Foundation-sec-8b-reasoning: World's First Security Reasoning Model


Today marks another significant step forward in Cisco’s commitment to AI-powered cybersecurity. Following the recent release of Foundation-sec-8b, our foundational cybersecurity model, the Cisco Foundation AI team is excited to announce the private preview of Llama-3.1-FoundationAI-SecurityLLM-8B-Reasoning (Foundation-sec-8b-reasoning), an 8-billion parameter reasoning Large Language Model (LLM) purpose-built to bring enhanced analytical capabilities to complex security workflows.

Foundation-sec-8b-reasoning enables the kind of sophisticated analysis and decision-making required in security workflows. This model outperforms state-of-the-art (SOA) models and will be made publicly available later this summer.

In cybersecurity, effective analysis demands intricate, multi-layered reasoning. This includes deciphering vulnerabilities, tracing attack pathways, assessing defenses, understanding organizational security posturing, and gauging risk with precision. Traditional security tools often rely on rigid rulesets that lack the adaptive reasoning needed to identify and dissect emerging threats. While generic reasoning LLMs exist, their capacity to navigate multifaceted security problems remains limited.

Reasoning models are now more accessible than ever, in part due to advancements demonstrated by models like DeepSeek-R1. Security applications, however, necessitate robust, domain-specific reasoning to weave together scattered data points from logs, code, and threat intelligence. A security reasoning model would be optimal for use by cybersecurity professionals, IT security teams, security researchers, and developers building security features into their applications who need assistance with complex security reasoning.

This makes advanced reasoning an essential building block, not just an optional feature, for security-tuned LLMs to effectively understand complex security problems, apply logical thinking, and navigate multi-step reasoning within the cybersecurity domain.

According to Cisco’s 2025 Cybersecurity Readiness Index, 86% of business leaders with cybersecurity responsibilities worldwide have experienced AI-related security incidents in the past 12 months, highlighting the urgency for advanced, AI-driven security solutions. Foundation AI, a team of leading AI and security experts, is dedicated to meeting this need by developing cutting edge technology to address the fundamental security issues of the AI era with novel open-weight tools.

Foundation-sec-8b-reasoning is fine-tuned from foundation-sec-8b. Foundation-sec-8b, built in house using the Llama 3.1 8B framework and Foundation AI’s first release, is a general-purpose foundation model retrofitted for security to enhance reasoning capabilities for security applications. The model is designed to serve as a tool for security tasks that require logical reasoning, such as threat modeling, attack vector analysis, risk assessment, and security architecture evaluation.

Foundation-sec-8b-reasoning can be used directly for various cybersecurity reasoning tasks, including:

  • System and Configuration Analysis: Evaluate system settings and configurations to identify vulnerabilities and improve security posture.
  • Adversary Behavior Mapping: Correlate threat intelligence data with attacker tactics to predict and understand adversary behavior.
  • Threat Detection and Analysis: Analyze logs and traffic to identify malicious patterns and enhance threat-hunting accuracy.
  • Access and Privilege Management: Assess permissions and roles to uncover over-privileged accounts and mitigate insider threats.
  • Context Enrichment and Investigation: Provide contextual insights to streamline investigations and support faster incident response.

To explore how Foundation-sec-8b-reasoning can be applied across real-world security workflows, check out the use case cookbook on our public Github repository. These hands-on notebooks offer practical examples to help teams get started, inspire new applications, and accelerate development on top of the model.

Like Foundation-sec-8b, Foundation-sec-8b-reasoning will be released as an open-weight model. This commitment to openness empowers the cybersecurity community to:

  • Foster Innovation: Encourage collaboration among security experts to develop cutting-edge solutions.
  • Customize and Adapt: Tailor the model to specific needs, ensuring it aligns perfectly with unique security challenges.
  • Accelerate Deployment: Provide a powerful building block for security teams to accelerate defense, reduce fatigue, and gain clarity in complex threat environments.
  • Control Deployment: Run the model on-prem, in air-gapped environments, or within secure cloud enclaves.
  • Compliance Confidence: Keep sensitive data local; no forced inference APIs or third-party sharing.

Foundation-sec-8b-reasoning enables organizations to build AI-driven security tools with strong reasoning capabilities that can be deployed locally, reducing dependency on cloud-based AI services while maintaining high performance on security reasoning tasks.

Our specialized cybersecurity reasoning model shows that small open-weight models can outperform other general-purpose models that are orders of magnitude larger. Our reasoning model is able to exploit test-time computation to answer security questions at higher accuracy rates than larger models without reasoning capabilities.

We argue that open weight is becoming the best path forward for building powerful, secure, and future-proof cybersecurity AI, which is why we will be publicly releasing our security reasoning model later this summer.

Foundation-sec-8b-reasoning is the next step in building purpose-built AI-native security systems; tools that don’t just process data but truly understand the security domain. The upcoming public release of this cybersecurity reasoning model underscores Cisco’s dedication to providing essential infrastructure that cybersecurity teams can immediately leverage.

Over the coming months, Cisco Foundation AI will be releasing:

  • An open-weight version of Foundation-sec-8b-reasoning, a cybersecurity reasoning model that brings explainability and deeper analysis to complex security workflows.
  • Foundation-sec-8b-reasoning as part of the Nvidia NIM model factory to streamline deploying and scaling models.
  • A new benchmark suite designed to evaluate AI models on real-world, practitioner-defined security tasks.
  • Additional tools and components that help teams fine-tune, operationalize, and embed AI safety and effectively into their security stacks.

If you are excited about partnering with us to advance the future of AI-powered cybersecurity, we invite you to request early access to Foundation-sec-8b-reasoning.

For more information on the Foundation AI team, check out our website. And to explore the foundation model we already released, Foundation-sec-8b is available for download on Hugging Face.


We’d love to hear what you think! Ask a question and stay connected with Cisco Security on social media.

Cisco Security Social Media

LinkedIn
Facebook
Instagram
X

Share:





Source link

Leave a Comment