> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# VisionHeight Wants to Give AI SOCs the Threat Data They're Missing
- URL: https://www.cybrsecmedia.com/visionheight-wants-to-give-ai-socs-the-threat-data-theyre-missing/
- Published: 2026-09-01T13:07:24.000Z
- Updated: 2026-09-01T18:47:36.000Z
- Description: CYBR.SEC.CON LaunchPad finalist VisionHeight is building a pre-attack intelligence layer designed to give AI-driven SOCs the external threat data they need to move from reactive detection to proactive defense.
- Author: Bill Brenner
- Tags: LaunchPad, CYBR.SEC.CON, AI SOC, Article

Five cybersecurity startups. A panel of CISOs, investors, marketing and revenue leaders. And a chance to prove that what they've built can solve a problem security practitioners actually care about.

That's the idea behind **LaunchPad**, the startup competition making its debut at CYBR.SEC.CON 2026 in Houston Sept. 15-16.

**Full LaunchPad coverage:**

[CYBR.SEC.CON LaunchPad: 5 Cybersecurity Startups to WatchFive early-stage cybersecurity companies will pitch before CISOs, investors, marketing and revenue leaders at the CYBR.SEC.CON 2026 LaunchPad competition in Houston.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-af757ca5-ed69-4929-b792-88454d1b70d2.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/FINALISTS-63f4d77c-9907-4093-8a63-fc602d0d6df7.png)](https://www.cybrsecmedia.com/cybr-sec-con-launchpad-puts-five-cybersecurity-startups-to-the-test/)

**Full CYBR.SEC.CON coverage:**

[CYBR.SEC.CON 2026: News, Speakers, Agenda & CoverageFollow CYBR.SEC.CON 2026 in Houston with the latest news, speakers, keynotes, agenda, cybersecurity tracks, AI.SEC.CON highlights, interviews and event coverage.![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/icon/CYBR.SEC.Media-Logo-copy-058de458-97b5-440c-928d-9138b99ca566.jpg)CYBR.SEC.MediaBill Brenner![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/thumbnail/42601a79-4e56-4e1b-8342-c02f537cefcd-6ee5ae04-1d34-4644-90a5-087fab06cab7.png)](https://www.cybrsecmedia.com/cybr-sec-con-2026-news-speakers-agenda-and-coverage/)

As we outlined when we introduced the five finalists last week, LaunchPad is designed to give promising early-stage cybersecurity companies something they don't always get: direct exposure to the people who buy, use, evaluate, fund and help bring security products to market.

The five finalists will pitch their companies during CYBR.SEC.CON, where they'll be evaluated on the problem they're solving, the strength of the technology, market opportunity, differentiation and their ability to turn an idea into a sustainable cybersecurity business.

But a pitch can only tell you so much.

So ahead of CYBR.SEC.CON, CYBR.SEC.Media is profiling each of the five LaunchPad finalists individually. We're asking the founders what problem pushed them to build their companies, who they're building for, what separates their approach from what's already on the market and what success looks like from the perspective of the security practitioner.

Next up is **VisionHeight**, and the problem CEO Guy Amir wants to solve sits at the intersection of two of the biggest issues facing security operations: too much data inside the organization and not enough useful intelligence about what's happening outside it.

Modern SOCs aren't exactly starved for telemetry. SIEMs, EDR platforms, identity systems, firewalls and other security technologies generate enormous amounts of it. But Amir argues that internal visibility tells only part of the story.

Security teams — and increasingly the AI agents working alongside them — also need context about the external threat landscape and the infrastructure adversaries are preparing to use against them.

That's where VisionHeight sees its opportunity.

The company describes itself as fundamentally a data company, using passive telemetry and multiple intelligence sources to create a consolidated view of adversary infrastructure. The idea is to feed that intelligence into SIEMs, security automation, firewalls, identity systems and AI-driven security workflows so defenders can identify potentially malicious infrastructure earlier and make better decisions about it.

VisionHeight calls this a move toward "pre-attack" intelligence: identifying adversary infrastructure during its build-out rather than waiting until an attack is underway. The company says its platform is designed to predict malicious infrastructure, explain why it considers that infrastructure risky and then allow those decisions to be enforced across the security stack.

For Amir, that external context becomes particularly important as organizations put more trust in AI-driven SOC automation. An AI agent may be able to reason quickly, but its answer is only as useful as the information available to it.

Here's our Q&A with VisionHeight CEO Guy Amir.

[Subscribe to the CYBR.SEC.Media newsletter](#/portal/signup/free)

## What problem did you see in the market that convinced you this company needed to exist?

**Guy Amir:** The modern SOC has a data problem.

Organizations using SIEM platforms such as Splunk, Microsoft Sentinel and emerging agentic-SOC technologies have deep visibility into what is happening inside their environments. What they lack is visibility into what is happening outside their organizations across the broader threat landscape.

