Human-AI cooperation in cyber defence groups: Ex-CIA director’s Andesite snaps$ 23M from General Catalyst

Despite soaring cybersecurity spending, security teams face mounting challenges. Analysts are overwhelmed with alerts as they attempt to interpret, prioritise, and act on countless indicators while navigating disconnected tools and portals. SOC leaders struggle to demonstrate a return on rising investments, while AI-powered threats leave CISOs questioning their teams’ preparedness. Andesite aims to address these challenges.

Virginia-based Andesite AI, which enhances cybersecurity operations through human-AI collaboration, has secured an additional $23M in funding from and Red Cell Partners. Following its early success in meeting technology, customer acquisition, and revenue targets, its total funding now stands at $38.25 million.

Andesite will use the new funding to accelerate product development and scale its go-to-market initiatives.

Andesite: a solution to overburdened cybersecurity teams

Founded in April 2024 by , a former CIA senior executive who served as Director of CIA’s Special Activities Center (SAC), and (who is also  Chairman of Red Cell Partners), Andesite AI tackles the core challenges facing cybersecurity teams: data overload, sophisticated threats, skilled analyst shortages, and rapid threat evolution.

Brian Carbaugh, co-founder and CEO of Andesite, told TFN: “Andesite was founded to directly address a market need – automation in the Security Operations Center (SOC) has failed. Security analysts today are forced to toggle between applications, drowning in threat intel feeds and alerts while trying to navigate more than 100 different security tools. This fragmentation of data and tools has led to widespread analyst burnout and operational inefficiency, with valuable team members spending most of their time on menial tasks instead of meaningful threat hunting.”

Speaking specifically, Andesite AI has developed an advanced AI-driven security analytics platform. The system analyses decentralised data sets at scale, helping cyber defenders and analysts quickly identify threats and vulnerabilities, optimise resource allocation, improve threat response and remediation, and reduce cybersecurity operational costs.

Carbaugh said: “At Andesite, we recognise that an organisation’s competitive advantage lies in unleashing the full potential of its people. Security analysts are irreplaceable: their intuitive pattern recognition, creative thinking, and ability to turn insights into action are crucial. Our promise to them is clear: Your expertise will be amplified. You will be focused on what matters. Your potential will be unleashed.”

Inside Andesite’s bionic SOC platform

“There is a large volume of data within emails, PDFs, social media, and other media that present near-real time threat information. Andesite reduces the time to assess enterprise risk relative to this changing information landscape from hours or days to minutes.  Imagine taking a newly released security bulletin, extracting all TTPs, and searching for any evidence across your entire enterprise in minutes.  This is just not possible without Andesite, and early adopters have praised this functionality for its ability to compress investigative timelines when faced with breaking threat intelligence dramatically,” noted Carbaugh.

Andesite’s bionic SOC marks a breakthrough in human-AI collaboration for cybersecurity. It elevates human insights and empowers SOC teams to move beyond reactive alert triage toward proactive threat hunting. By unifying data silos, platforms, and tools across a SOC’s ecosystem, Andesite provides analysts with the context and visibility they need for informed decisions. This speeds up investigations and transforms security outcomes, helping teams better protect their organisations’ assets, people, and customers.

The platform’s key features include context-aware AI that consolidates scattered data across organisational silos to deliver actionable insights; evidentiary AI that provides complete visibility and auditability of machine-assisted decisions—no black boxes; and adaptive automation that streamlines workflows from threat intelligence to response, optimising security operations.

The platform’s ‘Safe AI architecture’ is a robust system that ensures sensitive data remains within predefined boundaries and isn’t used to train external AI models. Additionally, built-in enterprise-ready compliance — including SOC2 Type I and NIST AI Risk Management Framework — enables seamless deployment in regulated environments, providing high data security and privacy.

William MacMillan, Chief Product Officer, former CIA CISO and former Senior Vice President of Infosec at Salesforce, emphasised: “Andesite’s technology frees analysts from toggling between tools and learning countless query languages, so they can focus on hunting down threat actors. Our vision for the SOC is a symbiotic relationship between humans and AI that elevates analysts of every skill level. For CISOs, this means not just better outcomes faster, but the ability to buy down more risk with the team they already have.”

Andesite’s cross-industry impact and future plans

As Carbaugh puts it, “The future of cybersecurity isn’t just about better technology, but about fundamentally reimagining how humans and machines work together to defend against threats. Our goal is to unlock data, unleash teams, and transform outcomes so enterprises can gain an unfair advantage against those that seek to do them harm.”

Andesite’s innovative approach has gained traction with partners in the national security, financial services, and healthcare sectors. The company plans to use the new funding to accelerate product development and scale its go-to-market initiatives. It will focus on expanding its reach across industries and enhancing its solutions to meet the evolving needs of the cybersecurity landscape.

Chief Technology Officer concluded: “We bring insights, scattered across data islands and buried in unstructured PDFs and wikis, to the edge of action. Andesite keeps the human in control, but upgraded — delivering the right data they need, when they need it, in a human-actionable format.”

DNS checker

Leave a Comment