Hadrian raises $40M Series B for agentic offensive security
Forgepoint Capital International and SmartFin co-lead a $40M Series B for Amsterdam's Hadrian, whose AI agents emulate attackers around the clock, taking total funding to $65M.
Also see more funding coverage: /funding/
Founded 2021 · Amsterdam, Netherlands
Hadrian, the Amsterdam-based offensive security company, has raised a $40M Series B co-led by Forgepoint Capital International and SmartFin to take its agentic AI platform deeper into EMEA and the US.
The round, announced on 6 October 2026, also brings in HV Capital, Motive Partners, Picus Capital and Oetker Ventures, and lifts Hadrian’s total funding to $65M (company announcement, 6 October 2026). The use of funds is refreshingly unexotic: expansion across EMEA and the US, and deeper investment in the engineering and research teams that build the product.
Below, I lay out what Hadrian actually sells, the market it is compounding into, and the pattern behind a third European cybersecurity round landing on our desk in a single week.
Two co-leads and a $65M war chest
A co-led Series B is a statement of conviction, and this syndicate is a deliberate mix: a dedicated cybersecurity investor in Forgepoint Capital International alongside SmartFin, with HV Capital, Motive Partners, Picus Capital and Oetker Ventures filling out the table. Forgepoint’s Damien Henault put the thesis in one line: “Hadrian’s AI native always-on solution delivers both depth and breadth and helps focus on genuine issues” (round announcement, 6 October 2026).
That “always-on” is the operative phrase. The product Hadrian sells is not a better report; it is the replacement of a yearly ritual with a continuous process.
Atlas maps, Nora attacks
Founded in 2021 by Rogier Fischer, Olivier Beg and Maurice Clin (round announcement, 6 October 2026), Hadrian built its platform around two products. Atlas continuously discovers a company’s internet-facing assets and validates which exposures an attacker could genuinely exploit; Nora runs agentic penetration tests that emulate real attack paths. “AI can work much faster than any human offensive security team,” says CEO Rogier Fischer in the announcement.
The customer list – McKesson, NBCUniversal, Total Energies, Amadeus, Leroy Merlin, Damen Shipyard – reads enterprise through and through, from a French energy major to a Dutch shipbuilder.
Hadrian’s own research claims 87% of organisations still rely on manual pentests, and that only 0.47% of vulnerability scanner findings proved genuinely exploitable (Hadrian announcement, 6 October 2026). Vendor numbers, granted – but anyone who has sat through a quarterly vulnerability review will recognise the noise problem they describe.
Pentesting: $1.98bn today, $4.39bn by 2031
The global penetration testing market is worth $1.98bn in 2025 and is projected to reach $4.39bn by 2031, a 14.2% CAGR (MarketsandMarkets, 2025). For a Series B company, a category compounding at 14% a year doubles before the next fundraising cycle closes.
The ladder below it is filling in too. On our own desk this is the third European cybersecurity round in under a week: Fleuret AI raised a €4M pre-seed for automated penetration testing led by RAISE Ventures, and Osavul closed an €8.5M Series A led by 33N Ventures. A $40M Series B sits comfortably at the top of that stack – pre-seed, Series A and Series B in the same vertical in the same week is what a maturing category looks like in the fundraising data.
Offence is becoming a European discipline
So why is offensive security suddenly commanding this kind of cheque? Part of the answer is regulatory and very European: DORA now obliges significant financial entities to run threat-led penetration testing, and NIS2 extends security duties across far more sectors than the old regime ever did. Testing that used to be an annual consulting engagement is becoming a standing obligation, and standing obligations get bought as software.
The good news is Europe is not just absorbing this shift – it is building the vendors. An Amsterdam company founded in 2021 now sells attacker emulation to McKesson and NBCUniversal, with a US security specialist crossing the Atlantic to co-write the cheque and European funds alongside. That direction of travel – American specialist capital coming to Amsterdam, rather than Dutch founders moving to San Francisco – is the detail worth keeping.
The annual pentest had a good run. Watch it turn into a continuous one, built in Amsterdam. The opportunity is clear.