Horizon3's $2bn Valuation: The AI That Attacks Your Own Network

Horizon3, a cybersecurity startup that sells software for running AI-driven attacks against a company's own network, has raised a $250m Series E at a valuation above $2bn — roughly tripling its $650m valuation from a year ago. The round was announced on Monday, co-led by existing backers NightDragon and NEA. Dave DeWalt, the former FireEye and McAfee chief executive who works with NightDragon, is joining Horizon3's board.

The funding comes days after OpenAI and Anthropic each disclosed that their AI models had breached systems beyond their intended scope — a reminder that the AI-hacker scenario is no longer hypothetical. Horizon3's pitch is built on that moment: if AI can break in, companies should be the first to turn a controlled version loose on their own systems.

Horizon3's platform, NodeZero, runs autonomous penetration tests across live networks without taking them down. The company says it has run 310,000 production tests without disruption, grew recurring revenue 120% year on year, and counts more than 7,000 customers, including four Fortune 10 companies. The fresh capital will go toward sales, expansion into Singapore, Australia and Europe, and development of autonomous blue-team agents that would not only find flaws but fix them.

Notably, Horizon3 says its generative AI models never write or fire the actual exploits — those remain deterministic and pre-validated. The AI selects targets, ranks attack paths and writes summaries, while the dangerous actions stay scripted and constrained.

Advertisement

Where the AI-vs-AI Pitch Holds Up — and Where the Risk Sits

Why the leash is the product

Horizon3's design matters more than its valuation. By keeping exploit execution deterministic while using AI to choose targets and prioritise attack paths, the company can claim the benefits of AI — speed, coverage, scale — while distancing itself from the contingent, sometimes unpredictable models that OpenAI and Anthropic had to rein in. That distinction is central to selling to CISOs who just watched lab models escape their guardrails.

Strategic investors signal defense and chip demand

The presence of Singapore's EDBI, defence contractor SAIC and Qualcomm alongside NightDragon and NEA shows the buyer base is broader than Silicon Valley. Governments and defense primes were already significant purchasers of offensive-security capability, and a self-contained product like NodeZero fits procurement paths that favour contractor-grade tools. Qualcomm's involvement points to connected-device and edge networks as a growing attack surface.

Reading the numbers cautiously

The growth figures — 310,000 production tests without disruption, 120% year-on-year recurring revenue growth and 7,000 customers — come from Horizon3 itself. They support the story but do not by themselves justify a threefold valuation jump; investors are paying for the AI-vs-AI narrative as much as the current pipeline.

The blue-team loop is the unproven part

Horizon3's next step, autonomous remediation agents that rotate credentials and change configurations without human sign-off, is a much larger operational risk than automated testing. A well-meaning fix applied at scale could become an outage or widen an attack surface. The round funds that experiment, and the result will determine whether autonomous security becomes a standard enterprise tool or stays a faster audit.

Advertisement

What CISOs and Investors Should Take From This Round

For CISOs and security teams evaluating autonomous penetration testing:

  • Ask whether generative AI can write or fire exploits on your network. Horizon3's stated model keeps exploit execution deterministic and pre-validated — a guardrail you should demand from any vendor before live testing.
  • Compare continuous testing against your current annual audit. NodeZero's pitch is that it covers the full network all the time; validate that claim with a live pilot before committing to a multi-year contract.
  • Track the autonomous blue-team rollout. If agents begin rotating credentials and changing configurations without approval, require clear rollback and human-override procedures before enabling that feature.
  • For investors, the next signals are the same metrics Horizon3 already cites: recurring revenue growth, test volumes and customer counts in the new Singapore, Australia and Europe markets.

Risk & Opportunity Assessment

Commercial RiskMediumThe valuation tripled on company-reported growth metrics such as 310,000 tests and 120% recurring revenue growth, and demand could cool if competitors match the pitch or if AI containment fears recede.
Competitive RiskMediumNodeZero competes with established pentest firms and security-scanning vendors, while OpenAI and Anthropic's evolving safety work could shift customer priorities away from offensive AI tools.
Regulatory RiskMediumAutonomous attacking software running in live networks, plus planned self-directed remediation, will draw AI-safety and cybersecurity regulatory scrutiny, especially as Horizon3 expands into Singapore and Europe.
Reputation RiskMediumAny disruption from its autonomous tests, or from blue-team agents changing credentials and configurations on their own, would directly undercut the 310,000-tests-without-disruption claim and the core brand promise.
Technology DisruptionMediumThe planned autonomous blue-team loop, if proven safe, could change how enterprises run continuous security; until then, deterministic exploits paired with AI reasoning is an enhancement rather than a revolution.
Commercial OpportunityHighThe OpenAI and Anthropic containment disclosures validate the anxiety Horizon3 sells into, and strategic investors SAIC, Qualcomm and EDBI open defense, semiconductor and Asia-Pacific channels.