The Problem AI Development Created for Security Teams
Every time a developer — or an AI coding assistant — ships a change, an organisation's risk surface shifts. That's always been true, but AI-assisted development has fundamentally changed the scale of the problem.
Manchester cybersecurity startup Cytix has raised $7 million to address this gap, closing a Series A round led by Northern Gritstone, with participation from existing backers Auriga Cyber Ventures and NPIF II – PXN Equity Finance, managed by PXN Ventures as part of the Northern Powerhouse Investment Fund II.
Why "Finding Bugs" Is No Longer Enough
The central argument Cytix is making — and betting its growth on — is that the security industry is solving the wrong problem. Traditional tools can surface known vulnerabilities. What they can't do is tell a CISO how much risk a specific software change introduces to the business right now.
That gap is widening fast. According to research cited by Cytix, 62% of security leaders believe security risk within their organisations is moving from a background concern to an immediate one. More starkly, only 38% strongly agree their organisation is prepared for the volume of AI-generated code entering its environment.
"Software is changing. AI-assisted development means change now happens at machine speed. Meanwhile, very few security leaders have control over, or understanding of, those changes from a risk perspective." — Ben Armstrong, CEO, Cytix
The framing is pointed: existing tools report on what vulnerabilities exist; Cytix's change risk management platform is designed to report on what each change means for risk — in real time.
How the Platform Works
The platform operates between a customer's software development lifecycle and its risk, security and compliance functions. It:
- Continuously monitors software changes and updates as they occur
- Analyses the risk profile each change introduces
- Determines the appropriate security response — whether automated or manual
- Validates that identified risks have been addressed
- Creates an evidence trail documenting how individual changes were handled, supporting regulatory and compliance audits
By providing a central control point for software changes, Cytix aims to give security teams visibility into what has changed, the associated business risk, and the actions taken in response.
Enterprise Customers and the Compliance Angle
The Series A funding will be used to accelerate platform rollout and expand adoption among enterprise customers and regulated industries, where software change governance is increasingly a hard compliance requirement — not just a best practice.
Distribution is a key part of the strategy. Customers can access the platform directly, or through managed service partnerships with NCC Group and KPMG — two names with serious enterprise and regulated-sector reach.
The Broader Market Context
Cytix isn't the only company in this space attracting capital. The AI-generated code problem has opened up a wave of security sub-categories — from AI agent security to pre-deployment policy enforcement — all competing for enterprise security budgets. What differentiates Cytix's angle is the change-centric framing: rather than scanning code for known vulnerability patterns, it tracks the risk delta introduced by each deployment event.
For security leaders building or buying in this space, the implication is structural: as agentic workflows and AI copilots drive commit velocity to levels human reviewers can't match, point-in-time security tools become inadequate by design. The organisations best positioned to respond will need infrastructure that maps change to risk continuously — and can show an auditor the receipts.



