Summary
- Hadrian has raised $40 million in a round led by Forgepoint Capital International and SmartFin.
- The Amsterdam company says the investment takes its total funding to $65 million.
- Its platform uses automated offensive testing to identify and validate attack paths across customer environments.
Amsterdam cybersecurity company Hadrian has raised $40 million to expand an offensive security platform that uses automation to test enterprise attack paths more frequently than conventional periodic assessments.
The investment was led by Forgepoint Capital International and SmartFin, with existing investors HV Capital, Motive Partners, Picus Capital and Oetker Ventures also participating. Hadrian says the round takes its total funding to $65 million.
The company describes its technology as agentic AI for offensive security. The platform discovers assets, identifies weaknesses and attempts to determine whether they can be combined into practical attack routes through an organisation’s environment.
Hadrian plans to use the capital to expand across EMEA and the United States. It lists customers across sectors including healthcare, energy, media, retail, travel, investment and maritime industries.
The proposition addresses a familiar limitation in security testing. A penetration assessment describes an environment at a particular moment, while cloud services, applications and external infrastructure can change continually between scheduled engagements.
Automation is competing on frequency and prioritisation
Continuous offensive testing is intended to reduce the gap between formal assessments by repeatedly examining what an attacker can reach and how weaknesses might connect. The usefulness of that model depends on whether the platform can identify meaningful paths rather than creating another large queue of findings.
Hadrian argues that exploit validation helps customers distinguish vulnerabilities that can be turned into an attack route from issues that have little practical consequence in the environment being tested.
The company says customers have recorded ten times greater visibility into critical risk, five times return on investment compared with manual penetration testing and an 80% reduction in time to resolution. Those figures are Hadrian’s own performance claims and have not been independently validated within the material used for this article.
Automation also changes the operating model for offensive security. Human penetration testers work within a defined scope and engagement period, while software agents can perform repeated discovery and testing as the environment changes.
Hadrian’s use of the term agentic AI reflects a wider shift in cybersecurity products towards systems that perform sequences of actions rather than merely ranking alerts or summarising data. In offensive testing, those actions are intended to reproduce parts of an attacker’s decision process.
The company does not say that its agents operate outside customer-authorised testing or that its platform has caused an incident. Its commercial claim is that more frequent offensive validation can give customers a current view of exploitable exposure.
Whether that model reduces risk depends on more than the use of AI. Asset discovery has to be accurate, testing needs appropriate controls, findings must be reliable and organisations still need to remediate weaknesses once they are identified.
The $40 million round gives Hadrian additional capital to expand that approach. Investors are backing a company with $65 million in total funding that is trying to move offensive testing from a periodic exercise towards a more continuous security function.





