Skip to content

Product2 publishers3 min readPublished

Investors put $40M behind Hadrian's plan to sell attack-surface monitoring and AI pentests together

Amsterdam's Hadrian raised $40 million, bringing its total funding to $65 million, to sell exposure monitoring and AI-run penetration tests as one platform. For the security team asked to buy it, the case comes down to sorting real flaws from scanner noise, and almost every number behind that case comes from Hadrian.

The Product Desk · Product desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying Investors put $40M behind Hadrian's plan to sell attack-surface monitoring and AI pentests together
Photo: thenextweb.com

What happened

  • Atlas maps a company's internet-facing systems around the clock and has AI agents check which exposures are exploitable, while Nova runs penetration tests on demand using the same context.
  • Hadrian says 87% of organizations still rely on manual penetration tests and that only 0.47% of vulnerability scanner findings turn out to be exploitable.
  • The round came less than a month after Anthropic disclosed that criminal and state-linked groups used its Claude models to automate attack chains and hunt for zero-day flaws.
  • According to Hadrian, customers see ten times as many critical exposures and resolve issues 80% faster, figures the company reports across its own customer base.
  • Forgepoint Capital International and Smartfin co-led the round, with HV Capital, Motive Partners, Picus Capital and Oetker Ventures returning as investors.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision Teams that pay one vendor for scanning and another for periodic pentests now have a consolidation offer, and its value depends on how often their findings move from monitoring to deeper testing.
  • exposure When AI agents decide which exposures are exploitable, a wrong 'not exploitable' call takes a live flaw out of the human queue, and the buyer answers for the miss.
  • constraint Every outcome figure in the pitch comes from Hadrian, so a security lead building a budget case will need trial results from their own estate before finance accepts the numbers.

A scanner export lands in a security analyst's queue with 1,000 findings. By Hadrian's figure, about five of them are flaws an attacker could actually use [15][19]. Hadrian sells agents that confirm which exposures are real before a person spends time on them, and that sorting is the product [4].

The fundraising pitch points somewhere else. It leans on Anthropic's threat report, which covered Claude misuse from December 2025 to August 2026 [6]. "We have been working with LLMs since before they went mainstream, and we know that AI can work much faster than any human offensive security team," chief executive Rogier Fischer said [8]. He also said "most people are focused on automating the wrong bits" [7]. In his account, the bits worth automating are the attack paths hackers take. He said the platform emulates those paths so customers can see their biggest risks and decide where to spend their security resources [9].

By Hadrian's count, most users still test by hand: 87% of organizations still rely on manual penetration tests [14]. Damen Shipyards ran a version of that setup. Hans Quivooij, the shipbuilder's chief information security officer, said Damen used to rely on periodic assessments and a known asset inventory [10]. Hadrian now gives it "continuous visibility into what an attacker can actually see and potentially exploit," he said [11]. That describes Atlas, the monitoring half. Hadrian's claim to be different rests on the pairing, since it says no other vendor offers continuous exposure management and agentic penetration testing on one platform [18]. The sources do not show how many customers use Nova alongside Atlas.

The outcome numbers are self-reported. Beyond the tenfold visibility and faster fixes, Hadrian claims five times the return of manual testing [17]. Seeing more critical exposures measures how much got looked at. Resolution speed is closer to time-to-value. Hadrian reports it as an average across a customer base that includes McKesson, NBCUniversal, TotalEnergies, Amadeus and Leroy Merlin [16][12]. Smartfin partner Saumitra Dubey said the firm is backing Hadrian's plan to "build a nine-figure revenue business" [13].

Two variables sort the purchase. One is how fast the internet-facing estate changes. The other is whether the team loses more hours finding exposures or proving which ones are real. With a stable estate and a finding problem, an accurate inventory and the periodic test may be enough. A churning estate with the same problem points to the monitoring half alone. Stable assets buried in unconfirmed scanner output point to on-demand testing. The bundle pays where the estate churns and triage is the bottleneck. A team in that position would otherwise start each investigation over when a finding moves from monitoring to testing [4].

The quickest forcing number is the share of last quarter's scanner findings the team confirmed as exploitable. If it sits near Hadrian's 0.47%, the triage pitch fits [15]. I'd trial the platform on the churning, triage-heavy assets first. The tradeoff is concentration. When one vendor builds the map and runs the test, an asset Atlas fails to discover is also an asset Nova is never sent to probe [4].

What to watch

  • Published pricing for Atlas and Nova bought together versus separately.
  • Customer-reported data on how often Atlas findings are sent on to Nova, the usage that would show whether buyers want the bundle.
  • A rival exposure management vendor adding agentic penetration testing to the same platform, against Hadrian's claim that no one else offers both.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories