Cisco has officially unveiled its first open-weight security-focused large language model (LLM), Foundation-sec-8b, marking a major milestone in the company’s AI journey. Developed by the newly formed Cisco Foundation AI group, this model is purpose-built for cybersecurity—combining deep domain expertise with the flexibility and control enterprises demand in today’s evolving threat landscape.

A Foundation Model Built for Security—Not Adapted to It
Unlike general-purpose AI models that are later modified for security use cases, Foundation-sec-8b was designed from the ground up to understand the complex language, logic, and workflows of cybersecurity.
Built on the Llama 3.1 8B framework, Cisco’s model has been pre-trained on an extensive, proprietary dataset curated by its Foundation AI team. This dataset integrates:
- Vulnerability databases and threat behavior mappings (CVEs, CWEs, MITRE ATT&CK)
- Threat intelligence reports and red team playbooks
- Real-world incident summaries and post-mortems
- Security tool documentation across cloud, identity, and infrastructure domains
- Compliance and secure-coding references (NIST, OWASP, etc.)
This domain-specific training allows the model to perform with greater accuracy, fewer hallucinations, and faster response times compared with generalist LLMs.
“Foundation-sec-8b is a foundational step toward building AI-native security systems—tools that don’t just process data but truly understand the security domain,” said Jeetu Patel, Chief Product Officer at Cisco.
Compact Size, Outsized Performance
Despite being an 8-billion-parameter model, Foundation-sec-8b’s performance rivals models nearly ten times larger.
On cybersecurity benchmarks like CTI-MCQA and CTI-RCM, it surpasses Meta’s Llama 3.1 8B and even matches or exceeds the 70B variant—offering top-tier inference at a fraction of the computational cost.
| Benchmark | Foundation-sec-8b | Llama 3.1 8B | Llama 3.1 70B |
|---|---|---|---|
| CTI-MCQA | 67.39 | 64.14 | 68.23 |
| CTI-RCM | 75.26 | 66.43 | 72.66 |
Just as importantly, it maintains strong general-language performance (on MMLU), making it ideal for investigative narratives, chat workflows, and context-rich threat analysis.
Real-World Use Cases Across the Security Lifecycle
Foundation-sec-8b is open-weight and built for flexibility, enabling organizations to fine-tune or extend it with their own telemetry, rules, or threat intelligence. It can be deployed securely on-premises, in air-gapped environments, or within private cloud enclaves.
Key applications include:
- SOC Acceleration: Automate alert triage, summarize incidents, and assist investigations
- Proactive Defense: Simulate attacks, prioritize vulnerabilities, and model threats
- Engineering Enablement: Perform AI-assisted code reviews, validate configurations, and ensure compliance
- Custom Integration: Fine-tune the model to your organization’s unique detection logic and vocabulary
“We are very excited about the capabilities of an AI model that truly understands our domain and can scale across use cases,” said Omar Santos, Distinguished Engineer, Cisco Security & Trust Organization.
Open, Transparent, and Privacy-Conscious
Trust remains paramount in cybersecurity. That’s why Foundation-sec-8b is released as an open-weight model under a permissive license, giving organizations full control over deployment and data privacy.
Users can run it locally, adapt it to their environment, and ensure compliance without relying on external APIs or third-party inference services.
The model weights and tokenizer are now available for download on Hugging Face, with a technical paper detailing Cisco’s research and training methodology.
The Beginning of Cisco’s Foundation AI Era
Foundation-sec-8b is the first release from Cisco Foundation AI, a team dedicated to advancing AI infrastructure for security. It sets the stage for a new generation of AI-native cybersecurity systems, where intelligence is embedded at every layer of defense.
Future releases from the Foundation AI group will include:
- A reasoning model designed for explainable security analysis
- A benchmark suite tailored to real-world practitioner tasks
- New tools for fine-tuning, operationalizing, and embedding AI safely in security stacks
Cisco describes Foundation-sec-8b as “open, ready, and built to defend.”
It represents not just a technological leap, but a signal of how deeply AI will shape the future of cybersecurity.
Learn more:
Explore the model and its documentation on Cisco’s official Foundation AI page or download it directly from Hugging Face.