Horizon3 Raises $250M at $2B Valuation for AI-Driven Pentesting
The cybersecurity firm's autonomous platform has run 300,000 production penetration tests, collecting proprietary data as attack speeds compress from minutes to seconds.
Horizon3 triples valuation on AI-driven security thesis
Horizon3 has closed a $250 million Series E round at a valuation exceeding $2 billion, more than tripling from approximately $650 million just over a year ago. The San Francisco cybersecurity company's growth centers on a stark premise: AI-powered attacks are accelerating so rapidly that human-led defenses can no longer keep pace.
The oversubscribed round was co-led by NightDragon and NEA, with NightDragon founder Dave DeWalt—former CEO of McAfee and FireEye—joining the board. Horizon3 reported 120% annual recurring revenue growth and now serves more than 6,500 organizations, including the NSA, CISA, and four Fortune 10 companies, according to details first reported by Forbes.
Why it matters
As generative AI lowers the barrier for sophisticated cyberattacks, enterprises face a fundamental speed problem. Horizon3's thesis—that autonomous systems must handle both offense and defense, with humans intervening only by exception—represents a structural shift in how organizations approach security. The company's ability to operate safely inside live production environments at scale, combined with proprietary training data from hundreds of thousands of real-world penetration tests, positions it differently than competitors relying primarily on public vulnerability databases or controlled lab environments.
From seven minutes to 77 seconds
CEO Snehal Antani, a former CTO of Joint Special Operations Command who worked with the Defense Department's Project Maven AI team, points to a dramatic compression in attack timelines. An attack that required roughly seven minutes and 19 seconds three years ago now takes 77 seconds, he told Forbes. Antani expects that window to shrink further—potentially to 30 seconds—at which point organizational decision-making speed, not technical capability, becomes the limiting factor.
The company's NodeZero platform performs autonomous penetration testing inside live enterprise networks, including banks, hospitals, and defense contractors. Horizon3 claims to have conducted more than 300,000 production-safe penetration tests, with every engagement feeding a reinforcement-learning loop that refines the system's judgment about which actions are safe to attempt and which carry unacceptable operational risk.
Betting on data, not models
Antani frames Horizon3's competitive advantage around proprietary operational data rather than any specific AI model. "Every single time our AI hacker runs a penetration test, it's collecting training data that literally nobody else has," he said. The company views foundation models as disposable—new ones will continuously emerge—while the workflow harness that executes attacks and the unique training data from customer environments create durable differentiation.
This approach contrasts with newer entrants like XBOW, which apply large language models directly to offensive security, and established players like Pentera, Picus, AttackIQ, and SafeBreach that automate penetration testing or validate security controls. Horizon3's edge, if it holds, lies in having solved the harder problem: letting autonomous software attack Fortune 10 companies, hospitals, and defense contractors without breaking anything.
Expanding from red team to blue team
The Series E funding will support geographic expansion into Singapore, Australia, and deeper penetration across EMEA. More significantly, Horizon3 plans to develop autonomous blue-team agents that remediate vulnerabilities directly based on NodeZero's findings—creating AI learning loops between attackers and defenders.
The platform already expanded into web application testing this year and joined Anthropic's Project Glasswing initiative focused on critical infrastructure security. Autonomous remediation introduces new risks, as incorrect fixes can disrupt production systems, but Antani argues the alternative—leaving exploitable weaknesses unaddressed—poses greater danger.
Details of the funding round and company metrics were first reported by Victor Dey at Forbes.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call