🌏 中文版
Deal Terms
| Item | Value |
|---|---|
| Company | Hadrian (Amsterdam, Netherlands) |
| Round | Series B |
| Amount | $40M |
| Lead | Forgepoint Capital International, SmartFin |
| Participants | HV Capital, Motive Partners, Picus Capital, Oetker Ventures |
| Valuation | Undisclosed (the official press release does not state this round's valuation) |
| Total raised | $65M |
| Founded | 2021 |
| Headcount | 80+ (per Forgepoint's blog, spanning its Amsterdam HQ plus US and UK offices) |
What the Company Does
Hadrian builds agentic attack-surface testing — it replaces work enterprise security teams used to outsource to human pentesting firms with AI agents running continuously, around the clock.
The product has two parts: Atlas continuously maps an organization's external digital footprint and uses AI agents to validate which exposed assets are actually exploitable, while Nova is on-demand agentic pentesting at a level matching or exceeding manual testing. Both products share the same context, so security teams can move from "always-on visibility" straight into "deep testing" without starting over each time. The company cites its own data: only 0.47% of findings from vulnerability scanners turn out to be genuinely exploitable — meaning 99.5% of the alerts teams normally stare at need no action. Cutting that noise down is Hadrian's core pitch.
Customers include Fortune 500 and multinational names such as McKesson, NBC Universal, Francisco Partners, Total Energies, Amadeus, Leroy Merlin, and Damen Shipyard. Co-founders Rogier Fischer and Olivier Beg have worked together as white-hat hackers since meeting on a forum at age 13; Fischer previously founded and exited LiteBit, one of Europe's earliest crypto exchanges. The two co-founded Hadrian with Maurice Clin in 2021.
What This Round Signals
What It Means for the Agent Ecosystem
The timing here matters: the press release directly cites Anthropic's recent disclosure that criminal and state-linked groups have used its models to automate entire attack chains and write zero-day exploits — security attacks have formally entered machine-speed territory. Hadrian's positioning is agent-against-agent: humans set the mission and make the final calls, while AI handles the scanning, validation, and repetitive testing in between. That means the security-agent category is evolving from "augmenting human analysts" into "matching agent speed with agent speed," with both attackers and defenders ratcheting up automation in lockstep.
What Investors Are Betting On
Lead investors Forgepoint and SmartFin aren't betting on novel technology — they're betting on commercial validation. Hadrian has already won head-to-head technical evaluations against both legacy security incumbents and other AI-native entrants, with growing enterprise contract values and retention rates. SmartFin partner Saumitra Dubey's comment points straight at the goal: turning Hadrian into a "nine-figure revenue" global cybersecurity leader. This isn't a bet on a concept — it's a bet on whether a company that already has paying Fortune 500 customers can scale.
Numbers Worth Watching
- Customer data shows only 0.47% of vulnerability-scanner alerts are genuinely exploitable — i.e., 99.5% is noise — which explains why "continuous validation" is worth more than "more scanning"
- 87% of enterprise security teams still rely on manual pentesting today (per Hadrian's own benchmark report), suggesting this market's automation penetration is still low with significant room to grow
- This $40M round pushes total funding to $65M; compared to peers in the same category like Zenity ($38M Series B plus $27M Series C), Hadrian's single round is larger, suggesting round sizes in the security-agent category are trending up
Watchlist Status
Hadrian is not currently on the watchlist. Recommend adding it to section B7 (Agent Security/Governance/Security Tech), alongside Zenity, Onyx Security, Cyera, and HiddenLayer — tracking point: Hadrian's focus on "attack-surface testing" is a different entry point than Zenity/Onyx's focus on "agent runtime monitoring" within the security-agent category, worth comparing which business model scales first.
Today's Takeaway
Cybersecurity's old narrative was "use AI to save human analysts time." Hadrian, read alongside the Anthropic threat report it cites, tells a different story: attackers have already automated the entire attack chain, so a defense that's still stuck at "AI-assisted humans" is guaranteed to fall behind on speed. This round is really defenders admitting that fighting an agent-speed war requires agent-speed weapons first.
References
Loading...