From $650 Million to $2 Billion in 15 Months
Startup valuations move fast in 2026, but Horizon3.ai’s trajectory stands out even by that standard. The company’s own press release confirms it closed a $250 million Series E on August 3, 2026, at a valuation exceeding $2 billion — roughly triple the $650 million valuation the company held at its Series D round about 15 months earlier. The round was co-led by existing investors NightDragon and NEA (New Enterprise Associates), and was oversubscribed, drawing participation from seven new investors — including Acrew Capital, EDBI (Singapore’s state investment arm), PSG, and Sapphire Ventures — alongside five returning backers including Craft Ventures, Qualcomm Ventures, and SignalFire.
The growth metrics behind that valuation jump are concrete rather than aspirational. Horizon3 reports 120% year-over-year growth in annual recurring revenue, and now protects more than 7,000 organizations globally, including four Fortune 10 enterprises, according to the company’s own disclosure. That customer count — up from a smaller base at the Series D stage — reflects rapid adoption of a product category that barely existed as a distinct market five years ago: autonomous, continuous security testing that doesn’t wait for an annual penetration test.
TechCrunch’s coverage of the round frames the raise explicitly around escalating AI-driven threats, describing Horizon3 as positioning itself at the center of a security market reacting to attackers who are themselves deploying AI tooling at scale. Forbes’ reporting on the same announcement similarly frames the round as a bet that the defining cybersecurity conflict of the next several years will be automated systems fighting automated systems, rather than human analysts manually chasing human-directed intrusions.
What NodeZero Actually Does
Horizon3’s core product, NodeZero, occupies an unusual position in the cybersecurity toolchain: instead of defending a network, it attacks it — autonomously and continuously, on the company’s own infrastructure, to find weaknesses before a real adversary does. The platform conducts what the company describes as autonomous production-environment testing, identifying exploitable attack chains, providing remediation guidance, and then instantly verifying that fixes actually closed the gap. That verification loop — attack, fix, re-attack, confirm — is what distinguishes NodeZero from traditional penetration testing, which typically happens once or twice a year and leaves organizations blind to changes made in the interim.
The company’s newest capability push extends the “attacker” framing to defense directly: NodeZero now deploys honeypots specifically designed to detect AI-driven attackers, a feature that only makes sense in a threat landscape where the attacking side is itself increasingly automated. That framing — AI systems probing for weaknesses, other AI systems deployed to catch them in the act — is the “AI vs. AI” era the company’s own messaging invokes, and it reflects a broader shift security vendors have been racing to address throughout 2026 as offensive AI tooling has matured faster than most defensive counterparts. The shift from periodic, human-scheduled penetration tests to always-on automated adversary simulation also changes the internal buyer for these tools: rather than a compliance team scheduling an annual audit, it’s increasingly the security operations function treating continuous testing as an operational input alongside monitoring and detection.
A Board Seat From a Recognizable Name
Horizon3’s board additions signal the round is bringing more than capital. Dave DeWalt — founder and CEO of NightDragon, and former CEO of both FireEye and McAfee — is joining Horizon3’s board alongside Morgan Kyauk, NightDragon’s managing director. DeWalt’s prior leadership of two of the most consequential cybersecurity companies of the past two decades gives Horizon3 direct access to institutional experience scaling a security company through exactly the growth-stage challenges — enterprise sales motion, channel partnerships, eventual public-market readiness — that separate a fast-growing startup from a durable market leader.
The company’s recognition record adds independent validation to its own growth claims: Horizon3 was named the fastest-growing cybersecurity company in North America on Deloitte’s Technology Fast 500 list, was recognized as a Most Innovative company by Fast Company in 2026, and holds FedRAMP High authorization — a certification that specifically opens the door to US federal government contracts requiring the highest tier of cloud security compliance. That authorization matters commercially: FedRAMP High is a multi-year, resource-intensive certification process, and holding it signals Horizon3 has already cleared a bar that keeps many well-funded competitors out of federal deals entirely.
