Cytix Raises $7M to Solve the AI Software Change Blind Spot

·
Listen to this article~4 min

Cytix secures $7M Series A led by Northern Gritstone to tackle AI-driven software change risks. The platform helps enterprises manage change risk at machine speed.

Cybersecurity startup Cytix just locked in a $7 million Series A round, and the timing couldn't be more telling. The company is going after a problem that's quietly keeping security leaders up at night: rapid software change and the risks it introduces before anyone can even blink. Led by Northern Gritstone, a UK venture firm backing deep tech in the North of England, the round also saw continued support from existing investors Auriga Cyber Ventures and NPIF II – PXN Equity Finance. That mix of new and old backers says a lot about the confidence in Cytix's direction. ### Why Software Change Has Become a Security Nightmare Here's the thing: software isn't changing at human speed anymore. With AI-assisted development and agentic workflows, code is being pushed out at machine speed. That's great for innovation, but it's terrible for the old security models that were built to govern change. Ben Armstrong, CEO of Cytix, puts it plainly: "Software change is becoming a key risk for organisations and those that build software need a solution that scales with the current pace of development." He's not wrong. Traditional tools can tell you what vulnerabilities exist, but they can't tell you what risk a specific change introduces. Cytix was founded in 2020 with a simple but ambitious mission: make change risk visible and manageable. The company's newly launched change risk platform is designed to answer three questions that most security teams can't answer today: - Should security even care about this change? - What risk does it actually introduce? - What action should be taken, and when? ### The Funding Details and What's Next Duncan Johnson, CEO of Northern Gritstone, sees the bigger picture. "The explosion of AI-assisted software development has led to a race to ensure software implementation remains secure," he says. "Cytix's platform aims to help enterprises take a realistic approach, recognising where change carries the most risk whilst allowing businesses to innovate." The funding will accelerate the rollout of that platform, with a focus on enterprise and regulated businesses where change governance isn't just good practice—it's a regulatory obligation. Customers can access Cytix directly or through managed service partnerships with big names like NCC Group and KPMG. ### A Practical Take on AI Risk Management What makes Cytix interesting is its realism. It's not trying to stop change or slow it down. That would be pointless. Instead, it's giving security leaders a way to understand what's actually happening in their environments. Armstrong sums it up well: "AI-assisted development means change now happens at machine speed. Meanwhile, very few security leaders have control over, or understanding of, those changes from a risk perspective. Right now, existing tools can tell you what vulnerabilities you have, but can't tell you about the risk." That's the gap Cytix is filling. And with this fresh capital, the company is positioning itself to be a key player in the next wave of cybersecurity—one where risk management keeps pace with the machines building the software. For anyone in the security space, this is a signal worth watching. The old ways of managing change risk are breaking down, and the tools that replace them are going to define the next decade of enterprise security.