Cybersecurity company Hadrian has raised $40 million in new funding as the security industry prepares for a fundamental change in the economics of hacking: artificial intelligence is making it possible to search for vulnerabilities, test defenses and potentially execute attacks at machine speed.
The investment was co-led by Forgepoint Capital International and SmartFin, with participation from existing investors HV Capital, Motive Partners, Picus Capital and Oetker Ventures. The round brings Hadrian’s total funding to approximately $65 million. The company plans to use the new capital to expand in the United States and Europe and increase investment in engineering and security research.
The bigger story, however, is not the size of the financing round. It is the problem Hadrian is attempting to solve. Generative AI and increasingly autonomous AI agents are reducing the amount of human work required to conduct cyber reconnaissance. Tasks that once demanded hours of manual investigation can increasingly be automated: identifying exposed infrastructure, examining software configurations, looking for known vulnerabilities, testing possible attack paths and prioritizing promising targets. AI does not eliminate the need for sophisticated attackers, at least not yet, but it can dramatically increase their productivity.
That creates an uncomfortable imbalance for corporate security teams. Attackers can operate continuously, while many traditional defensive processes remain periodic. A penetration test might be performed once or several times a year. Vulnerability scanners may operate much more frequently, but they can generate enormous lists of potential weaknesses without necessarily determining which ones can actually be exploited. Security teams are consequently faced with two problems at once: attacks are becoming faster while the amount of security information requiring human attention keeps growing.
Hadrian’s answer is essentially to automate part of the attacker’s job and put that capability in the hands of the defender. Instead of waiting for the next scheduled penetration test, its technology continuously examines an organization from an external attacker’s perspective. AI agents discover exposed assets, investigate potential vulnerabilities and attempt to determine whether those weaknesses provide meaningful paths into the organization.
The company has divided this approach between complementary systems. Atlas continuously maps an organization’s external attack surface and validates exposures, while Nova provides agentic penetration testing. Together they are intended to create a continuous loop between discovering something potentially vulnerable and testing whether it represents a genuine security problem.
This matters because finding a vulnerability is not the same thing as finding an exploitable vulnerability. Modern organizations can have thousands of internet-facing assets and potentially tens of thousands of vulnerability findings. Treating every alert as equally important is impossible. The more useful question is which weakness an attacker can actually exploit, what that weakness leads to and how urgently it needs to be fixed.
That is where autonomous offensive-security systems could become particularly valuable. Rather than merely generating another security alert, an AI system can potentially investigate the vulnerability, attempt exploitation within controlled limits, examine the resulting attack path and provide defenders with evidence that the problem is real. In other words, the industry could gradually move from vulnerability detection toward continuous exploitability testing.
There is also a larger technological shift taking place. Cybersecurity has traditionally been asymmetric in a way that favors attackers: defenders must protect an enormous environment while an attacker needs to find only one useful weakness. AI does not remove that asymmetry. In some respects it could make it worse. An autonomous agent does not need sleep, can investigate thousands of possibilities and can replicate techniques almost instantly once they have been discovered.
But the same economics apply to defense. An AI penetration-testing agent can also operate around the clock, repeatedly examining infrastructure as applications, cloud environments and configurations change. That creates the possibility of something that was previously prohibitively expensive: effectively keeping a permanent red team attacking an organization every day.
Hadrian is therefore competing in a market that could become considerably larger than conventional penetration testing. The potential category is continuous autonomous offensive security — software that behaves enough like a real attacker to discover the vulnerabilities that matter before a hostile attacker reaches them.
The company already lists major organizations among its customers, including McKesson, NBCUniversal, TotalEnergies, Amadeus, Leroy Merlin and Damen Shipyards. That is significant because autonomous penetration testing ultimately has to cross a substantial trust barrier. Companies are allowing software to behave aggressively toward their own production infrastructure. Reliability, safeguards and the ability to distinguish controlled testing from dangerous behavior are therefore just as important as the intelligence of the underlying AI.
Competition is also intensifying. Venture capital is moving rapidly into AI-native cybersecurity companies, including businesses developing autonomous penetration testing, attack-path discovery and AI security agents. The attraction is easy to understand. If offensive AI materially reduces the cost of attacking organizations, companies may have little choice but to automate more of their defenses. Human security teams cannot manually compete with millions of machine-generated probes.
That does not mean human penetration testers disappear. Their role is more likely to move upward. Humans remain particularly valuable for defining objectives, understanding business context, devising unconventional attack strategies and making judgments where automated exploitation would be dangerous. AI agents can take over much of the repetitive reconnaissance and testing underneath those decisions.
The $40 million Hadrian round consequently represents something larger than another cybersecurity financing announcement. It is another bet on the emergence of machine-speed cybersecurity, where both sides of the network are increasingly populated by autonomous agents.
For years, companies have talked about an arms race between attackers and defenders. AI is making that description considerably more literal. The attacker may increasingly be software. The penetration tester may increasingly be software too. And the competitive advantage may ultimately belong to whichever side finds the exploitable path first.