Horizon3 Raises $250M Series E at $2B Valuation as AI Cyberattacks Escalate
Horizon3, the San Francisco cybersecurity company behind the NodeZero autonomous penetration testing platform, has raised an oversubscribed US$250 million Series E at a valuation exceeding US$2 billion, co-led by returning investors NightDragon and NEA. The round more than triples the roughly US$650 million valuation the company carried after its Series D in June 2025 and brings total funding to about US$428.5 million. New investors include Acrew Capital, Blue Cloud Ventures, Demeter Group, PSG, Sapphire Ventures, defense contractor SAIC, and Singapore state investor EDBI, alongside returning backers Craft Ventures, Prosperity7 Ventures, Qualcomm Ventures, Ridge Ventures, and SignalFire. Dave DeWalt, founder and CEO of NightDragon and former chief executive of both FireEye and McAfee, joins the board along with NightDragon managing director Morgan Kyauk.
Horizon3 was founded by CEO Snehal Antani and Anthony Pillitiere, who met while serving at U.S. Joint Special Operations Command, where Antani was the organization's first chief technology officer after earlier roles at IBM, GE Capital, and Splunk. NodeZero conducts autonomous penetration tests against live production systems, chaining together misconfigurations, weak credentials, and identity gaps to map exploitable attack paths without taking systems offline. The company reports annual recurring revenue growth of 120% year over year, approaching US$100 million, with more than 7,000 customer organizations including four Fortune 10 enterprises, the NSA, and CISA, and says it has executed 310,000 tests in production environments. The capital will fund sales and channel expansion, new offices in Singapore and Australia, deeper presence across Europe, the Middle East and Africa, and development of autonomous defensive agents.
Market Context
The raise reflects how quickly capital is moving toward automated defense as attackers adopt the same tools. The global cybersecurity market was valued at roughly US$271.9 billion in 2025 and is projected to reach US$663.2 billion by 2033. Horizon3 has spent approximately US$100 million building what Antani describes as controllable, automated AI systems, and frames its advantage as accumulated operational data rather than model architecture. "Every single time our AI hacker runs a penetration test, it's collecting training data that literally nobody else has," Antani said.
The competitive field is crowded and expanding. Pentera has offered automated penetration testing to enterprises for years, Picus, AttackIQ, and SafeBreach compete in security control validation, and newer entrants such as XBOW apply large language models to offensive security. Horizon3 positions its primary competition not as those vendors but as the incumbent model itself: annual, human-led assessments that sample roughly 2% to 3% of an environment, against continuous testing across the full network. The valuation implies a multiple of roughly 20 times annual recurring revenue, a substantial premium over the single-digit to low-double-digit ranges typical of private software companies, reflecting both the growth rate and investor appetite for the AI security category.
The Signal
"Every single time our AI hacker runs a penetration test, it's collecting training data that literally nobody else has." — Snehal Antani, co-founder and CEO, Horizon3
Regional Relevance
For the United States: Operating from San Francisco, Horizon3 has built an unusually deep position inside American federal cybersecurity, holding FedRAMP High authorization and counting the NSA and CISA among its customers, with defense contractor SAIC now on the cap table. The founders' background at Joint Special Operations Command illustrates a well-worn Silicon Valley pathway in which military cyber expertise converts into commercial security products, and the round strengthens a domestically owned alternative at a moment when federal agencies are under pressure to defend against adversaries already using AI to accelerate attacks. For US enterprises, the shift being funded here is from annual compliance-driven testing toward continuous validation.
For Singapore and the Asia-Pacific region: The participation of EDBI, the corporate investment arm of Singapore's Economic Development Board, alongside plans for offices in Singapore and Australia, signals that the company's next growth phase runs through Asia-Pacific. For Singapore, backing a US cybersecurity firm that is establishing regional operations fits a long-running strategy of attracting advanced technology companies to anchor operations there, and gives the country's own institutions earlier access to autonomous security tooling as regional threat activity intensifies.
The Other Side
Is enterprise confidence in fully autonomous testing actually rising? Cobalt's June 2026 research found that confidence in fully autonomous AI penetration testing fell from 29% in 2025 to 9% in 2026, a 68% decline in a single year, and that 78% of companies had automated systems miss significant vulnerabilities. Practitioners increasingly describe the sustainable model as agent-augmented human testing rather than removing humans entirely, which sits somewhat awkwardly against a valuation premised on autonomy.
Does a data moat hold when the underlying models are commoditizing? Antani's thesis rests on proprietary test data rather than foundation models, but competitors including XBOW have posted strong results applying general-purpose language models to offensive security, and it remains unproven whether accumulated pentest telemetry compounds into a durable advantage or whether capability converges as models improve for everyone.
What are the implications of commercializing an autonomous attack engine? Security researchers have documented criminals adopting autonomous offensive AI agents to run attacks they lack the skill to execute manually, noting that the same reconnaissance and exploitation engines built for authorized testing can be pointed at real infrastructure. Horizon3's own claim of 310,000 production tests without disruption is company-reported and unaudited, and the broader proliferation question applies to the category rather than to any single vendor.
Sources & Transparency
- Tech Startups — Horizon3 raises $250M at $2B valuation as AI cyberattacks fuel cybersecurity demand
- BusinessWire — Horizon3 Raises $250M Series E at $2B+ Valuation to Lead the "AI vs. AI" Cybersecurity Era
- TechCrunch — Horizon3 hits $2 billion valuation with $250M Series E as AI threats escalate
- Forbes — Horizon3 Raises $250 Million As Cybersecurity's Next War Goes AI Vs. AI
- BetaNews — Horizon3 raises $250M Series E, valuation tops $2 billion
- Dark Reading — AI Decline? Confidence Falls in Autonomous Penetration Testing
- Security Affairs — Cybercriminals Are Leveraging Autonomous AI Offensive Security Agents