Horizon3 has raised $250 million in fresh funding at a valuation of more than $2 billion, more than tripling what the cybersecurity company was worth just over a year ago as businesses race to defend their networks against a new generation of AI-assisted attacks.

NightDragon and NEA co-led the round, Horizon3 said Monday. Acrew Capital, Blue Cloud Ventures and Demeter Group joined as new investors, alongside returning backers Craft Ventures, Prosperity7 Ventures, Qualcomm Ventures, Ridge Ventures and SignalFire.

The jump in valuation is hard to miss. Horizon3 was valued at $650 million when it raised its Series D in June last year. Its latest round pushes that figure past $2 billion, marking a more than threefold increase in roughly a year.

The funding arrives at a moment when artificial intelligence is changing the economics of cyberattacks. Attackers can use AI to search for weaknesses, generate malicious code and automate parts of an intrusion that once required more manual work. Security companies are responding with their own autonomous systems, creating an increasingly machine-versus-machine contest inside corporate networks.

Horizon3 is betting that companies will want to find those weaknesses before attackers do.

“We invented the concept of AI Hackers and spent six years earning the right to autonomously pentest the most critical and sensitive networks in the world — with no humans in the loop,” said Snehal Antani, Co-Founder and CEO of Horizon3. “Our massive data moat – built on 310,000 tests safely executed in production – combined with thousands of radical champions who love our product, has allowed us to achieve consistent top-tier financial and operational metrics. This round gives us the fuel to scale aggressively as the definitive leader of the AI vs. AI era.”

NodeZero turns penetration testing into a continuous process

At the center of Horizon3’s business is NodeZero, an autonomous penetration-testing platform that attacks a customer’s environment much like a real adversary would.

Traditional penetration tests often involve security professionals manually probing corporate systems during scheduled assessments. NodeZero takes a different approach. The platform autonomously searches production environments for attack paths that could actually be exploited, shows customers how those weaknesses can be fixed, and then verifies whether the fixes worked.

That distinction matters. Security teams routinely face thousands of vulnerability alerts, yet a vulnerability existing on a network does not necessarily mean an attacker can turn it into a successful compromise.

Horizon3’s approach focuses on proving which weaknesses can be exploited and how multiple weaknesses can be chained together to reach sensitive systems.

The company has accumulated a substantial amount of real-world testing data in the process. CEO and co-founder Snehal Antani said Horizon3 has gathered data from 310,000 penetration tests safely conducted against live systems.

That dataset could become increasingly valuable as Horizon3 puts more AI into both sides of the cybersecurity equation.

Horizon3 wants AI attackers testing AI defenders

The company’s next bet goes beyond automated penetration testing.

Horizon3 plans to create a continuous learning loop connecting AI systems that simulate attacks with AI systems responsible for defense. One system searches for a way in. Another attempts to close the opening. The attack system can then test whether the defense actually worked.

The company is developing automated defensive agents capable of fixing problems uncovered by NodeZero penetration tests.

That creates a potentially different security cycle from the familiar process of discovering a vulnerability, creating a ticket, assigning it to an employee, deploying a fix and scheduling another test.

Horizon3 is pushing toward a model where discovery, remediation and verification can happen with far less human intervention.

The idea comes as security teams confront a growing asymmetry. Attackers increasingly have access to AI systems that can automate reconnaissance and other parts of an attack. Defenders, meanwhile, still rely heavily on alerts, dashboards and human analysts to decide what deserves attention.

Autonomous penetration testing gives defenders a way to continuously ask a much more practical question: Can someone actually break into this system right now?

A $2 billion cybersecurity bet

Investors are putting serious money behind that thesis.

The $250 million round gives Horizon3 fresh capital to grow its sales, marketing and channel operations and push into new markets. The company plans to enter Singapore and Australia and increase its presence across Europe, the Middle East and Africa.

Part of the funding will go into product development, including Horizon3’s work on autonomous defensive agents.

NightDragon founder and CEO Dave DeWalt and managing director Morgan Kyauk will join Horizon3’s board following the investment.

For NightDragon, the deal puts the firm behind a company sitting at the intersection of two major security trends: automated penetration testing and AI-driven cyber defense.

For Horizon3, the financing provides something else: time and capital to turn NodeZero from an automated testing product into a broader autonomous security platform.

Cybersecurity is becoming a battle of machines

Horizon3’s funding reflects a bigger change underway across the security industry.

AI lowers the amount of time and technical work required to perform certain cyber operations. Tasks that once consumed hours of an attacker’s time can increasingly be automated or accelerated by models capable of writing code, analyzing systems and processing large amounts of technical information.

That same capability can work in reverse.

Security software can search continuously for exploitable weaknesses, attempt controlled attacks against corporate infrastructure, recommend fixes, and test those fixes after deployment. The result is a feedback loop where machines increasingly participate on both sides of the attack-defense cycle.

Horizon3’s 310,000 tests give the company a large collection of data showing how real systems fail under simulated attack. The question now is how effectively that history can be turned into better automated defense.

There is plenty of competition for that opportunity. Cybersecurity vendors across vulnerability management, endpoint protection, cloud security and threat detection are adding AI agents and greater automation to their products.

Horizon3 has a straightforward pitch in that crowded market: don’t judge security by how many vulnerabilities a scanner finds. Test whether an attacker can actually exploit them.

Investors appear convinced that idea can support a much larger company.

A year ago, Horizon3 was worth $650 million. After its latest $250 million raise, the company is valued at more than $2 billion.

The bigger test comes next: whether autonomous security can move from finding the door an attacker might enter through to closing it before anyone gets inside.