Horizon3 Raised $250 Million to Let AI Hackers Fight AI Hackers

Horizon3 raised $250M at a $2B+ valuation to make AI hackers fight AI hackers. The market is real; the capital furnace is also.

Share
SiliconSnark robot watches AI hackers and defenders battle across an enterprise security console.

Somewhere, a chief information security officer is staring at a dashboard full of red dots while an AI agent asks for permission to access production. The CISO says no. The attacker says nothing, because attackers have never been famous for respecting calendar holds.

That is the world Horizon3 is trying to monetize. The cybersecurity company behind NodeZero announced a $250 million Series E at a valuation above $2 billion on August 3, with the round co-led by existing investors NightDragon and NEA. Seven new investors joined, five existing backers returned, and the company says its valuation has tripled from $650 million in a little over a year.

This is not a tiny startup discovering that “AI” makes a nice noun. Horizon3 says NodeZero has run 310,000 production-safe tests and now protects more than 7,000 organizations, including multinational banks, major healthcare networks, four Fortune 10 companies, and government customers. Its annual recurring revenue grew 120% year over year, according to the company.

The pitch is simple enough to fit on a mug: let an AI hacker attack your systems before someone else’s AI hacker does. The business model is more complicated, naturally, because the enterprise software industry will happily spend $250 million making a simple idea pass a procurement review.

The AI hacker has entered the compliance meeting

NodeZero is an autonomous penetration-testing platform. In ordinary language, it safely probes a company’s production environment, chains together misconfigurations, weak credentials, and identity gaps, then shows how an attacker could reach something valuable. It supplies remediation guidance and retests the environment to verify that the fix worked.

That last part matters. Security teams do not need another list of theoretical vulnerabilities. They already have enough lists to wallpaper a medium-sized airport. The useful question is which weakness can actually become an attack path, and whether closing it changed anything.

Horizon3’s “hack, fix, verify” loop is strategically coherent because it makes the tool operational instead of decorative. It gives a security team a way to prioritize what to fix, and gives a CIO something more persuasive than a colorful pie chart when the board asks whether the security budget is accomplishing anything.

It also sits in the same uncomfortable neighborhood as Neo’s $100 million bet on putting a bouncer on AI agents. Neo wants to govern what software can do. Horizon3 wants to demonstrate what an attacker can do. Together they describe the next phase of enterprise AI: not just generating text, but acquiring permissions, making tool calls, and requiring adults in the room.

“AI versus AI” is a slogan with a decent threat model

Horizon3 calls the emerging conflict “AI vs. AI,” which is exactly the kind of phrase that makes a funding announcement sound like a movie trailer. It is also not entirely silly. Generative AI has lowered the cost of reconnaissance, code analysis, vulnerability research, and social engineering. Defenders need faster ways to test systems and identify exploitable weaknesses before an automated adversary finds them.

The company says NodeZero can also deploy honeypots while testing, creating decoy systems that help detect AI attackers and prove when they are inside. That is a neat convergence of offense and defense: the system tries to break the environment, learns where the dangerous paths are, and leaves a few fake doors open with cameras pointed at them.

There is real technical difficulty here. An autonomous system operating against production infrastructure has to be aggressive enough to find meaningful attack paths and constrained enough not to become the incident. It must understand identity, cloud permissions, networks, applications, and business context. It must also produce evidence a human can trust, because “the model felt suspicious about your Kubernetes cluster” will not survive a regulated-industry audit.

That is why the company’s reported customer base and regulatory posture matter more than the superhero branding. Horizon3 says it is FedRAMP High authorized and supports requirements including DORA, NIS 2, NIST CSF 2.0, HIPAA, SOC 2, and GDPR. Compliance badges are not the same thing as security, but they are often the price of admission to the rooms where security gets purchased.

The $250 million will buy a lot of international paperwork

Horizon3 plans to spend the money on aggressive go-to-market expansion, international growth in Singapore and Australia, deeper EMEA operations, and a product roadmap that includes autonomous blue-team agents capable of remediating findings directly from NodeZero tests.

That use of proceeds is refreshingly legible. There is no vague “reimagining the future of trust” paragraph here. The company wants more sales capacity, more countries, and more automation in the loop. This is late-stage money behaving like late-stage money.

It is also a lot of money to pour into a category already crowded with vulnerability management, breach-and-attack simulation, exposure management, endpoint security, cloud security, identity security, and enough overlapping dashboards to make the average CISO consider a career in artisanal bread.

The risk is not that the product is fake. The risk is that the category becomes a budget knife fight disguised as platform consolidation. Every security vendor wants to own the control plane. Every buyer wants fewer tools. Every tool wants to become the one tool that all the other tools feed. This is how a sensible product category acquires 19 integrations, four acronyms, and a slide titled “flywheel.”

We have seen the same tension in White Circle’s attempt to chaperone AI models: the underlying need is real, but the market is fond of promoting every layer of the stack to “the missing control layer.” Horizon3 has a stronger claim because it is selling a concrete action—attack, observe, fix, verify—rather than merely asking customers to feel safer near an AI.

Security is the rare market where paranoia has a budget

NightDragon’s participation is not random. Its founder and CEO, former FireEye and McAfee chief Dave DeWalt, is joining Horizon3’s board alongside NightDragon managing director Morgan Kyauk. The investor syndicate also includes Acrew Capital, Blue Cloud Ventures, Demeter Group, EDBI, PSG, SAIC, Sapphire Ventures, Craft Ventures, Prosperity7 Ventures, Qualcomm Ventures, Ridge Ventures, and SignalFire.

That is an impressively large cast for a company whose product is, at heart, a very sophisticated way of asking whether the doors are locked. But cybersecurity has a structural advantage over most software categories: the consequence of being wrong is vivid, expensive, and frequently explained by a regulator with a deadline.

Horizon3 is also benefiting from a timely shift in the threat model. Security teams are not preparing only for human criminals with laptops anymore. They are preparing for software that can scan faster, generate convincing messages, adapt its tactics, and exploit the same automation enterprises are rushing to deploy. The defensive product does not need to be magical. It needs to be faster, safer, and more useful than the quarterly penetration test that produces a PDF nobody reads until the audit.

That is a solid wedge. It is less glamorous than “AI defense,” but wedges are how infrastructure companies become institutions. For a nearby reminder of what happens when security turns into a visible physical system, revisit Verkada’s $200 million surveillance expansion. The cameras are easier to see. The attack paths are harder to explain. Both categories still have to answer the same question: what exactly gets safer after the budget is approved?

Verdict: a serious breakout with a capital furnace attached

Horizon3 looks like a serious breakout, assuming its customer and growth claims hold up outside the press-release environment. The product addresses a real bottleneck, the timing is excellent, and the “find exploitable risk, fix it, verify the fix” workflow is much more compelling than another AI security assistant that summarizes alerts in a soothing tone.

But $250 million and a $2 billion valuation create their own attack surface. Now Horizon3 has to expand internationally, sell into slow and regulated buyers, maintain production safety, build remediation agents that do not become autonomous chaos, and grow fast enough to justify a valuation that tripled before most of us finished updating our password managers.

My verdict is therefore affectionate and conditional: Horizon3 is not merely a capital furnace with good branding. It is a real security company with a credible technical wedge. It is also now a private-market institution with a burn rate large enough to require its own threat model. The AI hacker may be ready for the enterprise. The enterprise, as ever, would like the AI hacker to complete a vendor questionnaire first.