Cytix raises $7M to govern software changes as AI coding speeds up Cytix, a Manchester cybersecurity developer founded by Ben Armstrong, Thomas Ballin, and Matt Milan, raised $7 million in Series A funding led by Northern Gritstone, with participation from Auriga Cyber Ventures and NPIF II - PXN Equity Finance, to expand its change risk management platform for enterprises facing increased software changes from AI-assisted development. The funding, reported by Tech.eu on August 12, will help Cytix turn its continuous security-testing product into a control layer that assesses software changes in real time, addressing the limitations of annual penetration tests and static scanners. Cytix https://www.cytix.io/?ref=runtimewire , the Manchester cybersecurity developer founded by Ben Armstrong https://www.linkedin.com/posts/benarmstrong2 its-incredible-what-can-happen-when-you-activity-7462759170526662657-JQwP?ref=runtimewire , Thomas Ballin https://balancethegrind.co/interviews/thomas-ballin-co-founder-of-cytix/?utm source=openai&ref=runtimewire and Matt Milan https://startups.co.uk/startups-100/2024/cytix/?ref=runtimewire , raised $7 million in Series A funding, Tech.eu reported on August 12 https://tech.eu/2026/08/12/cytix-raises-7m-series-a-to-tackle-cyber-risks-from-ai-driven-software-development/?ref=runtimewire . The financing gives the founders a larger budget to turn their continuous security-testing product into a control layer for enterprises managing a rising volume of software changes. Northern Gritstone https://www.northern-gritstone.com/?ref=runtimewire led the round. Existing investors Auriga Cyber Ventures https://www.aurigacyberventures.com/?ref=runtimewire and NPIF II - PXN Equity Finance also participated, with the latter managed by PXN Ventures https://www.pxnventures.co.uk/?ref=runtimewire as part of the Northern Powerhouse Investment Fund II. Cytix did not attach a valuation to the announcement. Armstrong, Cytix's commercial co-founder and CEO, previously held sales and business-development roles at NCC Group and penetration-testing specialist Secarma. Ballin worked as an ethical hacker at Secarma and NCC Group, while Milan brought software-engineering experience. The three incorporated Cytix in Manchester on April 12, 2022, according to UK Companies House https://find-and-update.company-information.service.gov.uk/company/14043556?ref=runtimewire . Their original complaint was practical: annual penetration tests could find complex flaws, yet the results arrived too slowly for software teams shipping continuously. Static scanners ran faster, but generated noise and missed risks that depended on business logic or architectural context. Cytix built its product around assessing software changes as they happen rather than relying only on scheduled testing. From penetration tests to a decision layer Cytix's product materials describe its processing of tickets, pull requests, code diffs, deployments and release information. Cytix says its change risk management platform determines whether a change requires security attention, assesses the business risk, selects a response and records how that response was completed. That evidence trail is central to Cytix's enterprise pitch. Security leaders can use the record to show risk and compliance functions why a change was approved, tested or escalated. Cytix's product materials https://cytix.io/how-it-works/?ref=runtimewire describe AI agents that assess changes and choose targeted testing. Straightforward risks can receive automated tests, while complex, contextual risks can be assigned manual testing; higher-risk changes can be escalated to human-led penetration testing. "AI-assisted development means change now happens at machine speed," Armstrong said in the funding announcement https://tech.eu/2026/08/12/cytix-raises-7m-series-a-to-tackle-cyber-risks-from-ai-driven-software-development/?ref=runtimewire . He said vulnerability alerts provide an incomplete answer because they identify technical issues without consistently explaining how a specific change affects the organisation. The Series A backs a broader product than the penetration-testing service Cytix initially sold. Armstrong, Ballin and Milan are betting that the durable control point will sit between the software development lifecycle and the security, risk and compliance functions responsible for governing it. AI gives Cytix urgency and competition Cytix cites research https://tech.eu/2026/08/12/cytix-raises-7m-series-a-to-tackle-cyber-risks-from-ai-driven-software-development/?ref=runtimewire finding that 62% of security leaders viewed organisational security risk as moving from a latent problem to an immediate one. The same research found that 38% strongly agreed their organisation was prepared for the volume of AI-generated code entering its environment. These are company-supplied figures rather than independently validated findings in the supplied material. Cytix is entering a category where application-security products increasingly compete on context and prioritisation. Endor Labs https://www.endorlabs.com/learn/introducing-ai-security-code-review?ref=runtimewire uses AI agents to examine pull requests for design flaws and architectural changes, including new API endpoints and altered authentication logic. OX Security https://ox.security/appsec-vulnerability-prioritization-by-ox/?ref=runtimewire prioritises findings using factors such as reachability, exploitability and potential impact. Cytix's distinction is the attempt to govern the complete decision around a change: whether security should care, what testing is proportionate, whether the risk was addressed and what evidence should be retained. Execution will depend on how accurately Cytix makes those decisions and whether security leaders trust its assessments in regulated environments. The round funds an enterprise distribution push Cytix previously raised GBP 1.6 million in September 2024 https://www.pxnventures.co.uk/cybersecurity-specialist-cytix-raises-1-6m-from-npif-ii/?ref=runtimewire from investors including NPIF II, Auriga Cyber Ventures and SFC Capital. That financing supported Cytix's move into larger accounts. The Series A will fund the platform's rollout as Cytix targets enterprise and regulated customers. Customers can buy Cytix directly or through managed services delivered with NCC Group and KPMG. Cytix announced its NCC Group partnership in February https://www.cytix.io/resources/cytix-partners-with-ncc-group?ref=runtimewire , combining its change analysis with NCC Group's offensive-security testing capacity. Those partnerships give Cytix a route into regulated enterprises that already buy security consulting from established providers. They also let Cytix position its software as infrastructure for continuous testing programs rather than another dashboard competing for a security leader's attention. The financing announcement says Cytix will use the capital to accelerate the platform rollout and reach more enterprise and regulated customers. Armstrong and his co-founders built Cytix around a bottleneck they encountered in penetration testing: expert security reviews were too periodic to keep pace with development. AI coding has widened that gap. The Series A gives Cytix the chance to prove that enterprises will place a policy and evidence layer around every consequential software change, rather than simply add another scanner to the pipeline.