Summary
- Horizon3 has raised $250 million at a valuation above $2 billion after reporting 120 per cent annual recurring revenue growth.
- Its NodeZero platform attacks customers’ live environments to find exploitable paths, recommend fixes, and test whether remediation worked.
- A new Amsterdam headquarters connects the funding to European demand, although automated testing still requires strict controls and skilled human oversight.
Horizon3 has raised $250 million to expand its autonomous penetration-testing platform, combining a late-stage cybersecurity funding round with a deeper push into Europe from its new regional headquarters in Amsterdam.
The Series E values the US company at more than $2 billion, compared with $650 million when it completed its previous round just over a year ago. Existing investors NightDragon and NEA co-led the financing, joined by seven new investors and five returning backers.
Horizon3 says annual recurring revenue increased by 120 per cent over the past year and that more than 7,000 organisations now use its technology. The company plans to expand sales, marketing, channels, and product development, while deepening its presence across Europe, the Middle East, and Africa.
Its European headquarters opened in Amsterdam in June, giving the company a regional base as financial institutions, infrastructure operators, public bodies, and other regulated organisations face growing pressure to prove that their security controls work rather than merely documenting that controls exist.
Testing moves from weaknesses to attack paths
Traditional vulnerability management can produce extensive lists of missing patches, weak configurations, and exposed services, although the number of findings often exceeds the capacity of security teams to address them. Severity scores also provide an incomplete guide because a technically serious weakness may be difficult to exploit, while several modest problems can be combined into a route towards a sensitive system.
Horizon3’s NodeZero platform is designed to test those routes by attacking a customer’s own production environment under controlled conditions. It attempts to combine misconfigurations, credentials, identity weaknesses, and reachable systems, then provides remediation guidance and tests the environment again after changes are made.
That cycle can give organisations stronger evidence about which weaknesses create a practical risk. It can also help security teams check whether a patch or configuration change closed the attack path rather than simply making a warning disappear from a management console.
The company says NodeZero has completed more than 310,000 production tests. That volume provides operational data for its automated methods, although the number of tests does not remove the need to examine how safely the platform behaves across different networks and business processes.
Production environments contain systems that may be fragile, poorly documented, or essential to daily operations. An automated test that is safe in one organisation may have unintended effects in another, particularly where legacy equipment, industrial controls, medical systems, or unusual authentication processes are involved.
Customers must therefore define scope, permissions, timing, exclusions, escalation routes, and emergency controls before allowing an autonomous system to probe live infrastructure. They also need reliable records of what the platform attempted, which data it accessed, and whether any testing artefacts remain afterwards.
European rules support recurring evidence
European cybersecurity rules are encouraging a shift from periodic compliance exercises towards recurring evidence of operational resilience. The Digital Operational Resilience Act applies detailed technology-risk requirements to financial organisations and important suppliers, while the NIS2 regime extends security and incident-management obligations across a wider set of essential and important entities.
Neither framework requires organisations to purchase automated penetration testing, but both strengthen the commercial case for tools that can demonstrate whether controls, remediation, and recovery arrangements remain effective between formal audits.
Human penetration tests will retain an important role because experienced specialists can apply context, creativity, and judgement that an automated platform may miss. They can examine business logic, unusual applications, social processes, and emerging attack methods that do not fit the platform’s existing model.
Automation is more likely to alter the frequency and division of that work. Organisations may use software to run recurring checks against common attack paths, while reserving specialist teams for deeper assessments, sensitive systems, adversarial exercises, and interpretation of the results.
That model also changes security procurement. A customer is no longer buying a report produced once or twice a year but a continuing service connected to production systems, identity platforms, cloud environments, and remediation workflows.
The supplier consequently becomes part of the organisation’s risk surface. Buyers must assess how Horizon3 secures its platform, protects test data and credentials, separates customers, controls software updates, and responds if its own technology is targeted by attackers.
The Amsterdam expansion provides a commercial base for addressing local procurement, regulatory, and support requirements, although a regional office does not resolve questions over data location, jurisdiction, subcontractors, or access by teams elsewhere in the business.
Horizon3’s financing shows that investors expect autonomous security validation to become a larger category, but the company’s language around an “AI versus AI” era risks reducing a practical security discipline to a contest between algorithms. Most breaches still exploit familiar weaknesses in identity, configuration, patching, access, and operational response.
Automated attack tools may help organisations find those weaknesses more frequently and prioritise them more effectively. Their value will be determined by whether customers close exploitable paths, verify the repairs, and improve their underlying systems — not by how convincingly one machine can describe itself as hacking another.




