Zaitsev is joining Gur Talpaz and Tayler Sipperly, two former CrowdStrike corporate-development executives who later founded early-stage investor Brightmind. Axios says Cognition expects to lead or co-lead seed and Series A rounds, investing in only three or four companies a year, with average checks of $6 million at seed and $15 million at Series A.
No other outlet had independently reported the timing of Zaitsev’s departure or Cognition’s fundraising target as of August 20. CrowdStrike’s own executive biography, which remained indexed recently, describes Zaitsev as the company’s Global CTO and says he was promoted to that role in 2023. CrowdStrike has not publicly identified a successor in the reporting available so far.
CrowdStrike’s CTO is backing a platform bet, not a point-tool boom
Cognition’s stated goal, according to Axios, is to find the rare technical team capable of building the next broad cybersecurity platform for an AI-driven enterprise. That is a consequential distinction. Security markets are full of startups that identify a narrow control gap—prompt filtering, model scanning, AI inventory, data-loss prevention for chatbots, or suspicious-agent detection—but a platform claim means the founders expect a company to own several parts of the decision and enforcement chain.
For enterprise customers, an AI agent is rarely a standalone model. It is usually a model connected to Microsoft 365, Teams, SharePoint, Active Directory or Entra ID, endpoints, code repositories, ticketing systems, SaaS applications, cloud APIs, and internal knowledge bases. The technical risk is not confined to whether the model returns an unsafe answer. The risk is whether an agent can read an untrusted document, accept a poisoned instruction, invoke a privileged connector, and make a change before a human understands what happened.
That is why the most credible AI-security opportunities are likely to sit close to identity and runtime enforcement rather than in a separate dashboard that merely tells a security team an agent exists. A useful product will have to answer practical questions: Which non-human identity authorized an action? What tool did it call? What data did it access? Which policy allowed it? Can the organization revoke the permission immediately and reconstruct the sequence afterward?
Cognition’s investment thesis tracks that reality, but it should not be confused with proof that a single new vendor will solve it. The market is still defining the boundaries between AI security, identity security, cloud security, application security, and security operations. The startups that win will need to integrate with systems enterprises already run, not ask administrators to replace their identity provider, endpoint tooling, SIEM, and access-control model in one purchase.
Federal guidance backs the risk diagnosis
The “new attack surface” language from Zaitsev is not just venture-capital positioning. In May, CISA, the NSA, and cyber agencies in Australia, Canada, New Zealand, and the United Kingdom issued joint guidance on adopting agentic AI services. The agencies highlighted risks including privilege escalation, emergent behavior, and accountability gaps, and advised organizations to limit agent autonomy, apply strong identity management, use layered defenses, and continuously assess security.
NIST’s Center for AI Standards and Innovation has reached a similar conclusion. Its 2026 work on AI-agent security describes risks that emerge when model output is combined with the ability to operate software systems: indirect prompt injection through adversarial data, poisoned models, and harmful actions taken by agents even without an external attacker directly compromising a conventional software vulnerability.
Those are not abstract risks for a Windows-heavy organization. An agent with access to a Microsoft 365 tenant may be able to search SharePoint, read mail, generate documents, query line-of-business data, or trigger workflow automation. An agent attached to a developer environment may access source code, build pipelines, secrets-management tools, or cloud subscriptions. The same connection that makes the agent useful becomes the path that needs authorization boundaries, logging, monitoring, and rapid revocation.
The shift is from protecting a user session to managing delegated machine action. Traditional endpoint detection, email security, and identity controls remain relevant, but they may not capture the entire sequence if the harmful instruction arrives as normal-looking content and the agent executes it with legitimate credentials. Security teams will need telemetry that connects the user, the agent, the model, its instructions, its tool calls, and its data access.
The SGNL record explains why identity sits at the center
Talpaz and Sipperly’s Brightmind previously backed identity-security company SGNL. Axios says the pair entered that investment at a $105 million valuation and later exited at $740 million, calling it the largest Series A exit in cybersecurity history. The precise investment economics have not been independently disclosed in the sources reviewed, but the $740 million transaction itself is established: CrowdStrike announced its agreement to acquire SGNL in January.
CrowdStrike described SGNL as a continuous-identity company focused on context-aware authorization—granting and revoking access according to current conditions rather than relying only on static permissions. The Register, SiliconANGLE, CSO Online, and CrowdStrike’s own announcement all reported the $740 million deal and its focus on authorization for human, machine, and AI-agent identities.
That acquisition is the clearest real-world evidence for Cognition’s view of where AI security spending will go. Security vendors do not need to build a separate “AI” product category if the practical control problem is authorization: deciding what an agent can do, for how long, in what application, with access to which data, and under which changing risk conditions.
For Windows and enterprise IT administrators, this points to a less glamorous but more urgent project than shopping for an AI-security label. Organizations deploying copilots and autonomous workflows need to inventory the non-human identities those systems create or use, remove standing privileges where possible, separate high-risk tools and data stores, and retain logs detailed enough to trace automated activity across services.
Cognition’s strategy will be tested by deployment, not deal size
A $170 million target is substantial for a concentrated early-stage cyber fund, but it does not guarantee that Cognition will find the platform it is describing. Seed and Series A investing is unusually dependent on technical judgment: whether a founding team understands a security problem deeply enough to build durable enforcement rather than a feature that a larger security vendor can absorb.
Cognition’s founders do have relevant experience. Zaitsev’s CrowdStrike role covered technology vision and strategy, including data science, AI, machine learning, and malware research. Talpaz and Sipperly worked on corporate development at CrowdStrike before Brightmind, giving the group visibility into how a major cybersecurity buyer evaluates product gaps and acquisition targets.
That background could help Cognition identify companies that are technically strong but not yet legible to a chief information security officer. It could also pull the fund toward the same broad-platform framing now common across cybersecurity: one vendor promising to consolidate tools, context, workflows, and enforcement. Customers should be wary of that promise until a product demonstrates how it works across real Microsoft, cloud, identity, and security-operations deployments.
The immediate significance is therefore not a change to CrowdStrike Falcon or a new product available for purchase. It is a signal from a long-serving CrowdStrike technology leader and two former dealmakers that the next cybersecurity investment cycle will focus on AI agents with permissions—not AI models in isolation. Enterprises adopting those agents should treat every connector, delegated credential, and automated action as part of the attack surface today, rather than waiting for the category-defining startup Cognition hopes to fund.