As AI agents become more common in security operations, those blind spots become even more problematic. Agents can only reason effectively when they have the right data. Without external visibility, organizations cannot become truly proactive.

VisionHeight was created to close that data gap and provide the intelligence needed to make preemptive cybersecurity a reality rather than an aspiration.

## Who is the ideal customer for your solution?

**Guy Amir:** Our initial focus is on large enterprises with mature security operations centers and established SIEM deployments.

Organizations in critical infrastructure, financial services, healthcare and other large enterprises all face similar challenges: overwhelming alert volumes, excessive false positives and difficulty automating security operations effectively.

We are particularly focused on organizations using Splunk and Microsoft security technologies because those environments often experience the greatest need for additional external context and intelligence.

## What makes your approach fundamentally different from other security vendors?

**Guy Amir:** Most companies today are focused on building automation layers around existing AI models. We started with a different premise: the data itself.

VisionHeight is fundamentally a data company. We built unique passive-telemetry capabilities that provide visibility into the global threat landscape and the infrastructure adversaries use to conduct attacks. On top of that, we have developed and integrated multiple intelligence sources into a unified platform.

The result is a single source of truth that can power security operations, automation, SIEM platforms, firewalls, identity systems and agentic-security workflows from one consolidated intelligence layer.

## Can you share a customer story that validates your approach?

**Guy Amir:** One of our early customers was an FTSE 100 Energy Giant with approximately 30,000 employees.

The company had deployed Microsoft Copilot for Security within its security operations environment. However, analysts were seeing significant escalation rates because the AI lacked sufficient data to answer many questions confidently.

After integrating VisionHeight's intelligence capabilities, those escalations dropped dramatically. Analysts were able to spend more time on meaningful investigations and less time chasing false positives.

The organization also connected our intelligence to its firewall infrastructure, reducing unnecessary data flowing into the SIEM and lowering associated operating costs. It demonstrated the value of providing AI systems with richer context and better intelligence from the start.

## What is the biggest misconception buyers have about the problem you're solving?

**Guy Amir:** Many buyers assume that major security vendors will eventually solve this problem themselves.

Customers often expect providers such as Microsoft, Splunk, CrowdStrike, Palo Alto Networks or Google to deliver all of the external intelligence their platforms need. In reality, those tools often depend on organizations bringing in additional data sources.

The challenge has existed for more than a decade, and it remains unresolved. Organizations increasingly recognize that solving the external-data problem requires a dedicated approach rather than waiting for platform vendors to address it on their own.

## What has been the hardest challenge in building the company?

**Guy Amir:** One of our biggest challenges has been delivering value quickly and seamlessly.

Early on, we solved an important problem for SOC analysts by eliminating the need to jump across numerous browser tabs and intelligence sources while investigating threats. The next challenge has been creating a deployment experience that demonstrates value almost immediately.

We continue to focus on reducing implementation friction and helping customers see meaningful results as quickly as possible after deployment.

## If we were having this conversation a year from now, what milestone would tell you the company is succeeding?

**Guy Amir:** For me, the milestone is simple: 25 meaningful enterprise customers.

If we reach that goal, it means we successfully solved many of the other challenges involved in building the business. Strong customer adoption is the clearest indicator that the market understands the value of what we are delivering and that our approach is working.

## Why is now the right time for this company and solution to exist?

**Guy Amir:** AI has dramatically accelerated the speed of cyberattacks.

The window between establishing attack infrastructure and launching attacks has shrunk from days to hours and, in some cases, even minutes. Organizations can no longer rely exclusively on traditional detection-and-response approaches.

To become proactive, security teams need better intelligence and greater visibility into threats before they reach the organization. As agentic systems become more common, the quality of the underlying data becomes even more important. Without the right data, automation and AI will ultimately fail to deliver on their promise.

## What does success look like for the security practitioner using your product every day?

**Guy Amir:** Success means eliminating friction from the investigative process.

Instead of opening dozens of browser tabs and hunting through multiple intelligence sources for answers, analysts should be able to get the information they need in one place and move on to the next task.

The goal is to create repeated moments throughout the day where analysts quickly find answers, resolve questions and avoid unnecessary investigation effort. That efficiency allows them to focus on higher-value work and become significantly more productive.

[ ![HOU.SEC.CON CTA](https://s3.us-east-1.amazonaws.com/assets.cybersecmedia.com/HSC+CTA.jpg) ](https://houstonseccon.com/?ref=cybrsecmedia.com)