Virgin Money Customer Testimonial: Scaling Agentic Security Operations with Legion
Hear directly from Neil Robinson, CISO at Virgin Money, on how Legion’s agentic security operations platform learned his team’s existing investigation workflows and scaled them without forcing new tools or processes onto analysts. Neil shares how Legion delivered faster, more repeatable, and more secure investigations, aligned to how his team already operates, rather than a generic playbook applied from outside.

Hear directly from Neil Robinson, CISO at Virgin Money, on how Legion’s agentic security operations platform learned his team’s existing investigation workflows and scaled them without forcing new tools or processes onto analysts. Neil shares how Legion delivered faster, more repeatable, and more secure investigations, aligned to how his team already operates, rather than a generic playbook applied from outside.
TL:DR. The eval said Claude had no internet access. That ended up being not true… three times. Anthropic just disclosed that across 141,006 cybersecurity evaluation runs, three separate incidents let its models reach the open internet from environments that were supposed to be sealed. A misconfiguration between Anthropic and its eval partner, Irregular, left the machines with live connectivity. The models didn't know it was a mistake, they just found a door that should not have been open, and walked through it. It’s a stark reminder of the importance of agentic systems' reliance on organizational context, and how without it, or without a complete picture of it, things can go astray.
Three Models, Three Choices
First, Opus 4.7 ran into a real company that happened to share a name with a fictional target in its scenario. It exploited weak passwords and unauthenticated endpoints, pulled credentials, and reached a production database with several hundred real rows in it. Anthropic's own review notes that the model "eventually recognized... that the system was real" but kept going anyway.
Mythos 5 published a booby-trapped Python package to PyPI as part of a capture-the-flag exercise. It sat live for about an hour and was downloaded onto 15 real systems, including a security vendor's scanner. The model's own reasoning flagged the problem as "NOT okay, and surely not the intended solution,” then talked itself out of stopping, pointing to an unfamiliar certificate authority and a 2026 date as evidence the whole thing must be simulated.
An internal research model scanned roughly 9,000 targets, compromised one real company using textbook techniques (exposed debug credentials, SQL injection), recognized the target was live, and stopped on its own.
It’s the same false premise with the same moment of doubt, but three different endings for how agents proceeded.
The Line Anthropic Drew
Anthropic's own framing of the incident is quite poignant, as the state, "The line between an aligned action and a harmful one is dependent on the model's understanding of its situation."
This really hits home, as it’s not what you might expect, which could be a statement about model safety training or the importance of guardrails, but rather a clear statement that the agent’s contextual awareness of what it was doing determines the outcomes.
Every one of these models had the values and the guardrails baked in during training. What they didn't reliably have was an accurate read on where they actually were. Read the situation wrong, and the same model that would refuse an obviously harmful request will talk itself into finishing one it thinks is fictional.
Why This Isn't Just Anthropic's Problem
While it is likely tempting to file this under "frontier lab eval hygiene" and move on, we don’t think this is the way to think about this particular incident.
Anthropic calls it correctly and deserves much credit for their response and summary to this grouping of incidents. This was a harness and operational failure, not an alignment failure. The failure here wasn't a jailbreak, a novel exploit, or a model deciding to go rogue. In fact, the models behaved exactly as agentic systems behave when they're missing organizational context… they filled the gap with their best guess, it just so happened that two out of three guessed wrong.
On the defensive side, this is a tidy summary of why there is hesitation to unleash generic AI systems into their environments. Particularly for an AI agent that is responsible for triaging your alerts, scoping a compromise, or deciding whether to isolate a host, it is critical to remember that these agents inherently make the same kind of situational judgment call, constantly and with real stakes. The agent determines if this is real, is this expected, does this action match how this specific business actually operates. The Anthropic incidents are a rare, public, unusually well-documented look at what happens when that judgment runs without enough grounding to get it right. That should be a stark reminder of how every CISO evaluates the agentic tools already running inside their own stack, from offensive research models to defensive SOC copilots alike.
What This Should Change for Security Leaders
From our perspective, there are a few things worth pulling out of this disclosure and applying directly to whatever agentic AI you're already running or evaluating:
- Assume your environment is a target, not just a beneficiary. Fifteen real systems downloaded a package that was never meant to exist. Roughly 9,000 targets got scanned by a model that was supposed to be sandboxed. Eval infrastructure, research environments, and "internal only" tooling deserve the same monitoring as production; because from the outside, they increasingly look identical.
- Don't take "it has guardrails" on faith. Context is king. All three models retained their safety training. It didn't prevent two of the three incidents. Guardrails matter, but they're not a substitute for auditability and contextual awareness — you need to see the reasoning and deploy agents that understand your organizational context (tools, processes, bespoke knowledge, etc.), not just trust the outcome.
