Who pays, for what, and the pain being removed
Enterprises pay vulnerability management vendors to turn a growing stream of security findings into a prioritised, trackable remediation workflow. Hackuity’s pitch is that AI-assisted discovery is creating an “explosion” in detected vulnerabilities, overwhelming security teams that still rely on manual triage and coordination across IT and application owners.
The deal
French cybersecurity company Hackuity has raised EUR 19 million in a funding round backed by Forgepoint Capital International, Bright Pixel (Bright Pixel Capital), Bpifrance and Seventure Partners, according to the company’s announcement and reported coverage. Hackuity is headquartered in Lyon.
The company said the financing will support product innovation and international expansion, with coverage pointing to a focus on growth across Europe and Asia.
Why this is a with-trend round
This raise sits squarely in a broader shift: vulnerability management is moving from periodic scanning and reporting into an always-on operational discipline, because the time between discovery and exploitation is compressing.
A recent EU cybersecurity report notes that the window from vulnerability discovery to exploitation has shrunk from years to months and, in some cases, potentially hours or minutes. That dynamic makes traditional, ticket-heavy processes brittle. If the backlog grows faster than remediation capacity, security leaders need systems that help them decide what matters, route work to the right owners, and prove progress in ways auditors and boards will accept.
Hackuity is repeatedly described as an operational vulnerability management platform, a useful positioning nuance. The market has long had scanners and assessment tools, but buyers increasingly want an operating layer that can normalise findings, reduce noise, and drive execution across teams.
Commercial implications: retention and expansion drivers
For mid-market and enterprise buyers, vulnerability operations tends to become sticky when it is embedded into daily workflows.
- Switching costs: Once a platform is wired into asset inventories, ticketing systems, and reporting cadences, changing vendors can disrupt metrics and operational rhythm. That creates retention tailwinds if implementation is deep.
- Pricing power: Vendors that credibly reduce remediation cycle time can defend budget even under procurement pressure. The value case is less “better visibility” and more “fewer urgent incidents and less firefighting.”
- Expansion motion: Vulnerability management commonly lands in security and expands into IT operations, application security, and compliance reporting. If Hackuity’s product accelerates cross-team execution, it can justify seat and module expansion across business units.
- Sales cycle reality: These deployments are rarely impulse buys. Buyers typically require proof that prioritisation is explainable, integrations are reliable, and reporting maps to internal risk and audit frameworks.
Competitive context
Hackuity is entering a crowded, high-growth segment. Market research firms estimate the vulnerability management market in the multi-billion-dollar range, with projections pointing to continued growth over the next decade. That growth attracts both specialist vendors and broader security platforms that may bundle vulnerability features alongside endpoint, cloud, or governance offerings.
In this environment, differentiation often comes down to operational outcomes: how well a platform helps teams manage volume, reduce duplicates, and coordinate remediation across owners who do not report into security.
A European signal: public capital and strategic urgency
Bpifrance’s participation matters beyond the cheque. As France’s national investment bank, it signals continued public-sector support for domestic cybersecurity capabilities at a time when European institutions are explicitly focusing on AI-driven security risk. ENISA’s 2026 reporting highlights cybersecurity risks in the frontier AI era, reinforcing the policy backdrop for funding platforms that address faster, larger-scale vulnerability discovery and exploitation.
Hackuity’s stated plan to expand across Europe and Asia also points to a more export-oriented playbook for European security software, where local credibility can be paired with international channel and partnerships.
What this enables
- Faster product iteration aimed at handling higher volumes of AI-discovered vulnerabilities
- Commercial scaling beyond France, with a stated push into Europe and Asia
- Stronger enterprise positioning with a syndicate that includes both growth investors and state-linked capital
What to watch
- Evidence that automation reduces mean time to remediation, not just the number of findings processed
- Depth of integrations (ITSM, asset inventory, cloud) that drive switching costs and expansion
- Go-to-market choices for international growth: direct enterprise sales versus partners
- Competitive pressure from larger security platforms bundling vulnerability workflows