AI Penetration Testing Gets Backing as Hadrian Raises Funds
Hadrian, an Amsterdam-based security company, has raised $40 million to expand its AI-driven attack testing, according to a Business Wire release dated October 6, 2026. Forgepoint Capital International and SmartFin co-led the round. Total funding now stands at $65 million, and the company plans to grow in Europe, the Middle East, Africa, and the United States.
Security can feel like a tax on a young company. Even so, breaches are costly, and attackers now use automation too. Here is a plain-English way to think about AI cybersecurity without a security department.
What Hadrian Actually Sells
Hadrian offers two products. Atlas continuously maps a company’s external attack surface and checks which exposures can really be exploited. Nova runs penetration testing using AI agents, which means it probes systems the way a hired attacker would.
Customers named in the release include McKesson, NBC Universal, TotalEnergies, and Amadeus. These are large enterprises, so small teams will not buy the same package. Nevertheless, the approach shows where the market is heading.
Rogier Fischer, the CEO, started the company with two co-founders. Earlier backers, including HV Capital and Oetker Ventures, joined the round as well. The new money is earmarked for expansion and for deeper engineering and research work.
Why does this matter to a small company? Attackers use automation, so defenders are under pressure to match their speed. Funding rounds like this one show that investors expect continuous testing to become a standard practice.
The Numbers Behind the Pitch
The company cites research showing manual testing is still the norm, and that most alerts are noise. Treat the customer results as marketing claims, because the company reports them itself.
| Claim | Figure |
|---|---|
| Organizations still running manual penetration tests | 87% |
| Scanner findings that prove truly exploitable | 0.47% |
| Greater visibility into critical exposures (customer-reported) | 10x |
| Faster time to resolution (customer-reported) | 80% |
| Return versus manual testing (customer-reported) | 5x |
The 0.47% figure deserves a second look. If it is accurate, roughly 99.5% of scanner alerts do not need action. As a result, the hard part of security is deciding what to fix first.
Another statistic from the release says that over seven in ten security teams cannot easily separate real exposures from false alarms. That is a time problem as much as a technology problem. Small teams feel it most, because one person often handles security part time.
A Three-Question Framework for Founders
You can borrow the thinking without the enterprise price tag. First, ask what an outsider can see about your company. Second, ask which of those exposures could actually be used against you. Third, ask who fixes each one and by when.
That framework turns a scary topic into a short list. Start with your public website, login pages, and any cloud storage. For a primer on the basics, review these cybersecurity essentials and then work through the three questions.
Write the answers in a shared document and review them every quarter. Over time, the list shows whether you are getting safer or just busier. Keep the language plain so non-technical teammates can follow along.
Free and Low-Cost Ways to Start
You do not need a large budget to improve. The U.S. Cybersecurity and Infrastructure Security Agency publishes cybersecurity best practices that any business can follow. Turn on multi-factor authentication everywhere, keep software updated, and limit who can access sensitive files.
In addition, patch known problems quickly. When a flaw is under active attack, delay is the biggest risk, as one recent Citrix NetScaler vulnerability showed. Once the basics are covered, consider paid testing.
Train your team as well, since many attacks begin with a convincing email. A ten-minute monthly reminder about suspicious links goes a long way. People are your largest attack surface, and they are also your best defense.
Finally, keep perspective on the vendor claims. Customer-reported gains are a starting point for questions, not proof. Ask for references and a trial before you commit any budget.
AI Penetration Testing FAQ
What is penetration testing?
It is a controlled attack on your own systems to find weaknesses before criminals do. Traditionally, human experts run it a few times a year.
Is AI penetration testing right for a small company?
Possibly, once you have the basics in place. Continuous testing helps most when your systems change often.
If you are weighing vendors, ask three questions. How does the tool prove that a finding is exploitable? Who reviews the results, and how fast do you get them? Finally, how does pricing change as your company grows?
What to Watch in the Months Ahead
Watch whether continuous testing becomes affordable for smaller companies. Also watch how investors treat AI security, since big rounds keep arriving. The simple lesson is this: know what you expose, fix what matters, and keep checking.
Also keep an eye on how regulators and customers treat security. Larger clients increasingly ask vendors about their testing practices. Being able to answer clearly can help you win deals, not just avoid trouble.