Hadrian raises $40M for agentic offensive security platform

Hadrian raises $40M for agentic offensive security platform

Hadrian, an offensive security company based in Amsterdam, has closed a $40 million Series B round. The startup says it will use the money to grow in EMEA and the US.

The company sells an AI-native platform that tests organizations the way attackers would. Its pitch is that if AI lets criminals find and exploit flaws at machine speed, defenders need tools that move just as fast.

Who is backing the round

Forgepoint Capital International and SmartFin co-led the Series B. Existing investors HV Capital, Motive Partners, Picus Capital and Oetker Ventures also took part.

The new round brings Hadrian's total funding to $65 million. Beyond geographic expansion, the company plans to put more money into its engineering and research teams.

Hadrian was founded in 2021 by two former ethical hackers, CEO Rogier Fischer and chief hacking officer Olivier Beg. Entrepreneur Maurice Clin, who heads business development, joined them as a co-founder.

Atlas and Nova

The platform covers four stages: discovery, validation, prioritization and remediation. It combines continuous exposure management with agentic penetration testing, meaning AI agents carry out testing tasks that would normally be done by human pentesters.

Two products handle the main work:

  • Atlas keeps a running map of an organization's external attack surface. AI agents then check which of the exposures it finds can actually be exploited.
  • Nova provides agentic pentesting on demand.

According to Hadrian, the system follows the attack paths a hacker would take, probes for exploitable routes into the organization, and verifies on its own whether a fix has worked.

Too many alerts, too few real risks

Hadrian frames its product as a response to an imbalance. Attackers have adopted AI, while many defenders still depend on manual testing.

"Attackers now move at machine speed, but many security teams are years behind, with data showing that 87% of organizations still run manual pentests," the company said.

Manual work also struggles with noise. Hadrian points out that only 0.47% of findings from vulnerability scanners are genuinely exploitable. By that measure, 99.5% of the alerts security teams spend time on require no action at all.

Fischer said the industry has been aiming AI at the wrong targets.

"Everyone can see that AI is changing the threat landscape. It might also hold the answer, but most people are focused on automating the wrong bits," he said. "We have been working with LLMs since before they went mainstream, and we know that AI can work much faster than any human offensive security team. So, we built a platform that emulates hackers' attack paths, helping our customers to understand their key risks and prioritize their security resources appropriately."

Claimed results

Hadrian says its customers have gained 10 times more visibility into critical risks. It also claims five times better return on investment compared with manual pentests and an 80% faster time to resolution. These figures come from the company and have not been independently verified.

The company stresses that people remain in charge. "Humans set the mission and make the decisions that matter, while AI does the work in between, providing the coverage, repetition and speed that no team can sustain around the clock," Hadrian said.

Our Take

Hadrian's round is part of a clear funding wave around autonomous offensive security. SecurityWeek's coverage lists several recent raises in the same niche, including A Security ($37 million), XBOW ($35 million), Escape ($18 million) and Tenzai ($75 million in seed funding). Earlier this month, Armadin raised $255.5 million for its AI agents. Investors appear convinced that pentesting is about to shift from periodic projects to continuous, machine-driven work.

The reasoning behind that shift is easy to follow. Microsoft recently warned that attackers lead defenders in the early AI race. We have also seen a flaw found by AI later exploited in the wild. If discovery and exploitation keep getting faster, an annual manual pentest leaves a long window in which new exposures go unchecked.

Still, readers should treat vendor metrics with care. Claims such as "10 times greater visibility" depend on how they are measured, and Hadrian has not published its method. The more useful point for security teams is the noise problem. If only a tiny share of scanner findings are exploitable, proving which ones matter may be worth more than finding even more issues.

It is worth watching whether these platforms can show results in independent tests, and how well they handle accuracy and safety when agents probe live production systems. As the market fills with similar offerings, consolidation also looks plausible.