[ Funding
](https://www.unite.ai/series/funding/)
[Add Unite.AI to your preferred sources on Google](https://www.google.com/preferences/source?q=unite.ai)
Horizon3 has raised $250 million in Series E funding at a valuation exceeding $2 billion, giving the cybersecurity company substantial new capital to expand its autonomous penetration-testing platform and move further into automated defensive remediation.
The round was co-led by existing investors NightDragon and New Enterprise Associates (NEA). Horizon3 says its valuation has more than tripled from the $650 million valuation attached to its Series D just over a year ago.
The financing arrives as security teams face an increasingly difficult imbalance. Artificial intelligence can help attackers identify weaknesses, adapt techniques and move through compromised environments more quickly, while many organizations still depend on vulnerability scans and periodic penetration tests that provide only a snapshot of their security posture.
Horizon3 is betting that organizations will respond by continuously attacking their own infrastructure before someone else does.
Turning Penetration Testing Into a Continuous Process #
Horizon3 is the company behind NodeZero, a platform designed to autonomously conduct penetration tests against internal networks, external infrastructure, cloud environments, Kubernetes deployments and other components of an organization’s technology stack.
Rather than simply generating a list of known vulnerabilities, NodeZero attempts to exploit weaknesses and combine them into complete attack paths. A misconfiguration might expose credentials, for example, which could then provide access to another system and eventually lead to sensitive data or administrative privileges.
This approach is intended to distinguish between vulnerabilities that theoretically exist and weaknesses that can actually be used to cause meaningful damage.
During a test, organizations can observe the techniques being executed through a real-time interface. Once testing is complete, the platform provides proof of exploitation, maps the steps taken through the environment and recommends actions for disrupting the attack path. Security teams can then rerun the relevant test to verify that a repair was effective.
NodeZero can also identify problems that do not depend on a conventional software vulnerability, including weak passwords, exposed credentials, ineffective security controls, data leakage and poor network segmentation. Its internal tests can pivot from on-premises systems into services such as Amazon Web Services, Microsoft Azure and Microsoft 365 when an exploitable path exists.
The broader objective is to replace occasional assessments with a repeating cycle of finding weaknesses, fixing them and testing the same environment again.
How Horizon3 Uses AI Without Giving It Complete Control #
Although Horizon3 describes NodeZero as an autonomous AI hacker, its architecture is more controlled than that phrase may suggest.
The platform combines graph-based reasoning, machine learning, deterministic logic and narrowly scoped generative AI. It builds a map of systems, users, credentials and relationships within an environment, then uses that information to plan and reprioritize potential attack paths.
Generative AI is used for tasks such as identifying high-value systems, interpreting the potential business impact of compromised data, producing executive summaries and suggesting additional strategies when a test reaches an obstacle. Machine learning can classify files and behaviors, while graph reasoning helps the platform determine how individual weaknesses may connect.
Importantly, Horizon3 says generative models do not create or directly execute exploits. The actions used to attack production environments are deterministic, prevalidated and constrained by the testing configuration. This separation is intended to preserve the adaptability associated with AI while reducing the unpredictability that would come from allowing a large language model to independently generate attack code.
High-Value Targeting, one of the platform’s newer capabilities, illustrates the approach. The system evaluates naming patterns, privileges, network relationships and business context to identify targets such as domain controllers, administrative accounts and database servers. It can then prioritize the attack paths most likely to produce a serious operational or financial impact rather than treating every accessible system equally.
Growth Beyond Traditional Vulnerability Management #
Horizon3 reports that its technology has now completed approximately 310,000 tests in production and is used by more than 7,000 organizations, including banks, healthcare networks, government agencies and four Fortune 10 companies.
The company also reported 120% year-over-year growth in annual recurring revenue. These figures help explain why investors were willing to support a substantial late-stage round at a sharply higher valuation, although they remain company-reported metrics.
The funding round attracted seven new investors: Acrew Capital, Blue Cloud Ventures, Demeter Group, EDBI, PSG, SAIC and Sapphire Ventures. Returning investors included Craft Ventures, Prosperity7 Ventures, Qualcomm (QCOM ) Ventures, Ridge Ventures and SignalFire.
NightDragon founder Dave DeWalt, who previously led FireEye and McAfee, and NightDragon Managing Director Morgan Kyauk will join Horizon3’s board as part of the transaction.
Funding Global Expansion and Autonomous Remediation #
Horizon3 plans to divide the new capital among commercial expansion, international growth and product development.
The company intends to increase its sales, marketing and channel operations across enterprise, mid-market and federal customers. Internationally, it is preparing to enter Singapore and Australia while expanding its existing presence across Europe, the Middle East and Africa.
The more consequential part of the roadmap involves moving beyond identifying exploitable problems.
Horizon3 plans to develop autonomous blue-team agents that can act on findings produced by NodeZero. The long-term concept is a continuous learning loop in which an offensive system identifies and proves an attack path, a defensive agent implements or proposes a correction, and NodeZero tests the environment again to confirm that the path has been closed.
The company has already introduced integrations through its Model Context Protocol server that can pass penetration-testing results into tools such as Jira, GitHub, security orchestration platforms and infrastructure-as-code workflows. Potential actions include rotating compromised credentials, adjusting endpoint detection rules, deploying compensating controls and verifying whether a remediation worked.
NodeZero can also deploy Tripwires, which are decoy targets placed on vulnerable or strategically important assets. If an actual intruder later interacts with one, the system can alert the organization that malicious activity may be occurring.
From Finding Problems to Proving Security #
The Series E reflects a broader change in how cybersecurity risk is being evaluated.
Traditional vulnerability management often produces more findings than security teams can realistically address. Severity scores can indicate that a flaw is dangerous in general, but they do not always reveal whether it can be reached, combined with other weaknesses or used to compromise an important system inside a particular organization.
Autonomous penetration testing attempts to narrow that gap by producing evidence of what an attacker could accomplish under real conditions. The next challenge is determining how much of the resulting remediation process can also be automated without introducing new operational risks.
Allowing defensive agents to change credentials, configurations or security policies could reduce response times considerably. It will also require strict approval boundaries, audit trails, rollback mechanisms and safeguards against an automated correction disrupting legitimate systems.
Horizon3’s new funding gives it the resources to pursue that transition at a much larger scale. Its progress will help determine whether autonomous penetration testing remains primarily a faster security-assessment tool or develops into a broader control layer where AI systems continuously attack, repair and validate enterprise infrastructure.
The $250 million round suggests investors believe the latter model could become an important part of how organizations defend increasingly complex networks. Proving that it can be deployed safely and consistently will now be as important as proving that the technology can find a way in.