HomeIntelligenceBrief
BREACH BRIEF⚪ Informational ThreatIntel

Horizon3 Secures $250M Series E to Expand Autonomous Attack‑Simulation Platform for Infrastructure

Horizon3 raised $250 million to scale its AI‑driven, autonomous penetration‑testing service that shows what attackers can actually exploit across on‑prem and cloud environments without disrupting business. The move matters for SOC 2 readiness because it provides continuous, exploitable‑risk evidence for control mapping and audit trails.

LiveThreat™ Intelligence · 📅 August 08, 2026· 📰 databreachtoday.com
Severity
Informational
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
databreachtoday.com

Horizon3 Secures $250M Series E to Expand Autonomous Attack‑Simulation Platform for Infrastructure

What Happened — Horizon3, a security‑testing startup founded in 2019, announced a $250 million Series E round led by NightDragon and NEA. The funding will be used to broaden its AI‑driven, autonomous penetration‑testing service that demonstrates real‑world exploitability across on‑premises and cloud environments without disrupting customers’ operations.

Why It Matters for Compliance & Audit Readiness

  • SOC 2 auditors increasingly expect evidence that controls actually mitigate real attack paths, not just that vulnerabilities exist on a checklist.
  • Autonomous, attacker‑centric testing can generate continuous, reproducible evidence of control effectiveness, feeding directly into the Control Mapping and continuous evidence collection requirements of the Trust Services Criteria.
  • Demonstrating exploitation risk in a non‑disruptive lab mirrors the “real‑world impact” language required for the Security and Availability principles, reducing audit gaps and supporting a defensible audit trail.

Who Is Affected

  • Technology and SaaS providers building or consuming on‑prem and cloud infrastructure.
  • Organizations pursuing SOC 2 Type II certification that need ongoing proof of control efficacy.

Recommended Actions

  • Map your existing security controls to the attack paths Horizon3 simulates; identify any gaps where controls have not been proven against realistic exploitation.
  • Integrate autonomous testing results into your continuous‑compliance pipeline as audit‑ready evidence (e.g., attach test logs to control documentation).
  • Validate that testing is performed without production impact to satisfy the “no disruption” requirement often scrutinized by auditors.

Technical Notes – Horizon3’s platform leverages AI models (including a partnership with Anthropic) to emulate attacker behavior, automatically pivoting across infrastructure, identity, and web‑application layers. The service includes regression testing against a catalog of OS, firmware, and application versions to ensure exploitability is demonstrated safely. Source: DataBreachToday

📰 Original Source
https://www.databreachtoday.com/horizon3-raises-250m-to-prove-what-attackers-exploit-a-32478

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →