Analysis
A cybersecurity startup called Hadrian has raised a $40 million Series B led by Forgepoint Capital International and SmartFin, with HV Capital, Motive Partners, Picus Capital and Oetker Ventures also participating, according to Pulse2.com. It is, confusingly, a completely different company from the $7.87 billion defense-manufacturing Hadrian that Pulse has covered extensively this year -- that Hadrian builds automated factories making precision parts for Lockheed Martin and Navy submarines out of Torrance, California. This Hadrian, founded by Rogier Fischer, Olivier Beg and Maurice Clin, builds an AI-powered offensive security platform out of Europe.
What the product actually does
Hadrian's platform combines two tools: Atlas, which continuously maps a company's external attack surface to find exploitable exposures, and Nova, which runs on-demand AI-driven penetration tests. The company claims customers see 10 times greater visibility into critical exposures, an 80% faster time to resolution, and five times the return on investment versus manual pentesting. CEO Rogier Fischer put it plainly: "We built a platform that emulates hackers' attack paths, helping our customers to understand their key risks."
“The pitch to CISOs is cost and speed: continuous automated testing instead of periodic manual engagements that take weeks to schedule and deliver.”
The $40 million brings Hadrian's total funding to $65 million, and the company already counts McKesson, NBCUniversal, Francisco Partners, TotalEnergies, Amadeus and Leroy Merlin as customers -- a notably large-enterprise roster for a Series B-stage security vendor, and a signal that AI-run pentesting is moving from novelty to a procurement line item at Fortune 500 security teams.
Hadrian is entering a crowded field. Rapid7 and Tenable still dominate traditional vulnerability management, HackerOne and Bugcrowd own the human bug-bounty model, and a wave of AI-native challengers are racing to automate the offensive side of security testing the way Hadrian does. The pitch to CISOs is cost and speed: continuous automated testing instead of periodic manual engagements that take weeks to schedule and deliver.
The risk is one every AI-security startup shares: false positives and false negatives both carry real cost, and a platform promising five-times ROI over manual testing needs to prove it holds up against novel attack techniques that weren't in its training data, not just the exposures it was built to catch. Enterprise security buyers move slowly and conservatively for a reason, and a European Series B company competing against well-capitalized US rivals for the same McKesson-sized logos still has ground to cover before its claimed numbers become an industry benchmark.
For GPs evaluating the AI-security category, the real diligence question is renewal rate on existing large-enterprise logos, not the logo count itself -- a pilot with NBCUniversal is a sales win; a multi-year contract is validation.