Horizon3 has raised a $250 million Series E at a valuation of more than $2 billion, giving the cybersecurity company fresh capital to expand its NodeZero autonomous security platform. The round, announced on August 3, was co-led by existing investors NightDragon and NEA.
The financing more than triples Horizon3’s valuation from the $650 million figure attached to its Series D just over a year ago. Beyond the headline number, the round signals growing investor confidence in a shift from occasional penetration tests toward software that continuously checks whether an organization’s defenses work against real attack paths.
Why Investors Are Backing Continuous Security Validation
Horizon3’s NodeZero platform conducts authorized attacks against a customer’s own production environment. It looks for combinations of weaknesses, such as misconfigurations, exposed credentials, and identity gaps, that can be chained into a practical route to compromise. The platform then provides remediation guidance and can test again to confirm whether a fix closed the path.
That approach is different from a vulnerability scanner that mainly produces a list of possible weaknesses. It is also intended to supplement the point-in-time view delivered by a conventional annual penetration test. The investment case is that changing cloud environments, identities and applications create new attack paths faster than periodic testing can measure them.
NightDragon described that transition as a move from layered defenses that organizations hope will hold to security that continuously tests and adapts. The investor’s position is naturally promotional, but it explains why a late-stage funding round is being directed at autonomous validation rather than another alerting product.
What Horizon3 Plans to Do With the $250 Million
Horizon3 says it will use the capital across three areas, scaling sales, marketing and channel operations; expanding internationally; and accelerating product development. Its geographic plans include entering Singapore and Australia while strengthening its presence across Europe, the Middle East and Africa.
The company also plans to develop autonomous blue-team agents that can act on findings from NodeZero tests. If that roadmap works as intended, NodeZero would move beyond finding and verifying exploitable paths toward a tighter loop in which offensive testing informs defensive remediation.
That direction places Horizon3 within a broader market for agentic security systems. A separate InfoSeely analysis of Microsoft’s AI security system points to the same market shift from another direction: vendors are connecting vulnerability discovery, risk assessment and defensive action within a single coordinated process. The products are not interchangeable, but both reflect an effort to connect detection, prioritization and corrective action.
Horizon3 said the oversubscribed round also included new investors Acrew Capital, Blue Cloud Ventures, Demeter Group, Singapore’s EDBI, PSG, SAIC and Sapphire Ventures. Returning backers include Craft Ventures, Prosperity7 Ventures, Qualcomm Ventures, Ridge Ventures and SignalFire. NightDragon executives Dave DeWalt and Morgan Kyauk will join Horizon3’s board.
The Growth Figures Need Clear Attribution
Horizon3 says NodeZero has completed 310,000 tests in production and that the company now serves more than 7,000 organizations. It also reports 120% year-over-year growth in annual recurring revenue. TechCrunch separately reported, citing Horizon3 chief revenue officer Matt Hartley, that annual recurring revenue approached $100 million last year and that the platform had recorded zero disruptions across those production tests.
Those numbers suggest rapid expansion, but they remain company-supplied metrics. Horizon3 has not published an independent customer-performance audit that would allow readers to verify the zero disruptions claim, retention, expansion revenue, or the effectiveness of NodeZero across different environments.
The $2 billion-plus figure is the price attached to Horizon3 in this private financing round, not an audited measure of its operating performance. It shows what participating investors were willing to pay under the deal’s terms, but does not establish profitability, market leadership or future returns.
Production Safety Is Part of the Product
Autonomous penetration testing has an unusual trust requirement: the software must behave like an attacker while remaining inside an approved scope and avoiding operational damage. That makes permissions, network boundaries, audit logs, and stop controls part of the product’s value, not secondary administrative features.
Recent Claude cyber evaluation incidents offer a useful warning about those boundaries. The disclosed events were not evidence that a model escaped a sealed system; the evaluation environment retained paths to the public internet. The lesson for any autonomous security tool is that a written instruction cannot replace technically enforced scope, monitoring, and containment.
Horizon3’s production-test history is therefore central to its pitch. It is also the area where customers should conduct the most careful due diligence. Security teams need to understand what systems are in scope, which actions NodeZero can take, how an operation can be stopped, what evidence is retained and how the vendor handles an unexpected result.
What the Series E Does Not Prove
The round does not mean autonomous tools will eliminate human penetration testers. Human specialists remain important for unusual business logic, physical or social attack paths, creative adversarial work, and independent review. Automated validation is most useful when it increases testing frequency and helps teams prioritize exploitable problems between deeper assessments.
The announcement also leaves several business details open. Horizon3 disclosed broad spending priorities but not a detailed capital allocation, product release dates, pricing changes, or the financing split between primary and secondary shares.
The next measure of this investment will be execution rather than valuation. Horizon3 will need to show that it can expand internationally, preserve safety as testing volume grows, and turn its planned attacker-defender learning loop into reliable remediation outcomes.





