Cybersecurity Startup Hadrian Secures $40 Million to Combat AI-Assisted Hacking Threats

Amsterdam-based Hadrian has raised $40 million in funding to expand its AI-powered penetration testing platform that uses agents to simulate attacker behavior and identify exploitable vulnerabilities. The investment comes as state-linked groups and criminals increasingly leverage AI models to automate portions of attack chains, creating pressure on enterprises to move beyond manual security testing. Hadrian's technology aims to bridge the gap between vulnerability discovery and actual exploitability by filtering noise and prioritizing real security risks.
Hadrian's funding reflects a fundamental shift in how security threats operate. Adversaries—including criminal organizations and state actors—now use machine learning to streamline their attack workflows, automating tasks that previously required significant manual effort. This acceleration has exposed a critical weakness in traditional defense strategies: most organizations still depend on periodic manual penetration tests conducted by human specialists, a pace that cannot match automated attacks.
The company's research highlights another problem: vulnerability scanners generate massive volumes of alerts, but the vast majority lack genuine exploitability. By deploying AI agents to simulate realistic attack chains, Hadrian aims to filter noise and direct security teams toward vulnerabilities that represent actual operational risk—a more efficient use of finite security budgets and personnel.
Hadrian's expansion could reshape enterprise cybersecurity spending and strategy. If AI-assisted penetration testing becomes industry standard, organizations may reduce reliance on expensive manual security assessments while improving threat detection accuracy. However, the concentration of offensive AI capabilities among well-funded vendors may widen the security gap between large enterprises and smaller organizations with limited budgets, potentially increasing their exposure to AI-driven attacks they cannot adequately test against or defend.