· investment-strategies · 3 min read
Horizon3's $250M Series E at $2B: Continuous AI Pentesting Goes Mainstream
Horizon3 raised $250M Series E at a $2B valuation as enterprises demand continuous, production-safe penetration testing — NodeZero’s ‘AI hackers’ vs annual human sampling.
Horizon3 raised a $250 million Series E at a $2 billion valuation on August 3, 2026, more than tripling its mark in ~14 months. Returning investors NightDragon and NEA led the capital story; strategics now include EDBI, SAIC, and Qualcomm.
Key facts
| Field | Detail |
|---|---|
| Company | Horizon3 (San Francisco) — NodeZero platform |
| Round | $250M Series E · $2B valuation |
| Date | August 3, 2026 |
| Key investors | NightDragon, NEA (+ strategics EDBI, SAIC, Qualcomm) |
| Traction | ~$100M ARR approach; ~120% YoY; ~7,200–7,300 customers |
| Claim | 310,000 production security tests, zero disruptions |
| Founders | Snehal Antani & Anthony Pillitiere (ex–Joint Special Operations Command) |
Who uses the product — and for what job
Users: CISOs, red/purple teams, and MSPs.
Job: continuously attack your own network the way a real adversary would — across the full estate — without scheduling an annual consulting circus that samples 2–5% of assets.
NodeZero’s differentiator in coverage: live production testing that does not require downtime, plus a shift from yearly to weekly/monthly evidence that risk is actually falling.
Customer mix spans SMB-via-MSP to Fortune 10 — important because offensive security usually dies in mid-market if it only sells to elite red teams.
Why now
- AI labs’ own model-behavior headlines made boards ask whether internal AI deployments create new blast radius.
- Attackers use AI to ship exploits faster than patch cycles.
- Buyers are moving from “compliance pentest checkbox” to continuous control validation.
Why these investors — portfolio fit
NightDragon (cyber specialist) and NEA (multi-stage tech) re-upping at Series E is a classic category-leader defense: keep ownership when ARR crosses the threshold where growth equity and strategics pile in.
Strategics tell you the ICP expands:
- SAIC → federal/defense buying motions
- Qualcomm → device/edge attack surface
- EDBI → APAC expansion (Amsterdam office already open June 2026; Australia/Singapore next)
Likely founder rationale: raise from cyber-fluent capital that has already diligence’d NodeZero’s safety model, then add strategics that open channels — not from a generalist AI fund that treats pentest as another “agent demo.”
Competitive map
| Player | Lane |
|---|---|
| Human pentest firms | Still win deep custom work; lose on coverage frequency |
| XBOW / AI offensive startups | Adjacent autonomous attack tooling |
| Vulnerability scanners (Qualys, Tenable, etc.) | Breadth of CVE finding; different from full exploit-path validation |
| In-house red teams | Talent-constrained; Horizon3 productizes repetition |
Hartley’s framing: the real competitor is the legacy annual testing model, not a single SaaS peer.
Market signal
$2B for continuous autonomous pentest with ~$100M ARR approach implies a ~20× ARR multiple ballpark — investors are paying for category ownership in AI-era offensive security, not a niche tool.
Practical takeaway
- Founders (security): Productize repeatable attacker loops with hard safety proofs (Horizon3’s “zero disruptions” claim is the sales unlock).
- Investors: Underwrite false-positive/safety risk as carefully as growth — one bad production incident resets the category.
- Operators: Replace “annual 5% sample” with a continuous program; keep humans for novel threat modeling.