Where cybersecurity investment is going: five startups worth watching
Recent funding rounds cluster around AI agent security and autonomous testing. What the money says about where the industry thinks the next problem is.
Funding rounds are a lagging indicator of engineering reality and a leading indicator of what your vendors will be selling you in eighteen months. Both are worth tracking. Five recent rounds, and the pattern underneath them.
Rein Security — $25M Series A
AI agent security. Runtime controls for AI agents — constraining what an agent is permitted to actually do, as opposed to filtering what it is permitted to say. The largest round of the five, which is itself the signal.
Hadrian — $40M
AI-powered offensive security. External attack surface discovery, exploitability validation, and remediation prioritisation. The interesting half is validation: moving from “this CVE is present” to “this is reachable and exploitable here”, which is the distinction that makes a findings list actionable.
Hilt — $4.2M seed
Data security and behavioural analytics. Monitoring how data moves across cloud infrastructure and networks to surface anomalous behaviour. A crowded category, but the behavioural framing is where the remaining headroom is.
Fleuret AI — €4M pre-seed
Automated penetration testing. Agents that carry out vulnerability discovery to support continuous rather than point-in-time testing.
Guardrail Technologies — $3M
AI governance and controls. Earliest-stage of the five, in the part of the market that regulation rather than threat is currently creating.
What the pattern says
Four of the five are selling into problems created by AI adoption rather than into the traditional control stack. Two of them — Hadrian and Fleuret — are automating offensive testing, which is the clearest commercial signal yet that continuous validation is displacing the annual penetration test as the default expectation.
Expect “continuous” and “AI-powered” to appear on every testing proposal you receive next year. The question to ask is unchanged: show me a finding you validated as exploitable, and show me the re-test after we fixed it. Automation changes how often testing happens. It does not change what makes a report worth paying for.
On AI agent security specifically — if your organisation is deploying agents that can take actions in real systems, the control question is no longer prompt filtering. It is what the agent is authorised to do, under whose identity, and what the blast radius is when it is wrong. That is an access-control problem wearing new clothes, and it is worth scoping before the agents are in production rather than after.
Figures above are as reported by the companies and their investors; we have not independently verified round sizes.