Hadrian Raises $40M for Agentic Offensive Security
A vulnerability alert becomes useful when a security team knows whether an attacker can turn it into a path. Hadrian raised $40M in a funding round co-led by Forgepoint Capital International and SmartFin, with existing investors HV Capital, Motive Partners, Picus Capital, and Oetker Ventures participating. The Amsterdam cybersecurity company says the financing brings its total raised to $65M.
The capital will support expansion across EMEA and the United States while Hadrian invests further in engineering and research. The larger bet is that offensive security is moving away from periodic projects and toward continuous systems that can discover an exposed asset, test whether it creates a real attack path, and verify whether remediation actually closed it.
What Happened
Hadrian announced the round on October 6, 2026, without disclosing a formal series label, valuation, or revenue. The company described the financing as support for its next stage of growth, while independent reporting characterized the money as expansion capital. Forgepoint Capital International and SmartFin joined as co-leads, and every other named participant was an existing investor.
Hadrian was founded in Amsterdam in 2021 by Rogier Fischer, Olivier Beg, and Maurice Clin. Fischer serves as CEO, Beg as Chief Hacking Officer, and Clin as Chief Business Development Officer. Hadrian's current leadership page also lists Prash Somaiya as CTO. Fischer and Beg met in an online forum when they were 13 and learned offensive security as white-hat hackers before turning that judgment into a company.
The financing follows a €2.5M pre-seed round announced in November 2021 and a €10.5M seed round announced in June 2022. ABN AMRO Ventures disclosed a later investment without naming the amount. Hadrian's $65M total therefore includes capital beyond the 2 early euro-denominated rounds, but the company has not published enough detail to reconstruct every step safely.
From Finding Exposure to Proving Risk
Enterprise security teams already have vulnerability scanners, asset inventories, alerts, and annual penetration tests. The operating problem is deciding which finding can become an attack path before a person spends time chasing it, the environment changes, or an attacker gets there first. Discovery creates a list. Validation creates a decision.
Hadrian's platform combines Atlas and Nova around that distinction. Atlas continuously maps an organization's internet-facing assets and uses purpose-built agents to validate which exposures are exploitable. Nova performs deeper, scoped agentic penetration testing on demand, retaining the context needed to explore attack paths and produce evidence for security teams.
The products share context, allowing an exposure discovered during continuous monitoring to inform a deeper test without restarting the investigation. Hadrian's design keeps humans responsible for the mission and consequential decisions while software handles repetitive exploration and validation. That boundary matters because an autonomous security tool has to be aggressive enough to think like an attacker and controlled enough to remain safe inside a customer's operating environment.
Why the Round Matters
Hadrian says more than 300 enterprises use its platform worldwide. Its announced customers include McKesson, NBCUniversal, Francisco Partners, TotalEnergies, Amadeus, Leroy Merlin, and Damen Shipyards. The company reports 10x greater visibility into critical exposures, 80% faster remediation, and 5x ROI compared with manual penetration testing. Those are company-reported outcomes rather than independently audited results, but they clarify the commercial pitch: reduce the volume of findings competing for attention and attach proof to the risks that remain.
The $40M gives Hadrian more capacity to turn that pitch into engineering, research, and distribution. Expansion across EMEA and the United States will put the company in more enterprise buying cycles where exposure management, vulnerability validation, breach-and-attack simulation, and penetration testing increasingly overlap. Buyers will compare whether vendors merely automate familiar scans or improve the quality and speed of the remediation decision.
Forgepoint Capital International's investment thesis centers on that convergence. The firm argues that security teams need continuous validation because AI can accelerate reconnaissance, vulnerability discovery, and attack-chain execution. SmartFin points to Hadrian's enterprise contract growth and retention as evidence that the platform can compete with larger incumbents, though those commercial metrics were not disclosed publicly.
The Market Is Collapsing Separate Tools Into One Loop
Offensive security has traditionally been divided by cadence and product category. Attack-surface tools watch from the outside, vulnerability tools enumerate weaknesses, penetration testers investigate selected targets, and remediation teams work through tickets. That separation becomes harder to defend when software can move across the sequence continuously and preserve evidence between stages.
Hadrian is positioning Atlas and Nova as one loop: discover, validate, investigate, remediate, and retest. Competitors including Horizon3 and XBOW are also raising substantial capital around autonomous security testing, while established security vendors are expanding exposure-management portfolios. The category is being shaped by how much useful autonomy a vendor can provide without creating new operational risk or flooding teams with machine-generated noise.
Hadrian's founder history gives the company a coherent starting point. Fischer and Beg learned that offensive security depends on persistence, context, and deciding where to look next, not simply running another tool. The current product thesis is that those choices can be encoded into agents while people retain control over objectives and boundaries.
What to Watch Next
The new capital creates room for Hadrian to deepen the research behind its agents, hire more technical talent, and build commercial reach in the United States and EMEA. The strongest proof will come from whether enterprises expand the platform from a discovery tool into an operating layer for continuous validation and whether customer-reported improvements hold across larger and more regulated environments.
Hadrian is entering that test with verified customers, a clear product architecture, and investors willing to fund expansion. The work now moves from showing that agents can find and exploit a path to proving that security teams can trust the evidence, fix the right exposure, and watch the system return to confirm that the path stayed closed.
Cybersecurity funding, last 30 days
DevCuration's funding database tracked 6 Cybersecurity rounds totaling $335.8M in disclosed capital over the past 30 days. Recent deals we covered:
- RemoteThreat Discloses $7M for Offensive Cyber Operations$7M · Sep 29
- StrikeReady Reaches $29M for Saudi AI SOC ExpansionUndisclosed · Sep 18
- MIND Raises $72M to Rebuild DLP for the AI Agent EraSeries B · $72M · Sep 17
- Eve Security Raises $4.5M for Runtime AI GovernanceSeed Extension · $4.5M · Sep 15
- HelmGuard Raises $7.3M to Build AI Risk AssuranceSeed · $7.3M · Sep 9
Frequently Asked Questions
Why does Hadrian's $40M funding round matter for enterprise cybersecurity?
The round funds Hadrian's attempt to combine continuous exposure discovery with deeper agentic penetration testing in one operating loop. For security teams, the value is not another inventory of possible weaknesses but faster evidence about which exposures are exploitable and whether remediation closed them.
What do Hadrian's Atlas and Nova products do?
Atlas continuously maps an organization's internet-facing attack surface and validates exploitable exposures. Nova performs deeper, scoped agentic penetration testing on demand, using shared context so teams can investigate high-risk targets without restarting from zero.
Who led Hadrian's latest funding round?
Forgepoint Capital International and SmartFin co-led the $40M round. Existing investors HV Capital, Motive Partners, Picus Capital, and Oetker Ventures also participated.
How will Hadrian use the new funding?
Hadrian says it will expand across EMEA and the United States while investing further in engineering and research. The company did not disclose a formal round series, valuation, or revenue.
What should security buyers watch as Hadrian scales?
Buyers should watch whether Hadrian's agents consistently distinguish exploitable attack paths from scanner noise, preserve evidence that remediation teams can use, and retest fixes safely across larger and more regulated environments. Hadrian's performance metrics are company reported, so broader independent validation will matter.
Where the Money Moved
The intelligence briefing of the innovation economy. Funding, M&A, debt and fund closes, read as market signal rather than deal announcements.
Subscribe to Where the Money Moved