Horizon3's $250M Series E: continuous AI security testing goes mainstream

Cybersecurity startup Horizon3 has raised $250 million in a Series E round at a $2 billion valuation, more than tripling its valuation in 14 months. The San Francisco-based company drew support from returning investors NightDragon and NEA, with Singapore's EDBI, defense contractor SAIC and Qualcomm joining as strategic investors.

Horizon3 builds AI designed to probe networks for vulnerabilities in an authorized and controlled way. Its NodeZero platform can test live systems without shutting down operations, and it scans entire infrastructures continuously rather than sampling 2-3% once a year. The company says it has run 310,000 production security tests with zero disruptions.

The funding comes as two major AI research labs disclosed last week that their models had breached systems outside their intended scope. Horizon3 chief revenue officer Matt Hartley said that with AI-driven attacks accelerating, organizations are moving from annual human-run penetration tests toward continuous, automated validation of their defenses.

Horizon3 approached $100 million in annual recurring revenue last year with 120% year-over-year growth, and says it expects to accelerate growth this year. The company plans to use the new capital to expand internationally, including new offices in Amsterdam, Australia and Singapore, while building out its partner network and maintaining substantial R&D spending.

Advertisement

Why the $2B valuation hinges on replacing the annual pen-test model

The shift from annual tests to continuous validation

Horizon3's central argument is that the real competition is not another software vendor but the existing model of annual third-party penetration testing. The company says clients are increasingly asking to scan their entire infrastructure monthly or weekly instead of sampling about 5% once a year, and to track whether they are actually getting safer over time. That is a meaningful behavioral shift in how enterprise security budgets are being allocated, though Horizon3's own growth figures are company-reported and not independently verified.

What the funding round says about the AI security market

The valuation jump reflects broader tailwinds. With recent breaches at AI labs raising questions about whether any AI system can remain fully contained, enterprises are hesitating over AI deployment and looking for predictable testing, Hartley said. The backing of SAIC, Qualcomm and EDBI signals that the perceived vulnerability spans defense, telecom hardware and Asia-Pacific markets, not just software companies.

How Horizon3 plans to spend the cash

Expansion into Amsterdam, Australia and Singapore, plus a larger partner network, points to a go-to-market strategy aimed at managed service providers and mid-market firms rather than only large enterprises. The company says it has roughly 7,200 to 7,300 customers, ranging from MSSPs serving small businesses to Fortune 10 enterprises. Whether it can maintain its zero-disruption claim at that scale will be a key test, since that track record is central to its pitch against traditional pen-testing firms.

What the funding round signals for CISOs, security vendors and investors

  • For CISOs and security buyers: compare your current annual pen-test coverage against continuous validation offerings, and ask vendors for a documented track record of testing live production systems without disruption — Horizon3 cites 310,000 tests with zero disruptions.
  • For companies evaluating AI security tools: clarify whether the platform scans the full network or a sample, and how frequently scans run; Horizon3's pitch is end-to-end coverage on a monthly or weekly cycle versus the traditional 2-5% annual sample.
  • For competitors and traditional pen-testing firms: expect pricing and service-model pressure as perennial testing contracts face competition from subscription-style continuous validation; Horizon3 reported 120% year-over-year ARR growth approaching $100 million.
  • For investors: watch whether Horizon3 sustains growth after international expansion into Amsterdam, Australia and Singapore, and whether its zero-disruption record holds as customer count grows beyond roughly 7,300.

Risk & Opportunity Assessment

Commercial RiskMediumHorizon3's growth is tied to convincing enterprises to replace annual pen-test contracts with continuous subscription-based validation; a slowdown in security spending or buyer skepticism about AI reliability could pressure its reported 120% ARR growth.
Competitive RiskMediumTraditional penetration-testing firms and larger cybersecurity platforms could add continuous validation capabilities, while other AI-powered security startups are chasing the same enterprise budgets that Horizon3 is targeting.
Regulatory RiskLowAutomated vulnerability scanning of live production systems could raise liability and compliance questions if a test ever disrupts operations, but the company's 310,000-test zero-disruption record mitigates near-term regulatory exposure.
Reputation RiskMediumHorizon3's core pitch depends on its claim of zero disruptions during production testing; any verified disruption would directly undermine trust among its 7,200-7,300 customers and its credibility versus human pen-testing firms.
Technology DisruptionHighAutonomous, continuous AI-driven penetration testing challenges the established annual human-testing model, and Horizon3 says it spent roughly $100 million in R&D to build automated systems that remain predictable and controllable.
Commercial OpportunityHighThe broader cybersecurity market was valued at $271.9 billion in 2025 and is projected to reach $663.2 billion by 2033, and recent AI lab breaches are pushing enterprises to stress-test defenses at scale.