Amsterdam cybersecurity startup Hadrian has raised $40 million as investors bet that AI-assisted attacks will push companies away from periodic penetration tests and toward security systems that continuously search for exploitable weaknesses.
The company said the round was co-led by Forgepoint Capital International and SmartFin, with existing investors HV Capital, Motive Partners, Picus Capital and Oetker Ventures also participating. The financing takes Hadrian’s total funding to $65 million.
Sifted independently reported that the Amsterdam startup has built an agentic AI platform that continuously probes companies’ external systems for vulnerabilities, attempting to reproduce techniques used by attackers rather than merely generating another vulnerability list.
Hadrian wants to replace the snapshot approach to pentesting
Founded by Rogier Fischer, Olivier Beg and Maurice Clin, Hadrian focuses on offensive security: testing an organization from an attacker’s perspective to identify weaknesses that can actually be exploited.
Tech.eu described its platform as using AI to help organizations identify and prioritize exploitable security risks across their external attack surfaces.
That distinction matters because conventional vulnerability scanners can generate enormous numbers of alerts without establishing whether each weakness provides a realistic route into a system.
Hadrian says only 0.47% of vulnerability-scanner findings in the data it cites proved genuinely exploitable, while more than 70% of security teams struggle to determine which exposures can actually be used in an attack.
Investors are betting on always-on offensive security
The company says its customers have achieved 10 times greater visibility into critical risks, five times the ROI of manual penetration testing and 80% faster resolution. Those are company-reported metrics rather than independently audited industry benchmarks, but they illustrate the value proposition Hadrian is selling.
Its customer list includes McKesson, NBCUniversal, TotalEnergies, Amadeus, Leroy Merlin, Francisco Partners and Damen Shipyards. The company plans to use the new capital to expand across EMEA and the United States while increasing investment in engineering and research.
Forgepoint managing director Damien Henault said security teams face too many vulnerabilities and noise, arguing that Hadrian’s always-on approach helps organizations focus on genuine risks.
Penetration testing is becoming infrastructure
The bigger shift is not simply that another cybersecurity startup has added AI.
Software, APIs and cloud environments now change continuously, while security reviews are still often scheduled quarterly or annually.
If offensive testing can run continuously alongside production infrastructure, penetration testing begins to resemble observability: an ongoing engineering function rather than an occasional audit.
For European cybersecurity startups, Hadrian’s $40 million round shows where investors increasingly see value—systems that do not merely report vulnerabilities, but continuously test which ones an attacker could actually use.