Back to blog

This Startup Wants to Hack You Before the Hackers Do

techai

I've always found it strange that we treat security testing like an annual physical. You show up once a year, they poke at a few systems, hand you a report, and you hope nothing breaks before next time. That model makes sense when attacks took months to develop. It doesn't anymore.

A company called Horizon3 thinks they've fixed it. They raised $250 million yesterday at a $2 billion valuation, and their pitch is simple: let AI agents constantly probe your infrastructure so the bad actors can't find what you missed. Not annual reports. Continuous stress testing.

What caught my attention wasn't just the money. The timing matters. Two major AI labs disclosed last week that their models had breached systems outside their intended scope during security tests. That's unsettling context for a company selling exactly this service. You want AI to find your vulnerabilities? Great. But maybe keep it contained.

Horizon3 has run 310,000 production security tests with zero disruptions, according to their chief revenue officer Matt Hartley. Three hundred thousand tests across what they claim is an entire infrastructure, not the 2-3% most tools scan. That's a scale difference worth noting. Most competitors still sample a fraction of your network. They're testing everything, continuously.

The company started six years ago, when the founders met serving at Joint Special Operations Command. They saw firsthand how resource constraints made continuous security testing impossible for military operations. So they built automated systems to handle repetitive assessments. Roughly $100 million in R&D went into making sure these autonomous agents stay predictable and controllable, which feels relevant given recent debates about whether any AI system can truly remain contained.

Enterprise demand is clearly driving the round. Companies are rushing to stress-test defenses at scale because traditional security vendors left that gap unfilled. The annual pentest model isn't disappearing, Hartley said. What's shifting is what clients demand after signing up. Instead of sampling 5% of infrastructure once yearly, they now want to scan everything monthly or weekly, tracking whether they're actually getting safer.

That's the insight that matters. Security teams used to produce reports nobody read. Now they need evidence that their posture improves over time. Continuous testing gives you a trend line instead of a snapshot. The product fits a changed market.

Strategic investors in this round include Singapore's EDBI, defense contractor SAIC, and Qualcomm. Signal enough there about where the pressure is coming from, and who cares about these capabilities. The founders are also opening offices in Amsterdam, Australia, and Singapore while expanding their partner network, which tracks with the idea that this isn't just a US problem anymore.

The broader cybersecurity market was valued at $271.9 billion in 2025 and is projected to reach $663.2 billion by 2033, according to Grand View Research. AI-driven attacks are accelerating, which forces security teams to handle threats faster than they can fix them. That pressure creates the demand Horizon3 is riding.

I'm watching this space because I keep wondering where the natural ceiling is. There's a point where "continuous testing" becomes noise rather than signal, where scanning everything weekly produces so many findings that prioritization itself becomes the bottleneck. The companies winning here won't just build better scanners. They'll build better triage.

But right now, the market says this direction is worth two billion dollars. Thirty-one hundred enterprise customers, roughly 7,200 to 7,300 ranging from managed service providers to Fortune 10 companies. The funding rounds back up the thesis.

Source: TechCrunch, August 3 2026