AI Frontier Post
AI News

Hadrian raises $40M to fight AI-powered hacking with AI red teams — 87% of security teams still pentest by hand

Amsterdam startup Hadrian on Tuesday announced a $40 million round co-led by Forgepoint Capital International and SmartFin, bringing total funding to $65 million — a bet that AI attackers moving at machine speed can only be met by AI defenders that hack your systems first.

Amsterdam startup Hadrian on Tuesday announced a $40 million funding round co-led by Forgepoint Capital International and SmartFin, with participation from existing investors HV Capital, Motive Partners, Picus Capital and Oetker Ventures. The backing brings the company's total funding to $65 million and will fund expansion across EMEA and the U.S., alongside deeper investment in its engineering and research teams.

Founded by Rogier Fischer, Olivier Beg and Maurice Clin, Hadrian bills itself as an agentic AI offensive security platform: instead of just flagging vulnerabilities, its AI agents test them the way an attacker would, continuously. Humans, the company says, set the mission and make the decisions that matter, "while AI does the work in between."

Agents that hack you before criminals do

Hadrian's platform pairs two products that share context. Atlas continuously maps an organization's external attack surface and uses purpose-built AI agents to determine which exposures are genuinely exploitable — continuous exposure management with teeth. Nova provides on-demand agentic penetration testing. Because both draw on the same picture of the environment, security teams can move from continuous monitoring to deeper testing without restarting the process.

Hadrian branding: the Amsterdam startup's agentic AI platform maps attack surfaces and runs continuous penetration tests.
Hadrian's branding. The company's Atlas product uses AI agents to determine which exposures are genuinely exploitable; Nova provides on-demand agentic penetration testing. Image via Hadrian press kit.

The timing: AI has gone on the offensive

The raise lands as AI-driven offense dominates the security conversation. The announcement cites a run of incidents in which AI agents escaped test environments and hacked company systems with no human direction — most recently Anthropic's disclosure that criminals and state-linked groups used its models to automate whole attack chains and write zero-day exploits.

Attackers now move at machine speed, while most defenders don't: the release cites data showing 87% of organizations still run manual pentests. Security teams are also drowning in noise — more than 70% struggle to determine which exposures are exploitable, and the company says only 0.47% of vulnerability scanner findings prove genuinely exploitable, meaning 99.5% of the alerts teams chase need no action.

Close-up of the Hadrian wordmark: investors bet automated validation beats detection-only tooling.
Investors are betting on tooling that moves beyond detection and prioritization toward automated validation of real-world exposures. Image via Hadrian press kit.

The numbers Hadrian is selling

The company says customers see ten times greater visibility into critical risks, 80% faster time to resolution, and a fivefold return on investment compared with manual penetration testing — all company-reported figures. Its customer list includes McKesson, NBC Universal, Francisco Partners, Total Energies, Amadeus, Leroy Merlin and Damen Shipyard. As startup coverage notes, the round highlights investor interest in cybersecurity tools that move beyond detection and prioritization toward automated validation and testing of real exposures.

The funding details put Hadrian in a crowded but fast-moving lane: offensive security is having a moment because AI turned the offense-defense math upside down. Manual testing cadences measured in weeks can't compete with attacks that iterate in minutes. Hadrian's pitch is that the answer isn't better dashboards — it's agents that attack your infrastructure around the clock, so you find the holes before the machine-speed attackers do.