- Demand whitebox AI, not a black box you hope behaves. Anthropic found this because it went back and read the transcripts. That's the standard: agentic systems, yours or a vendor's, should be inspectable, not just monitored for red flags.
- Build for the model that stops, not the one that rationalizes. The internal research model got it right because it had enough signal to recognize reality and enough restraint built in to act on that recognition. That combination: context plus a real decision point for a human or a hard stop, is a choice, not coincidence.
Anthropic deserves real credit here: they found this themselves, through proactive review, disclosed it before anyone made them, and are publishing the transcripts for all to see and learn from. That's the posture every lab and every vendor building agentic security tools should be held to, very much including ourselves as well.
But the underlying lesson is the one we keep coming back to: agentic AI is only as trustworthy as its contextual understanding of the situation it's actually in. That's true for a frontier model deciding whether a target is real. It's just as true for an AI agent in your SOC deciding whether an alert is a false positive, a test, or the start of an incident. Build the context in, keep the reasoning visible, and give the system a real reason to stop when it isn't sure, because agents are often irrationally confident and take ‘not sure’ as an instruction to pick their best guess and go.

Anthropic found its "sandboxed" models reaching the real internet three times. Here's why context, not guardrails, decides if agentic AI stays safe.
TL:DR: Ask any security team what would give them back the most time, and the answers tend to converge on the same theme: less time spent stitching things together, more time spent actually deciding. These are exactly the things that DragonClaw is built to optimize, as the orchestration layer that deploys Legion’s trusted AI agents into any security task.
Automated workflows have already gotten teams part of the way there, triggering playbooks and kicking off investigations the moment an alert fires. DragonClaw is built upon the foundation of Legion’s platform, in that we require zero integrations in exchange for the ability to operate any tool, and goes further: it leverages the business context (past cases, runbooks, recordings, etc.) to orchestrate the agents needed to respond to an alert or escalation, to tell you why the last three cases like this one got closed the way they did, and to surface the exact query that finds the right evidence in your specific environment. That's the difference between automation that runs a process and intelligence that understands one.
Instead of an analyst hunting across five tools to reconstruct context that already exists somewhere in the organization's own history, DragonClaw brings that context directly to them and performs a task, in their own way, the moment they need it. Ask a question, get a grounded answer or a completed action, drawn from how your organization actually operates, not a generic playbook applied from outside.
The result is analysts can spend more of their time on the judgment calls only a person can make while orchestrating the agentic layer, where DragonClaw handles the reconstruction, the pattern-matching, and the acceleration and scale that used to eat the hours in between.
From Analyst to CISO: Closing the Context Gap in Security Operations
For security analysts, think of real-world threat hunting. Today, it means pulling and reading vast amounts of data across a bunch of different tools before you can even form an opinion or a lead on where to go. DragonClaw runs that process, end-to-end, with agents. DragonClaw consumes data across all of your tools, correlates it, and comes back with a thesis for the analyst to either approve or disapprove.
If you're a CISO or security leader, quickly investigating what the risk or impact is for a CVE requires organizational context not contained in a single tool. DragonClaw assembles all of that data and surfaces the answers, with recommendations, and where appropriate, autonomous actions that can put the findings to work.
Add it up across a team, and the opportunity is real: practitioners who spend their time on judgment instead of relearning tools, leaders with a straight answer whenever they need one, and a security program built to scale with the threat landscape instead of falling further behind it.
Introducing DragonClaw
DragonClaw is Legion Security's agent orchestration layer for the SOC. It gives security teams the ability to invoke Legion's agents in plain conversational language, enabling security teams to seamlessly get work done, or to answer questions about how their processes, tools, and people are actually making decisions.
One thing to be clear is that this is not (yet another) bolt-on chat interface. DragonClaw is the next step in the Legion platform, built on everything Legion has already learned across the tools, knowledge, and decision logic for your team’s security workflows. DragonClaw takes that further, putting that context and institutional knowledge to work answering questions and completing tasks the moment someone asks.
Under the hood, DragonClaw interprets intent, figures out which agents a request actually requires, and orchestrates them; across all tools in the stack, including agents that take real action, like API calls or web interactions, without any integrations required. All of it runs inside configurable guardrails: explicit permission before any response action, only approved tools, and credentials pulled from secure vaults. Nothing about “conversational” means “unsupervised.”
What Changes For Each of You
Threats are scaling with AI. Automation and agents close a large part of that gap, and they'll take a SOC further than headcount ever could… but not all the way. Security teams need humans to stay in the loop, not to keep pace with volume (which they can’t), but to supervise the work, evaluate outcomes, test and challenge what the agents conclude, and make sure security stays something that enables the business rather than something that slows it down or breaks it. Security analysts and leaders serve essentially as the maestros of the agentic orchestra. That's the same place the sharpest thinking on AI lands more broadly: the machine executes and reasons whereas the human owns judgment where needed and accountability.
