Horizon3's valuation tripled to more than $2 billion as CEO Snehal Antani claims machines will run both sides of the cyber battlefield, with humans intervening only by exception.Horizon3When Horizon3 revealed that its autonomous AI had compromised a bank in 77 seconds during a Black Hat keynote alongside the National Security Agency last year, CEO Snehal Antani argued the result reflected what he believes is cybersecurity's next inflection point: attacks are accelerating faster than organizations can realistically respond.That premise is now attracting serious investor backing.The San Francisco-based cybersecurity company has raised a $250 million Series E at a valuation exceeding $2 billion, more than tripling from roughly $650 million just over a year ago. The oversubscribed round, co-led by NightDragon and NEA, follows 120% annual recurring revenue growth and a customer base exceeding 6,500 organizations, including the NSA, CISA and four Fortune 10 enterprises. NightDragon founder Dave DeWalt, who ran McAfee and took FireEye public, joins the board.Rather than treating AI as a productivity tool for security teams, the company believes autonomous systems will take part in every stage of the attack-and-defense cycle, from finding exploitable paths to fixing them."The future of cyber warfare is fundamentally AI fighting AI, with humans operating by exception rather than controlling every action directly," Antani told me. "Every major component of the cybersecurity stack is now ripe for disruption because the speed of attack is changing so dramatically."Antani isn't a typical AI founder. An engineer who started at IBM before senior technology roles at GE Capital and Splunk, he left industry to serve as the first chief technology officer of Joint Special Operations Command, where he worked closely with the Defense Department's Project Maven AI team. The experience left him allergic to silver bullets. "There isn't some magic AI button that's going to solve all of your security problems," he says. "It's still about mastering the fundamentals." Every special operations plan, he notes, gets a "red cell" assigned to attack it from the adversary's perspective—a discipline Horizon3 has effectively turned into a product.MORE FOR YOUAsked what justified a valuation north of $2 billion, Antani began with a warning rather than a pitch. "It starts with execution," he says, citing 120% revenue growth "at meaningful scale," strong sales efficiency and gross margins he says exceed those of many comparable public companies.The company’s longer-term advantage, he shared, lies in the proprietary operational data it has amassed by running hundreds of thousands of production penetration tests."Every single time our AI hacker runs a penetration test, it's collecting training data that literally nobody else has," Antani said. "It's incredibly high-resolution operational data that's exactly what you need to build the next generation of offensive and defensive cyber algorithms. In many ways, I think of us as a data company."The Race Between AI Attackers and DefendersAntani asserts that the same attack that took about 7 minutes and 19 seconds three years ago fell to 4 minutes and 12 seconds last year and now takes 77 seconds. He expects the compression to continue—to as little as 30 seconds—at which point the limiting factor won't be the attack itself but an organization's ability to decide fast enough to contain it. "If your security organization can't detect and stop me within seventy-six seconds, the game is already over," he says. "By second seventy-seven, I've taken full control of your network."He also shared what he sees as a weakness in today’s AI attackers. Because many models are trained primarily on public vulnerability databases, cyber ranges and platforms such as Hack The Box, they often struggle with the messiness of real enterprise environments. Horizon3’s research claims that human hackers clicked on decoy credentials about 37% of the time, while leading AI models followed the same traps roughly 90% of the time.Antani expects that gap to narrow as models improve, setting up a cat-and-mouse race between AI attackers and AI-powered defenses. As NodeZero, the company's autonomous penetration testing and security validation platform, assesses customer environments, it can also deploy decoys designed to lure and expose AI-driven intruders already inside a network. "That completely changes the defensive equation," he says. “Deception becomes one of the cheapest, fastest and most effective ways to detect AI-driven attackers.”Why Horizon3 Is Betting on Data Over ModelsHorizon3 isn’t entering an empty market. Pentera has spent years automating penetration testing inside enterprise networks, while Picus, AttackIQ and SafeBreach validate whether security controls catch known attack techniques. A newer generation of startups, led by XBOW, applies large language models directly to offensive security, and climbed HackerOne's rankings this year by finding vulnerabilities that once required experienced penetration testers.The split reflects two assumptions about where offensive AI is heading. The newest entrants start with large language models and ask how autonomous agents can become better hackers. Horizon3 started with production environments and asked a harder question: how do you let autonomous software attack a Fortune 10 company, a hospital or a defense contractor without breaking anything?"When I was at the Department of Defense working closely with the Project Maven team, one of the biggest lessons we learned was that the models themselves don't matter nearly as much as people think," Antani says. "Models are disposable. New foundation models are going to come out all the time. If you've designed your company around one model, you've already made a strategic mistake."The durable advantage, he argues, lies in what surrounds the model. "The workflow harness is what actually executes the work," he says. "Then you combine that with proprietary training data. Those are the things that continue creating value regardless of which model happens to be leading the benchmarks."That philosophy shapes how NodeZero is built. Rather than handing control to a single AI model, the platform combines deterministic attack logic and graph-based reasoning with multiple AI models working in concert. In practice, it behaves the way a human intruder would — stealing credentials, hijacking identities and moving through cloud systems toward whatever matters most — while keeping every action explainable enough for enterprises to trust it inside live environments. Whether the data moat holds is an open question as proprietary data has looked insurmountable before, until foundation models closed the gap.Production Pentests Matter More Than AI BenchmarksHorizon3's data advantage exists only because thousands of companies let its software attack the systems they run their businesses on. That is a far higher bar than showing off an AI agent in a lab. NodeZero operates inside live networks at banks, hospitals, defense contractors and logistics providers, and the company says it has conducted more than 300,000 production-safe penetration tests. "We ran more penetration tests last year than the entire history of computing before us," Antani claims, and every engagement feeds a reinforcement-learning loop sharpening the platform's judgment.He describes building AI that can safely operate inside live enterprise environments as the hardest engineering challenge of his career. The difficulty isn’t identifying an exploitable attack path, rather, it’s knowing when not to pursue one because of the potential operational consequences. NodeZero weighs whether each action is safe, potentially disruptive or too risky to attempt. "There are certain actions that we simply will not perform because they're reckless," Antani says. "The system is designed to recognize those contextual differences and always bias toward safety rather than aggression." Customers typically start with narrowly scoped deployments before gradually expanding. Trust, he argues, is earned through operational experience rather than marketing.The platform grew into web application testing this year, and Horizon3 joined Anthropic's Project Glasswing initiative to help secure critical infrastructure. The Series E will fund entry into Singapore and Australia, a deeper push across EMEA and autonomous blue-team agents that remediate vulnerabilities directly from NodeZero's findings—AI attackers identifying the paths that matter, AI defenders validating the fixes."We started with pentesting because it was the hardest problem to solve," Antani says. "We've evolved into a proactive security platform, and now we'll accelerate remediation by creating AI learning loops between attackers and defenders."Autonomous remediation carries obvious risks of its own, as a bad fix can break production. But Antani frames the alternative as worse. "The enemy always has a vote," he says. Attackers probe constantly, and a weakness left untested gets discovered on their timetable, not yours.That logic extends to one of cybersecurity’s longest-held assumptions that good security means fixing every vulnerability. Antani argues attackers often don't need one—stolen credentials or a single weak password among a thousand employees can be enough—so organizations should assume breach, contain intrusions quickly and reserve urgency for the small number of flaws that are actually exploitable. Whether enterprises, regulators and cyber insurers embrace that shift remains an open question, particularly as autonomous AI moves from testing systems to fixing them.For now, Horizon3's investors are betting that six years inside live production networks will prove harder to replicate than whichever model leads the benchmarks next year.