Horizon3, a cybersecurity company that builds artificial intelligence designed to autonomously break into corporate networks and expose weaknesses, has raised $250 million in a Series E funding round. The deal values the San Francisco based firm at more than $2 billion, according to TechCrunch, which first reported the news.
The valuation has more than tripled in just over a year. Horizon3 was worth roughly $650 million at its Series D round in mid 2025, according to Forbes. The round was co-led by existing investors NightDragon and NEA, and drew participation from seven new investors alongside five returning backers, according to a company statement.
From annual checkups to continuous testing
For decades, most companies tested their cyber defences with an annual penetration test, a hired team of ethical hackers probing systems once a year and filing a report. Horizon3's core product, NodeZero, automates that process instead, running safe, authorised attacks continuously against live production systems rather than as an occasional exercise.
Cybersecurity startup Horizon3 has raised a $250 million Series E at a $2 billion valuation, more than tripling its valuation in 14 months, TechCrunch reported, adding that the funding arrives as two major AI research labs disclosed last week that their models had breached systems outside their intended scope.
“"We invented the concept of AI Hackers and spent six years earning the right to autonomously pentest the most critical and sensitive networks in the world, with no humans in the loop," said Snehal Antani, Co-Founder and CEO of Horizon3.”
Horizon3 says its approach has powered 120% year-over-year growth in annual recurring revenue, and the company now protects more than 7,000 organisations worldwide, including multinational banks, major healthcare networks and four Fortune 10 enterprises, according to its own announcement. Chief Revenue Officer Matt Hartley told TechCrunch the company approached $100 million in annual recurring revenue last year and expects growth to accelerate further this year.
Why the pitch resonates in Europe
The timing matters for organisations across the EU and UK, which face a tightening web of regulation on digital resilience. The bloc's NIS2 directive, which came into force in 2024 with member states required to transpose it into national law, obliges operators of critical infrastructure to regularly assess the effectiveness of their cybersecurity controls. The Digital Operational Resilience Act (DORA), which applies to banks, insurers and other financial firms since January 2025, goes further still, explicitly mandating penetration testing and resilience simulations.
Horizon3 says it is FedRAMP High authorised, the United States government's cloud security standard, and that it helps clients meet DORA, NIS2, the US NIST framework, healthcare rules under HIPAA, SOC 2 and GDPR, according to the company's press release. That regulatory alignment is likely part of the appeal for European buyers navigating overlapping compliance regimes with limited security staff.
The broader backdrop is a cybersecurity market both AI attackers and AI defenders are racing to dominate. According to Grand View Research, cited by the Ukrainian outlet Mezha in its coverage of the deal, the global cybersecurity market was valued at $271.9 billion in 2025 and could grow to $663.2 billion by 2033. Hartley told TechCrunch that AI tools have made it easier for attackers to develop new exploits quickly, forcing security teams to handle threats faster than they can fix them, and that Horizon3 has spent roughly $100 million on research and development building automated systems designed to stay predictable and controllable.
Hartley also said growing anxiety about AI's own risks is shaping demand. "It's also making people a lot more careful about how they deploy AI," he told TechCrunch, adding that clients are increasingly asking whether their own security tools could behave unpredictably once deployed at scale.
SiliconANGLE reported that the new round brings Horizon3's total funding raised to date to $428.5 million. The company, founded in 2019 according to SecurityWeek, has not disclosed specific plans for the new capital beyond continued global expansion and development of automated tools for remediation, following AI generated attacks with AI generated fixes.
This article is free to read. It always will be — no paywall, no account, no tracking.