DragonClaw is what supercharges the security workers. It's what lets a security team orchestrate its agents instead of losing control over what they do. For security practitioners and SOC analysts, that shows up as a partner inside the investigation itself: context and enrichment on demand, memory across past cases, guidance on what to do next, and the ability to generate the right query for your environment instead of learning a new query language from scratch.
For managers and security leadership, it's one place to ask about real-time SLA risk, process improvement opportunities, MTTR and false-positive trends, bottlenecks, coverage gaps, and team workload — instead of stitching the answer together from five dashboards.
For CISOs, DragonClaw provides direct answers on risk posture, SLA exposure, MTTR trends, exposure to a new CVE, audit evidence, automation ROI, and board-ready reporting, available the moment you need them instead of on the next reporting cycle.
Not Another Chatbot, An Orchestrator
Chat interfaces are becoming table stakes across the industry, and we're not going to pretend otherwise; it’s been proven that chat alone isn't a durable differentiator. What makes DragonClaw different is what's underneath it: every answer and every action is grounded in the workflows, case history, and coverage data Legion has already built for your specific security team and your specific organization.
A generic assistant sitting outside your platform can talk about security in general. DragonClaw can talk about your security workflows, because it already has the record of how your security team works.
That's the same principle behind everything Legion builds: AI for defenders should understand how a specific business operates, across its tools, its workflows, its people, before it's trusted to answer questions or take action with real business impact. DragonClaw is where that understanding becomes something every person in your organization can talk to directly, whether that's the analyst mid-investigation, the manager reviewing the week, or the CISO prepping for the board.
DragonClaw will be showcased at Black Hat USA 2026, visit us at Booth #5150 to see it in action!

DragonClaw is Legion's agent orchestration layer for the SOC; grounded in your org's own context, not a generic chatbot bolted onto security tools.
Security teams don't get to choose their threat model. They inherit it: alert volumes outpacing headcount, attackers moving at machine speed, and a stack of tools that all assume a human is sitting in the middle of every decision. Legion Security was built to change that operating model. It should go without saying that the platform doing the changing has to be secure to its core.
CISA's Secure by Design Pledge exists to push the whole industry toward that standard: security as a default, not an upsell. Legion Security has signed the pledge, and this page lays out how we deliver on each of its seven goals today, where we go beyond them, and where we're still pushing.
One note before diving in. Legion Security is independently certified against SOC 2 Type 2, ISO/IEC 27001:2022, and HIPAA, and against ISO/IEC 42001:2023 for responsible AI management, because AI reasoning sits at the center of everything the platform does and we believe that deserves its own standard of scrutiny. Everything below is backed by audited evidence, not just a blog post. Every report, policy, and pentest result is available on request through our Trust Center.
Authentication
The pledge commitment: Demonstrate actions taken to measurably increase the use of multi-factor authentication across the manufacturer's products
Every Legion Security customer gets enterprise-grade identity protection from day one, not as an add-on. The platform integrates with any SAML 2.0 or OIDC-compliant identity provider, including Okta, Microsoft Entra ID, and Google Workspace, so your existing MFA and conditional access policies extend automatically to every login. No extra licensing tier, no SSO tax, no “contact sales” for basic protection.
For teams still mid-rollout on SSO, direct logins to Legion Security require MFA. There is no opt-out, not for admins, not for anyone.
And because Legion Security operates natively in the browser rather than through a sprawl of API integrations, there are no long-lived API keys quietly wiring it into the rest of your stack. Your analysts sign in once, through the identity layer they already trust, and the platform meets them there. Sessions are scoped and expire like any other corporate login, which is exactly how it should be.
Default Passwords
The pledge commitment: Demonstrate measurable progress towards reducing default passwords across the manufacturer's products.
Default and shared passwords are how breaches happen quietly. Legion Security doesn't have any, and we never will. Every customer environment is provisioned with unique, securely generated credentials from the moment it's stood up, and service-to-service connections run on scoped, short-lived access that expires on its own rather than a static key someone forgot to rotate. There's no fallback password lurking in a setup guide for an attacker to find.
Reducing Entire Classes of Vulnerabilities
The pledge commitment: Demonstrate actions taken towards enabling a significant measurable reduction in the prevalence of one or more vulnerability classes across the manufacturer's products.
Most security automation platforms expand your attack surface before they ever deliver value: months of custom connectors and API plumbing, each one a new door into your environment. Legion Security was built to eliminate that door entirely. The platform works through the browser your analysts already use, so there's no integration sprawl and no expanded blast radius when something goes wrong elsewhere in your stack.
