The next cybersecurity battleground is inside the processor
Credit: CoreGuard
TL;DR
Processors still execute instructions with no understanding of whether they are legitimate. Dover Microsystems’ CoreGuard, born from DARPA’s $100M CRASH program, adds a silicon-level enforcement layer that watches every instruction against programmable micropolicies. NXP engaged Dover in 2018 for embedded platforms. IBM finds 1 in 4 malicious breaches are now AI-enabled at $6M average cost. Dover holds 17 patents and has been validated through government red-team exercises.
Cybersecurity has a location problem. Attackers often exploit vulnerabilities in systems that businesses have spent years protecting with software, yet the processor at the center of those systems can remain largely unaware of anything that is wrong. Verizon’s 2026 Data Breach Investigations Report found vulnerability exploitation had become the leading initial access vector, accounting for 31% of breaches, while only 26% of critical vulnerabilities in its dataset were fully remediated during 2025.
The stakes are rising as computing moves deeper into physical systems. AI workloads, connected infrastructure, industrial equipment, and autonomous machines all depend on processors to translate software instructions into real-world action.
A compromised application could then become more than a data-security problem; it can become a problem of control. IBM’s 2026 breach research found that one in four malicious breaches were AI-enabled, with those incidents costing an average of $6 million.
Software remains indispensable to modern computing, but its complexity can create a persistent security challenge. Adding another defensive layer of software can leave organizations defending vulnerable software with more vulnerable software. The question is becoming harder to avoid: what if the processor itself could participate in deciding whether an instruction should be allowed to execute?
Jothy Rosenberg, a 9x technology startup founder and Founder and Executive Chairman of Dover Microsystems, has spent years pursuing that question. His previous ventures included two exits exceeding $100 million, while his work at Dover has centered on a proposition that challenges the software-first model of cybersecurity: the processor should have a mechanism for recognizing prohibited behavior rather than blindly executing every instruction it receives.
“Processors are still the same simple basic design that was created in 1945, which means they cannot tell if they’re being attacked,” Rosenberg explains. His concern is particularly acute because the vulnerabilities do not disappear when a security product is installed. He says, “When you put this big system in place, and it’s supposed to protect you, and yet it has bugs, well, that’s just another avenue for the bad guys to get in.” All software has been shown to have 15 bugs per thousand lines of source code.
Dover’s CoreGuard approaches the problem at the silicon level. The technology is designed as an additional piece of processor security that watches instructions as they are executed. Programmable rules, known as micropolicies, establish what the processor should be permitted to do. If an instruction violates one of those rules, CoreGuard is designed to prevent its execution and alert the surrounding system.
Photo of Jothy Rosenberg — Credit: Jothy Rosenberg
According to Rosenberg, a processor normally has no inherent understanding of whether the instruction it is executing is legitimate. He puts the concept in simple terms: “Our job is to be watching every instruction that the processor is executing. And at the same speed that the processor works, we could tell if it’s the correct instruction or not.”
The idea has roots in one of cybersecurity’s defining episodes. The 2010 Stuxnet attack demonstrated that malicious code could move from the digital environment into the physical world, helping prompt DARPA’s CRASH program, a $100 million research effort aimed at developing fundamentally different approaches to cyber defense. Dover’s technology emerged from that research, was subsequently developed at a research company, and became an independent company in 2017.
The commercial path has included engagement with semiconductor companies. NXP announced in 2018 that it had engaged Dover to introduce CoreGuard into future embedded platforms, describing the technology as hardware-based security IP capable of defending processors against software vulnerabilities and network-based attacks.
Rosenberg believes the technology’s relevance will grow as processors become responsible for increasingly consequential decisions. In his view, AI is an obvious pressure point because AI systems are themselves software and can carry substantial operational authority. “AI systems are very vulnerable to attack,” he argues. “They’re highly leveraged. You’re asking them to go solve really critical problems.”
Dover’s technology is designed to function as silicon IP alongside a host processor. Its portfolio includes 17 patents, according to Rosenberg, giving the company a specialized position around processor-level enforcement. The architecture has also been developed to address classes of software exploitation, including buffer-overflow attacks, through hardware-enforced micropolicies.
The strategic question, then, extends beyond one cybersecurity company. Semiconductor manufacturers, defense contractors, and infrastructure technology companies increasingly face pressure to secure computing at the point where software becomes action. Rosenberg’s thesis is that another generation of software-based security products alone will not resolve that structural problem.
“Software has bugs. Hardware can’t be manipulated in the same way. It’s all fixed in the hardware,” he notes. That argument places Dover in a larger technological shift: cybersecurity may gradually move from protecting the software surrounding processors to giving processors an active role in enforcing what software is allowed to do. As computing becomes more deeply embedded in the physical world, Rosenberg insists that the silicon beneath the code may become one of the most consequential places to put a security boundary.
Get the TNW newsletter
Get the most important tech news in your inbox each week.