Hadrian's Series B Fuels AI Pentesting Push
Hadrian raises $40 million to expand its AI offensive security platform and challenge the slow pace of manual pentesting.
Security teams face a hard math problem: attackers now use AI to find and exploit vulnerabilities at machine speed, while most defenders still rely on manual processes that were never built for that tempo. Hadrian, an Amsterdam-based offensive security firm, wants to close that gap with an agentic platform that automates discovery, validation, and prioritization. The company announced an additional $40 million in Series B funding to expand its reach and deepen its engineering and research efforts.
A $40 Million Bet on Speed
The new round was co-led by Forgepoint Capital International and SmartFin, with participation from existing investors HV Capital, Motive Partners, Picus Capital, and Oetker Ventures. This latest injection brings Hadrian's total funding to $65 million. According to the company, the capital will be used to fund expansion across EMEA and the US, and to deepen investment in its engineering and research teams.
Inside the Agentic Offensive Platform
Hadrian's platform is built around two core components: Atlas and Nova. Atlas continuously maps an organization's external attack surface and uses AI agents to validate which exposures are actually exploitable. Nova provides on-demand agentic penetration testing. Together, they aim to offer continuous exposure management combined with autonomous pentesting.
The firm was founded in 2021 by former ethical hackers Rogier Fischer (CEO) and Olivier Beg (chief hacking officer), along with entrepreneur Maurice Clin (head of business development). Their background in offensive security shapes the platform's approach: it emulates the attack paths that real hackers would take, rather than simply scanning for known vulnerabilities.
Hadrian positions its technology as a way to resolve what it describes as an imbalance in manual pentesting and adversarial probing, an imbalance worsened by attackers' increasing use of AI. The company says its agentic system probes for exploitable pathways at the same machine speed that today's AI-assisted attackers use, providing always-on discovery, validation, and mobilization of critical cyber risks, and autonomously verifying remediation.
Why Manual Pentesting Falls Short
The core problem, according to Hadrian, is one of scale and precision. Manual pentesting struggles to separate importance from noise when only 0.47% of vulnerability scanner findings are genuinely exploitable. That means 99.5% of the alerts teams focus on require no action. Meanwhile, the company says data shows that 87% of organizations still run manual pentests.
“Attackers now move at machine speed, but many security teams are years behind, with data showing that 87% of organizations still run manual pentests,” says Hadrian. The company argues that this gap leaves defenders reacting to alerts that mostly don't matter, while missing the small fraction that do.
How Hadrian Says AI Changes the Equation
Hadrian's pitch is not simply to automate scanning, but to automate the right parts of offensive security. The company says it has been working with large language models since before they went mainstream.
“Everyone can see that AI is changing the threat landscape. It might also hold the answer, but most people are focused on automating the wrong bits,” says Fischer. “We have been working with LLMs since before they went mainstream, and we know that AI can work much faster than any human offensive security team. So, we built a platform that emulates hackers’ attack paths, helping our customers to understand their key risks and prioritize their security resources appropriately.”
— Rogier Fischer, CEO at Hadrian
Customer Results and Human Oversight
Hadrian claims its customers have seen significant improvements after adopting the platform. According to the company, users have achieved 10 times greater visibility into critical risks, five times improved ROI over manual pentests, and an 80% faster time to resolution.
“Humans set the mission and make the decisions that matter, while AI does the work in between, providing the coverage, repetition and speed that no team can sustain around the clock,” says Hadrian. The company emphasizes that its system is designed to augment human judgment, not replace it, with AI handling the repetitive probing and validation that humans cannot sustain continuously.
Built by Hackers, for Defenders
Hadrian's founding team brings direct experience from the offensive side of security. Fischer and Beg were ethical hackers before starting the company, and that perspective is central to how the platform is designed. The company says its agentic system probes for exploitable pathways using the same machine speed harnessed by today's AI-assisted attackers.
The platform provides always-on discovery, validation, and mobilization of an organization's most critical cyber risks, and autonomously verifies remediation. This continuous cycle is meant to keep pace with attackers who don't take breaks and don't rely on scheduled assessments.
Funding Landscape for Offensive Security
Hadrian's raise is part of a broader wave of investment in autonomous offensive security and automated pentesting. Other recent funding rounds include A Security's $37 million raise for its autonomous offensive security platform, XBOW's $35 million round, Escape's $18 million to automate pentesting, and Tenzai's $75 million seed round to build an AI-powered pentesting platform.
What This Means for Security Teams
The gap between attacker speed and defender speed is not just a technical problem; it's a resource problem. If 87% of organizations still run manual pentests and 99.5% of scanner alerts are noise, then the vast majority of security teams are spending time on the wrong things. Hadrian's bet is that AI can flip that ratio by autonomously finding and validating the exploitable few.
For businesses, the implication is that the window between vulnerability discovery and exploitation may keep shrinking. Tools that promise continuous, automated validation could become a practical necessity rather than a luxury. But the effectiveness of any such platform depends on how well it separates signal from noise — a claim that Hadrian backs with its own customer metrics, which have not been independently verified.
For the industry, the influx of funding into autonomous offensive security suggests growing confidence that AI-driven pentesting can complement, and in some cases replace, manual efforts. Whether that translates into measurably better security postures across the board remains to be seen, but the direction of travel is clear: defenders are being asked to match machine speed with machine speed.
Sources
- SecurityWeek Original source
Continue Reading
CISO Data: Cyber Risk Moves Into Workflow
Five years of Voice of the CISO research show risk shifting from the perimeter to the flow of daily work, with AI governance and human risk at the center.
New SonicWall Flaw Hits VPN Gateways
SonicWall issued hotfixes for a maximum-severity SSRF bug in SMA1000 appliances, urging customers to upgrade before attackers take note.
Pwn2Own Ireland Day One Yields 32 Zero-Days
Researchers exploited 32 zero-days at Pwn2Own Ireland 2026, targeting phones, printers, smart home hubs and AI infrastructure for $388,500.