Investing in Horizon3: hacking the enterprise before the attackers do
By Theresia Gouw, Tom Porter, Mark Kraynak, and Asad Khaliq
For years, when someone asked, “Are we secure?”, the most honest reply was, “We think we are.” Security teams patch the obvious holes, schedule a yearly assessment, and cross their fingers that the weaknesses they missed aren’t the exact ones an attacker will spot. Most organizations have no idea if they’re even secure until the bad actors knock on their door.
That uncomfortable truth is now colliding with a step-change in how attacks happen. A fresh patch drops, and a motivated adversary can pull it apart, figure out what it fixed, then build a working exploit in a matter of hours. Regulators are paying attention, too, especially in critical-infrastructure sectors. Financial services, healthcare, and governments aren’t just being told to “improve security,” they’re being pressured to prove resilience in this new era. The market need has shifted from discovering vulnerabilities to continuously validating what’s actually exploitable and fixing it quickly.
The vulnerability deficit
The old approach was never built for this pace, and waiting for a breach is a losing strategy. The traditional alternative is a manual, once-a-year test that samples only a sliver of the environment. Horizon3 CEO Snehal Antani has a good way of putting it: it’s “like brushing one tooth once a year.” And worse, the world can’t hire its way out of the problem. There are only tens of thousands of skilled offensive-security professionals in the world, most of whom already work inside governments. And training one takes the better part of a decade. Meanwhile, frontier models have begun finding and exploiting zero-days on their own, in what the industry now calls the “post-Mythos era”. The volume of exploitable weaknesses is set to rise by an order of magnitude.
A machine-speed, machine-scale threat won’t be solved with human-speed, human-scale tools. The only workable answer has to be autonomous.
The Horizon3 difference
Horizon3 was built to fill exactly that void. Built as an AI-native proactive security company, it helped create the category of the autonomous AI hacker. Its NodeZero® platform autonomously, and safely, attacks an organization’s own production environment in the same way a real adversary would. It maps exactly how misconfigurations, weak credentials, and identity gaps can link together into a real attack path. It also tells teams which fixes matter most, then immediately checks that the remediation actually worked. Hack. Fix. Verify. Repeat. A pen test on Wednesday for every patch you shipped on Tuesday.
The most important piece of this puzzle is, ironically, the one most often overlooked: safety. Putting an autonomous attacker into a live production environment is as high-stakes as security gets. Doing it in a hospital full of connected devices, inside a bank’s core systems, or on a defense network, without triggering outages, is exceptionally difficult. That difficulty is also why the most demanding organizations trust NodeZero. More than 7,000 organizations rely on Horizon3 today, including large, classified government agencies, four Fortune 10 enterprises, multinational banks, and major healthcare networks.
That trust builds on itself, and we see it as the company’s strongest moat. NodeZero has now run more than 300,000 autonomous pentests in live production. Each run creates real-world attack-and-defense data that doesn’t exist in public datasets, and can’t be scraped by a foundation-model lab. With every test, the advantage deepens. It’s the kind of barrier a clever model alone can’t copy.
That track record is why we’re proud to share that Acrew has invested in Horizon3 as part of its $250M Series E, alongside NightDragon and NEA, valuing the company at over $2 billion.
Snehal Antani, Horizon3 CEO
Why we invested
Three things gave us conviction.
First, the team. It’s rare to find a founder who has lived every side of this problem. Snehal was CIO at GE Capital and scaled Splunk as its CTO through and beyond its IPO. He then spent four years as the first-ever CTO of Joint Special Operations Command, running offensive and defensive cyber operations at the highest stakes imaginable. Roughly a third of the Horizon3 team comes out of the NSA, CIA, and special operations, paired with world-class enterprise software builders. That combination of buyer empathy, public-company discipline, and genuine offensive tradecraft is not something you can hire around.
Second, the business model. Horizon3 is compounding at 120% year-over-year ARR growth. Its efficiency and channel leverage reflect real demand, not a discount-driven land grab. It was recently named the fastest-growing cybersecurity company in North America by both the Deloitte Technology Fast 500 and Fast Company.
Third, the timing. As AI makes offense cheap and abundant, security is becoming a contest of AI versus AI. Continuous autonomous validation moves from a nice-to-have to a board-level mandate. Horizon3 didn’t adjust to this moment. It was built for it.
What comes next
Pentesting was always the wedge into a broader proactive security platform. The bigger prize is closing the loop. With this capital, Horizon3 will scale its go-to-market globally and expand into Singapore, Australia, and across EMEA. It will also accelerate the part of the roadmap we find most exciting: turning offensive insight into autonomous defense. The same data that trains NodeZero to attack is now training AI defenders: blue-team agents that automatically remediate the exploitable findings that NodeZero surfaces.
That is the natural next step for autonomous security: a continuous learning loop where your defenses get smarter every time your own AI attacker does. We’re thrilled to be backing Snehal and the entire Horizon3 team as they build it.
All of that and more is why we’re incredibly excited to announce our investment in Horizon3.
In Memory of Holly Grey
It’s impossible for us to talk about this without acknowledging Holly Grey. Holly was the reason we connected with Horizon3 in the first place, but her relationship and friendship to everyone at Acrew stretched back decades. Theresia first met Holly during their years together at Forescout, where Theresia sat on the board and Holly was VP of Finance. A few years later, we reconnected with Holly at Exabeam, where she had become CFO, leading the financial function for one of the largest privately held security companies in the world. After Exabeam was acquired, Holly joined Horizon3 as CFO, becoming a trusted strategic partner to Snehal.
Behind the scenes, Holly was quietly fighting a recurrence of the cancer she had battled for 15 years, though she rarely let it show. She fought courageously and gracefully for so long, and she will be deeply missed by her friends, family, and all who loved her, including the entire team at Acrew. Holly is survived by her wife, Ellen Grey, their daughter, Sammie, and her extended family. We extend our deepest condolences to everyone whose life she touched.
Holly’s family has asked that gifts be made in her memory to the Pan-Mass Challenge in support of the Dana-Farber Cancer Institute, a cause she championed for years and for which she personally raised more than $140,000. We will remember her always.
Holly Grey