For an AI-native platform, though, the honest conversation starts with a different vulnerability class: prompt injection. Legion Security's agents reason over evidence pulled from your tools, and some of that evidence, phishing emails and attacker-controlled artifacts among it, is adversarial. So we treat all of it as untrusted input. Evidence is validated and normalized before it ever reaches a model, agents operate with tightly scoped permissions rather than broad tenant access, and actions that change your environment pass through explicit approval gates. Malicious content can try to talk to our agents. It doesn't get to instruct them.
When we do find a weakness, whether through the independent penetration tests we commission, a researcher's report, or our own review, we don't stop at the fix. Significant findings get a root cause analysis and a set of preventative changes aimed at the pattern, not just the instance. Security isn't a checkpoint at the end of our development cycle; it's a constraint we design around from the start.
Security Patches
The pledge commitment: Demonstrate actions taken to measurably increase the installation of security patches by customers.
Legion Security runs as SaaS, full stop. There's no patch cycle for your team to manage, no fleet of installations slowly drifting out of date, no tenant running last year's fixes because nobody got around to the upgrade. We ship continuously through automated pipelines, so when we close a gap, every customer is protected at the same moment. The single biggest reason security patches don't get applied, the burden falling on the customer, simply doesn't exist in our model.
Vulnerability Disclosure Policy
The pledge commitment: Publish a vulnerability disclosure policy that authorizes testing in good faith, commits to not pursuing legal action against good-faith researchers, and provides a clear channel to report vulnerabilities.
As a SaaS-only platform, Legion Security maintains a vulnerability management policy that defines severity classifications, SLAs, and response processes for issues in the platform that may impact customers. We commit to those timelines contractually in our customer agreements, and our security operations are audited, internally and by third parties, to confirm we actually hold to them.
Researchers have a clear channel to responsibly disclose vulnerabilities to us, with explicit safe harbor: we will not pursue legal action against anyone making a good-faith effort to find and report an issue. Researchers working with us are partners, not liabilities, and we treat them that way.
Customers can follow all of it through our Trust Center, which provides self-service access to policies, procedures, security notifications, and third-party assessment reports such as penetration tests. Our Shared Responsibility Model, covered under Evidence of Intrusions below, defines which vulnerability management obligations sit with us and which stay with you. And when we patch a vulnerability that matters to you, you'll see it documented as a regular part of our release notes.
CVEs
The pledge commitment: Demonstrate transparency in vulnerability reporting, including accurate CVE records for the manufacturer's products.
Legion Security's SaaS-only architecture means we don't ship versioned software the way traditional on-prem vendors do, which changes how public vulnerability reporting typically plays out. What doesn't change is our commitment to transparency. We're formalizing a procedure that defines exactly how our security team evaluates and reports vulnerabilities, including issuing CVE records where appropriate, so customers always know what to expect from us. Not just when something goes wrong, but how we'll communicate it.
Evidence of Intrusions
The pledge commitment: Demonstrate a measurable increase in the ability for customers to gather evidence of cybersecurity intrusions affecting the manufacturer's products.
You shouldn't have to pay extra to see what's happening in your own tenant. Every Legion Security customer gets detailed, security-relevant audit logs at no additional cost, exportable to your own data lake for as long as you need to keep them. If something happens, you're never locked out of the evidence.
And here's the part we think matters most for a platform like ours: those logs don't stop at human logins and admin changes. Every action an agent takes during an investigation is recorded, along with the evidence it examined and the reasoning behind what it did. When an AI is doing SOC work, “who did what and why” has to include the AI. With Legion Security, it does.
We also publish a Shared Responsibility Model that spells out which parts of logging, monitoring, and incident response we own and which stay with you, so there's no ambiguity on the day it counts.
Software Supply Chain Security
The pledge commitment: The software manufacturer should maintain and share provenance data of third-party dependencies and have processes to govern its use of, and contributions to, open-source software components.
The pledge stops at seven goals. Your security questionnaires don't, and the topic that comes up most is supply chain. Third-party and open-source components in Legion Security are scanned automatically in source control and CI before anything reaches production, new vendors and dependencies go through a risk review before we adopt them, and a software bill of materials is available to customers through the Trust Center. If it runs inside Legion Security, we can tell you what it is and where it came from.
Looking Ahead
Legion Security's whole premise is that the best security systems don't freeze in place; they keep learning your environment and getting sharper with every investigation. We hold our own security program to the same standard. As the platform grows and the threat landscape shifts, this won't be a static page. We'll keep it current, and we'll keep raising our own bar right alongside it.
Questions about anything above? Dig into the documentation in our Trust Center, or reach out to your Legion Security team directly.

See how Legion Security meets CISA's Secure by Design Pledge with MFA by default, no default passwords, full audit logs, and SOC 2, ISO 27001, and HIPAA-certified security.


