Summary
- Hadrian has raised $40 million in a round co-led by Forgepoint Capital International and SmartFin.
- Its platform combines continuous attack surface discovery with agentic penetration testing and validation.
- The funding takes total capital raised to $65 million and will support engineering, research and expansion across EMEA and the US.
Amsterdam cybersecurity company Hadrian has raised $40 million to expand a platform that continuously discovers an organisation’s internet facing systems and uses AI agents to test which weaknesses can be exploited in practice.
Forgepoint Capital International and SmartFin co-led the round, with HV Capital, Motive Partners, Picus Capital and Oetker Ventures participating. The financing takes Hadrian’s total capital raised to $65 million and will support engineering, research and commercial expansion across EMEA and the United States.
Hadrian sits in a growing area of cyber security where software is being asked to perform more of the work traditionally associated with human penetration testers. Its Atlas platform maps exposed assets and tests risks continuously, while Nova provides deeper penetration testing using AI agents against defined targets.
Finding a technical weakness and proving that an attacker can use it are different tasks. Vulnerability scanners can generate large queues of findings, but security teams still have to decide which exposures create a plausible route into systems. Hadrian’s proposition is to automate more of that validation rather than simply produce another stream of alerts.
Testing moves closer to the pace of change
Periodic penetration testing provides depth at a particular moment, yet external infrastructure can change between assessments. Cloud services appear, applications are updated, certificates expire and new internet facing systems can be introduced without waiting for the next scheduled test.
Atlas is designed around that mismatch. It continually maps domains, addresses, services and other exposed infrastructure before feeding relevant findings into validation and remediation workflows. Nova can then carry out more concentrated testing when an organisation wants to examine a particular application or environment in greater depth.
Sharing context across those functions reduces the separation between attack surface management and penetration testing. A newly discovered asset does not first have to be entered manually into an entirely different testing process before the security team can establish whether it creates a meaningful route for an attacker.
Hadrian reports that customers have gained ten times greater visibility into critical exposure, resolved issues 80% faster and achieved five times the return on investment associated with manual penetration testing. Those remain vendor reported figures, and the funding announcement does not provide an independent methodology that would make them suitable as general benchmarks.
The customer list nevertheless shows that the platform is operating in substantial enterprise environments. Hadrian names organisations including McKesson, NBCUniversal, TotalEnergies, Amadeus, Leroy Merlin and Damen Shipyards, spanning sectors where acquisitions, digital services and distributed operations can create external assets faster than central security teams can catalogue them manually.
Autonomy raises the governance requirement
AI is changing both sides of offensive security. Attackers can automate reconnaissance, scripting and portions of an attack chain, while defenders are using similar technology to discover assets, validate vulnerabilities and repeat tests more frequently.
Techopia has already covered French startup Fleuret’s use of AI agents in automated penetration testing. Hadrian’s development is distinct in scale and product scope: the company is raising a substantially larger round around a platform that combines continuous discovery with offensive validation and already lists major enterprise customers.
As testing becomes more autonomous, authorisation becomes part of the technical problem. A platform designed to behave like an attacker cannot simply be given unlimited freedom against production infrastructure. Scope, timing, permissions and stopping conditions have to remain clear enough that a security test does not create an operational incident of its own.
Hadrian describes human users as retaining control over the mission and decisions while agents perform more of the discovery and testing between those points. That division is important because greater automation changes the frequency of offensive activity without removing organisational responsibility for what the system is allowed to do.
The market is likely to demand evidence beyond successful exploitation demonstrations. Enterprise customers need automated testing to produce findings that can be reproduced, prioritised and passed into remediation processes, while regulated organisations also need a record of how tests were authorised and controlled.
The $40 million round gives Hadrian more resources to develop that operational layer as well as the underlying agents. Commercial expansion will place the system into more environments where network design, governance requirements and internal security processes differ substantially.
Continuous offensive security will be judged on whether it improves that wider system rather than merely increases testing volume. Finding a vulnerability every day has limited value if remediation teams cannot understand the evidence or if autonomous testing creates uncertainty over what has happened inside a production environment.
Hadrian is betting that continuous discovery and exploitation validation can close the gap between changing internet infrastructure and the slower cadence of traditional assessments. Its funding gives the company more capacity to pursue that model, while the harder test remains whether automated offensive work can preserve the control and judgement that made skilled human testing valuable in the first place.












