Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News Trending AI News

Horizon3 Raises $250M: The AI vs. AI Security Era Is Here

Horizon3's $2B valuation signals enterprises can no longer afford annual pentests. Continuous AI-powered security validation is the new baseline.

Enterprise DNA | | via TechCrunch
Horizon3 Raises $250M: The AI vs. AI Security Era Is Here

Cybersecurity firm Horizon3 closed a $250 million Series E round on August 3, 2026, pushing its valuation past $2 billion. That is a valuation that more than tripled in fourteen months, from $650 million at Series D. NightDragon and NEA co-led the oversubscribed round, with seven new investors and strategic backers including Singapore’s EDBI, defense contractor SAIC, and Qualcomm.

The company is growing at 120% year over year, approaching $100 million in annual recurring revenue, and protecting more than 7,200 organizations globally. The capital will fund international expansion into Amsterdam, Australia, and Singapore, plus an expanded partner network.

Numbers like these do not emerge from niche software markets. They emerge from a real shift in how enterprises think about risk.

What Horizon3 Actually Does

Horizon3 builds NodeZero, an autonomous penetration testing platform. Instead of scheduling a human-led pentest once a year, NodeZero runs continuously inside live production environments, probing networks the way an attacker would, safely, at scale, without disrupting operations.

The platform does not just flag vulnerabilities. It strings them together into attack paths, showing security teams not just where a hole exists but how a real adversary would chain five smaller holes together to reach a crown jewel. Banks, hospitals, and Fortune 10 enterprises are customers. So are managed service providers serving small businesses.

The timing matters. Horizon3 has spent six years building autonomous security testing. That work lands right when the threat environment crossed a threshold that made the old model structurally inadequate.

Why the Annual Pentest Is Dead

The attack surface for most organizations has grown faster than their security teams. Cloud, SaaS, remote work, and now AI-integrated workflows have multiplied the number of systems, APIs, and permissions that need to be checked. An annual third-party pentest was already a snapshot taken eleven months before anyone looked at it again.

AI-driven attacks changed the math entirely. Attackers are now using AI to automate reconnaissance, generate novel exploits, and probe defenses at machine speed. A scheduled test that runs twice a year cannot keep pace with attacks that adapt daily.

The shift Horizon3 is betting on is this: security validation needs to match the cadence of the threat, not the cadence of the budget cycle. Continuous, autonomous testing is not a premium feature. It is the new baseline.

That position is gaining institutional validation. IBM’s security operations now run AI systems handling 95% of daily investigations. Google’s AI agents are patching over 100 critical vulnerabilities. Microsoft launched Project Perception, its own agentic security platform, earlier this week. The enterprise security market is reorganizing around AI-driven defense.

The AI vs. AI Dynamic

The phrase “AI vs. AI” is not marketing. It describes a real operational reality that enterprise leaders need to understand before they build their next AI workflow.

AI-powered attacks do not send obvious signals. They move slowly, blend into normal traffic patterns, and chain together permissions that individually look harmless. Human analysts reviewing logs after the fact cannot catch most of them in time.

What can catch them is a system that thinks like an attacker, runs continuously, and generates findings that security teams can act on the same day. That is the market Horizon3 is in, and the scale of this funding round tells you that the market is real.

Qualcomm and SAIC joining the round as strategic investors is a signal worth noting. Their presence suggests this technology is moving into hardware, embedded systems, and defense infrastructure, not just enterprise IT.

What This Means for Business

If your organization is deploying AI agents, integrating with AI-powered SaaS tools, or building internal workflows that touch sensitive data, your attack surface has changed. The question is whether your security program has changed with it.

A few practical implications:

Continuous beats periodic. If your security validation still runs on an annual or quarterly cycle, you are operating blind for most of the year. AI-driven threats do not wait for your next scheduled audit.

Autonomous tools reduce the talent bottleneck. Security talent is scarce. Platforms like NodeZero are designed to let smaller teams catch what larger ones used to miss, by running constantly instead of occasionally.

Agentic AI deployments need their own security model. AI agents that access data, run code, and make API calls introduce attack vectors that traditional security tools were not designed to find. Autonomous security validation tools that understand agentic behavior are becoming a requirement, not an option.

The market is consolidating fast. Horizon3 is at $2 billion with 120% growth. Microsoft, CrowdStrike, and Google are all moving into autonomous security. Organizations that build their security program around vendors in this space now will be better positioned than those that wait another cycle.

The Horizon3 raise is a data point about the market. But the underlying trend it reflects, the move from scheduled human-led security to continuous AI-driven validation, is one that every enterprise team deploying AI needs to understand now.

The “AI vs. AI” era is not coming. It arrived.


Enterprise DNA helps business leaders understand how to deploy AI responsibly across their operations. If your team is building AI workflows and wants to understand the governance and security questions that come with them, start with a discovery call.