Cytix Secures $7 Million in Series A Funding
The British cybersecurity startup Cytix has closed a Series A funding round of seven million U.S. dollars. The round was led by Northern Gritstone. Existing investors Auriga Cyber Ventures and NPIF II – PXN Equity Finance also participated again. The company plans to use the capital to expand its platform for managing security risks associated with software changes and to grow its presence, particularly among larger and regulated companies.
The focus is on a problem that is becoming increasingly significant due to the growing use of AI in software development: Software can be written and modified at an ever-faster pace, while traditional security processes struggle to keep up with this speed.
Series A Round Aims to Accelerate Expansion Among Enterprise Customers
With Northern Gritstone, the company gains a new lead investor that focuses on science and technology companies in Northern England. Existing investors Auriga Cyber Ventures and NPIF II – PXN Equity Finance are also increasing their stakes in this new round.
The fresh capital is primarily intended to accelerate the launch and adoption of Cytix’s newly launched Change Risk Platform. A key focus is on enterprise customers and companies in regulated industries, where the documentation and control of software changes are increasingly part of regulatory requirements. The platform can be accessed directly through Cytix as well as through managed service partnerships with KPMG and NCC Group.
AI Accelerates Software Development and Creates New Risks
Cytix is capitalizing on a trend that is gaining even more momentum thanks to generative AI and so-called agent-based workflows. Software changes are increasingly being automated and occurring at significantly shorter intervals.
A survey of 250 British IT security leaders at large companies, conducted on behalf of the company, highlights the associated challenges. According to the survey, only 38 percent strongly agree with the statement that their company is prepared for the volume of AI-generated code. At the same time, 62 percent of respondents increasingly view security risks as an immediate problem rather than merely a latent one. For Cytix, this gives rise to a new category of cyber risks: It is no longer enough to simply identify known vulnerabilities. Companies must be able to understand the specific risk posed by a single software change and determine which security measures should be implemented as a result.
Security Decisions Instead of Another Vulnerability List
The Cytix platform continuously monitors software changes and updates. It analyzes and validates the associated risk while simultaneously documenting how a company has addressed it. This is also intended to facilitate audit trail maintenance for regulatory and compliance functions.
Technically, Cytix positions itself between the software development lifecycle and a company’s risk, security, and compliance systems. The platform is designed to track which changes were made, what business risk they pose, and what security measures are necessary. It then documents how the risk was addressed.
CEO and co-founder Ben Armstrong sees the speed of AI-driven development as a particular challenge. While traditional security tools can identify existing vulnerabilities, they do not automatically provide companies with the necessary context to assess the actual risk posed by a change.
Cybersecurity Must Keep Pace with AI
Cytix is thus addressing a market that is itself changing due to the AI boom. Generative AI promises development teams significant productivity gains. However, as this results in more and more code being generated at ever-shorter intervals, security testing, risk assessment, and compliance must scale accordingly. Instead of treating every change the same, the platform is designed to help companies identify those changes that actually pose a relevant risk.
Northern Gritstone CEO Duncan Johnson sees a growing need for this. The sharp increase in AI-powered software development has triggered a race to ensure that the implementation of new software remains secure. Cytix is already being used beyond its traditional direct customers. According to the company, the technology forms the basis for continuous testing programs at KPMG and NCC Group, among others. The Change Risk Platform has been generally available since August 12, 2026.

Newsletter
Startups, stories and stats from the German startup ecosystem straight to your inbox. Subscribe with 2 clicks. Noice.
LinkedIn ConnectFYI: English edition available
Hello my friend, have you been stranded on the German edition of Startbase? At least your browser tells us, that you do not speak German - so maybe you would like to switch to the English edition instead?
FYI: Deutsche Edition verfügbar
Hallo mein Freund, du befindest dich auf der Englischen Edition der Startbase und laut deinem Browser sprichst du eigentlich auch Deutsch. Magst du die Sprache wechseln?