Symbolbild · KI-generiert
AI-Powered Security Validation: Continuous Monitoring Replaces the Annual Pentest

When the Annual Check Becomes Obsolete
Imagine a security company inspecting the lock on your front door once a year — but never checking the windows, the basement, or the newly installed patio door. That is essentially how classic penetration tests worked in the corporate world for a long time: an external team attempted to break into the IT infrastructure once a year, documented the gaps — and a year later the ritual repeated itself. In an era where software is updated every few weeks, cloud services open new interfaces daily, and attackers are increasingly using AI tools themselves, this model is structurally outdated.
The market is sending clear signals: U.S. cybersecurity start-up Horizon3 AI closed a Series E funding round worth $250 million at a valuation of two billion dollars. The company specializes in autonomous, AI-powered attack simulation — that is, continuous tests running around the clock rather than once a year. Investors' willingness to pay such a valuation reflects a deeper thesis: the "Continuous Security Validation" model could structurally displace traditional pentest service providers.
Horizon3 AI Series E Funding Round (USD millions)
Why Now? Three Forces Driving the Shift
The move from periodic to continuous security testing is not a marketing trend — it is the result of three overlapping developments.
1. AI on the attacker's side: Security researchers have observed a marked increase since 2023 in automated attack campaigns that use AI tools to identify vulnerabilities faster and personalize phishing messages. When attackers are active around the clock, an annual test loses almost all of its protective value immediately after completion.
2. The explosion in new attack surfaces: Modern enterprises operate hybrid cloud environments, use dozens of SaaS services, and connect external developers via APIs. Every new connection is a potential vulnerability. Studies by the U.S. National Institute of Standards and Technology (NIST) show that the number of newly reported vulnerabilities (CVEs) per year has risen nearly continuously since 2017 — more than 28,000 new CVEs were registered in 2023 alone.
3. Regulatory pressure: Frameworks such as the EU's NIS2 directive, which must be transposed into national law, and the U.S. SEC Cybersecurity Disclosure Standard require companies to demonstrate ongoing, verifiable security measures. An annual report is increasingly insufficient for compliance purposes.

The SaaS Model and Its Metrics: ARR, NRR, and Cash Runway
For investors — particularly in the small-cap space — the difference between a professional services firm and a SaaS provider is fundamental. Traditional pentest firms bill on a project basis: no engagement, no revenue. SaaS providers, by contrast, generate Annual Recurring Revenue (ARR) — annual contracts billed monthly that provide predictable cash flows.
The key metric for distinguishing real growth from hype is Net Revenue Retention (NRR): it measures how much revenue a company retains and expands from its existing customer base. An NRR above 120% means that existing customers spend on average 20% more than in the prior year — a strong signal of genuine product value. An NRR below 100%, on the other hand, indicates customer churn, which would be a critical warning sign in a growing market.
Especially for unprofitable growth companies — as many small-cap cybersecurity firms are — cash runway is also essential: it indicates how many months a company can operate with its current cash reserves before it needs additional funding. A shrinking runway increases the risk of a capital increase (share issuance) that dilutes existing shareholders.
An analogy from another technology sector: when cloud security providers came to market between 2018 and 2022, the discussion was similar — high valuations, no profits, but strong ARR growth and NRR figures above the 120% mark. Investors who entered early benefited significantly — those who bought speculative small caps without understanding the underlying metrics sometimes suffered substantial losses when growth rates normalized.
Which Market Segments Benefit — and Which Face Pressure
The shift toward continuous security validation affects different market participants in very different ways.
| Market Segment | Impact of the Paradigm Shift |
|---|---|
| Traditional pentest service providers (manual) | Structural pressure: differentiation through specialized expertise required |
| AI-native validation SaaS (e.g., Horizon3 AI) | High growth potential, but elevated valuations |
| Exposure management platforms (e.g., Tenable, Rapid7) | Expansion of existing portfolios; M&A candidates |
| MSSPs (Managed Security Service Providers) | Integration of new tools as an upselling opportunity |
For small-cap investors, the particular challenge is that many of the emerging AI-native providers are not yet publicly listed — as is the case with Horizon3 AI itself. The path to an IPO is often pursued via an additional funding round or a SPAC merger. This means the actual speculation frequently takes place in listed competitors or suppliers, not in the company making the headlines.
What Investors Can Take Away from This Structural Shift
The transition from periodic penetration tests to permanent, AI-powered security validation is not a passing hype cycle — it is a structurally driven market shift. It is sustained by regulatory pressure, an evolving threat landscape, and the SaaS model as a distribution mechanism.
For investors in small-cap cybersecurity companies, however, the iron rule remains: a growth story and a business model are two different things. ARR growth, NRR, and cash runway are the three metrics that mark the difference between a viable company and a capital-intensive hope trade. Investors who read only the headlines and buy into poorly capitalized small caps risk a total loss of capital — particularly when a capital increase leads to dilution or the cash runway runs out faster than planned.
This article is intended solely for general financial education purposes and does not constitute investment advice. Any investment decision should be made on the basis of independent analysis and, where appropriate, professional advice.
Key Terms at a Glance
- Penetration Test (Pentest)
- A targeted, time-limited attempt by authorized experts to break into an IT system in order to identify security vulnerabilities. Traditionally a process commissioned annually or on a project basis.
- Continuous Security Validation
- A permanently running, automated simulation of attack paths within an organization's own IT infrastructure. The goal is to detect new vulnerabilities before real attackers can exploit them.
- Annual Recurring Revenue (ARR)
- Annualized revenue from active subscriptions or recurring contracts. The central growth metric for SaaS companies.
- Net Revenue Retention (NRR)
- Measures how much revenue from the existing customer base is retained and expanded. Values above 100% signal organic growth without new customer acquisition; above 120% is considered a strong quality signal.
- Cash Runway
- Indicates how many months a company can sustain operations with its current cash reserves at the prevailing burn rate before new capital is required.
- Dilution
- When a company issues new shares (capital increase), the percentage ownership of existing shareholders in the total equity decreases — their stake is "diluted."
- CVE (Common Vulnerabilities and Exposures)
- A public registry of known security vulnerabilities in software and hardware, maintained by the U.S. NIST. The number of newly reported CVEs per year serves as an indicator of the growth rate of the attack surface.
- NIS2
- EU directive on network and information security (second version), which obliges companies in critical sectors to implement demonstrable, ongoing cybersecurity measures — thereby providing regulatory support for the demand for continuous security validation.
⚠️ Important notice: This article is for informational and educational purposes only. It does not constitute investment advice, a recommendation, or a solicitation to buy or sell any security. Investments in small-cap exploration and mining companies carry a high risk, including the potential total loss of capital. Before making any investment decision, consult a registered financial advisor and conduct your own analysis. Aktienatlas-Redaktion is not responsible for decisions taken based on the content published here.
Educational content only, not investment advice. Small caps are highly speculative and total loss is possible.