork plugin with 20 playbooks that pre-reviews inbound vendor NDAs against Cyera's negotiating positions.
Barracuda Networks Protects With AI
Barracuda Networks unified customer and product telemetry data using Databricks and AI to power BarracudaONE, an AI-powered platform delivering real-time threat detection and automated response by combining signals across attack vectors, securing hundreds of thousands of businesses worldwide.
WithSecure Built Luminen, an AI Cybersecurity Assistant, on Amazon Bedrock
Cybersecurity company WithSecure built Luminen, a generative AI assistant on Amazon Bedrock, to help organizations detect and respond to security events faster, minimizing damage and reducing downtime. WithSecure provides cybersecurity solutions for mid-market companies, prioritizing privacy, data sovereignty, and regulatory compliance in the European Union. Luminen integrates with WithSecure Elements and includes a Security Awareness Assistant that analyzes complex data tables to provide a 7-day security status overview, and an Investigation Assistant that analyzes technical data on identified security issues to build a narrative. Development began in December 2023, a public beta released in May 2024, and Luminen launched in September 2024. WithSecure also uses Amazon Neptune to build knowledge graphs storing relationships between security events.
Was this helpful?
Your feedback helps us improve our use case database