Horizon3, a San Francisco-based AI-powered cybersecurity firm, has closed a $250 million Series E round, one of the larger single raises in enterprise security this year, according to Ventureburn. The company's flagship product, NodeZero, runs continuous autonomous penetration tests — essentially deploying AI to probe a customer's own infrastructure for exploitable weaknesses before adversaries do.
The raise arrives alongside a separate $125 million Series C closed by Zenity, a Boston- and Tel Aviv-based AI agent security platform, as reported by Ventureburn. Together, the two deals represent $375 million flowing into a narrow sub-sector: AI systems designed to defend enterprises against AI-enabled attacks. The timing is deliberate — enterprise security teams are scrambling to understand and contain risks introduced by the very AI copilots and autonomous agents they are deploying internally.
Horizon3 says it will deploy the Series E capital to expand its platform's autonomous testing capabilities, grow its go-to-market headcount, and deepen integrations with enterprise security stacks. The firm has positioned NodeZero as a replacement for the traditional, expensive, and episodic model of hiring external penetration-testing consultants — shifting customers toward always-on, machine-speed vulnerability discovery. That pitch has resonated particularly with mid-market and government customers in the United States, where compliance mandates are tightening under frameworks like CMMC and CISA's Secure by Design guidelines.
Zenity's $125 million Series C targets a different but adjacent problem: the security of AI agents themselves. As enterprises roll out Microsoft Copilot, Salesforce Agentforce, ServiceNow AI, and custom large-language-model workflows, Zenity argues these autonomous agents create novel attack surfaces — prompt injection, privilege escalation through agent chains, and data exfiltration via unmonitored integrations. The company says it secures AI agent deployments across identity, data access, and workflow integrity. The Series C funding will be used to accelerate enterprise sales and extend platform coverage to more agentic AI frameworks.
The broader cybersecurity funding market provides important context. Global venture investment in cybersecurity rebounded sharply through 2024 and into 2025 after a two-year correction, with several $100 million-plus rounds closing across autonomous security operations, identity, and AI model protection. Horizon3's $250 million raise is notable even within that recovery — it signals that investors are willing to write very large cheques for platforms that promise to automate labour-intensive security workflows at scale, reducing the chronic talent shortage in the sector.
For African enterprises and investors tracking this space, the strategic read is layered. African banks, telcos, and fintechs — particularly those operating regulated infrastructure like mobile money switches and payment gateways — are deploying AI tooling at pace but almost entirely lack the in-house red-team capacity to stress-test those deployments. Platforms like NodeZero, if and when they expand distribution to emerging markets, would address a genuine gap: the continent's cybersecurity workforce deficit is severe, and the cost of retaining penetration-testing firms is prohibitive for most mid-sized operators. Zenity's agent-security pitch is similarly relevant as African enterprises begin adopting Microsoft 365 Copilot and similar productivity AI, often with limited security governance frameworks in place.
For African venture investors, neither deal is a direct continent-play, but both point to where infrastructure capital is flowing globally. Security-as-a-service models with recurring revenue and strong net dollar retention are commanding growth-stage multiples that are compressing in other software categories. A local equivalent — an African firm automating vulnerability management for banks and telcos across fragmented regulatory environments — would find this a favourable fundraising narrative to borrow.
Why it matters: With $375 million committed to AI-native cybersecurity in a single week, the market is pricing autonomous threat detection not as a nice-to-have but as critical infrastructure — and African operators still running periodic, manual security audits are accumulating a compounding risk gap.