PYMNTS’ coverage of the funding notes the round’s oversubscription is itself a signal of investor appetite for the “offense-informed defense” category Horizon3 occupies — where a vendor’s core value proposition is demonstrating exploitability rather than merely flagging theoretical vulnerabilities, a distinction that has historically separated products enterprise security teams actually act on from ones that generate alert fatigue.
Advertisement
What This Means for Enterprises Evaluating Autonomous Security Testing
1. Treat continuous autonomous testing as a category shift, not a point-tool upgrade
Horizon3’s growth suggests enterprises are increasingly treating continuous, automated attack simulation as core security infrastructure rather than a periodic compliance checkbox. Security leaders still running annual or semi-annual penetration tests should evaluate whether that cadence leaves too large a blind-spot window given how fast both infrastructure changes and attacker tooling now move.
2. Weigh FedRAMP-authorized vendors more heavily for regulated or government-adjacent workloads
Horizon3’s FedRAMP High authorization is a meaningful signal for any organization in regulated industries or with government contracting exposure — it indicates the vendor has already survived a compliance bar most competitors haven’t cleared. Enterprises evaluating security vendors for workloads touching sensitive or regulated data should weight FedRAMP status as a differentiator, not just a nice-to-have.
3. Expect AI-specific defensive tooling to become a standard RFP line item
NodeZero’s honeypots built specifically to detect AI-driven attackers point to a broader trend: security vendors are starting to build detection capability explicitly aimed at automated, AI-assisted attack patterns rather than generic anomaly detection. Enterprises drafting security vendor RFPs in 2026-2027 should start asking directly whether a platform has AI-attacker-specific detection capability, since this is likely to become a standard evaluation criterion within the next procurement cycle.
The Bigger Signal: Cybersecurity Capital Is Chasing Automation on Both Sides
Horizon3’s tripled valuation in 15 months isn’t just a single company’s success story — it’s a data point in a broader capital reallocation toward security tooling built around the assumption that both attackers and defenders are now running increasingly autonomous systems. A $250 million round at a $2 billion-plus valuation, backed by investors with deep security-sector expertise like NightDragon, signals institutional conviction that the “AI vs. AI” framing isn’t marketing language but an accurate description of where enterprise security is heading. For competitors and enterprise buyers alike, the relevant question going forward isn’t whether autonomous, continuously-testing security platforms will become standard — Horizon3’s growth curve suggests that shift is already well underway — but which vendors can scale the trust, compliance certifications, and enterprise sales infrastructure fast enough to capture it.
Frequently Asked Questions
How much did Horizon3.ai raise and at what valuation?
Horizon3.ai raised a $250 million Series E on August 3, 2026, at a valuation exceeding $2 billion — roughly triple its $650 million valuation from its Series D round about 15 months earlier. The round was co-led by NightDragon and NEA.
What does Horizon3’s NodeZero platform do?
NodeZero is an autonomous security testing platform that safely attacks an organization’s own production environment to identify exploitable vulnerabilities, provide remediation guidance, and instantly verify that fixes worked. The platform now also deploys honeypots specifically designed to detect AI-driven attackers.
How fast is Horizon3 growing, and who are its customers?
Horizon3 reports 120% year-over-year growth in annual recurring revenue and now protects more than 7,000 organizations globally, including four Fortune 10 enterprises. The company also holds FedRAMP High authorization, enabling it to serve US federal government customers requiring the highest tier of cloud security compliance.
Sources & Further Reading
- Horizon3 Raises $250M Series E at $2B+ Valuation to Lead the “AI vs. AI” Cybersecurity Era — Horizon3.ai
- Horizon3 hits $2 billion valuation with $250M Series E as AI threats escalate — TechCrunch
- Horizon3 Raises $250 Million As Cybersecurity’s Next War Goes AI Vs. AI — Forbes
- Horizon3 Secures $250 Million to Lead AI-Versus-AI Cyber Defense — PYMNTS













