TL;DR
Cytix, a cybersecurity business based in Manchester, has closed a Series A round worth £5.18m ($7m). Northern Gritstone led it, with two existing backers following on: NPIF II-PXN Equity Finance, which PXN Ventures runs inside the second Northern Powerhouse Investment Fund, alongside Auriga Cyber Ventures. The company sells a platform for assessing the risk carried by each software change.
The premise: velocity broke the model
Cytix’s pitch rests on a claim about tempo. Security practice was designed around release cycles measured in weeks, while AI-assisted coding, agentic workflows and continuous delivery have compressed those cycles to something closer to continuous. Its own figures put 62% of security leaders describing organisational risk as having shifted from a background concern to a live one, with barely more than a third confident of coping with the volume of machine-written code arriving.
Chief executive Ben Armstrong made the point bluntly: change now occurs at machine speed, while few security leaders have either control over those changes or a clear view of the risk they carry.
The product sits between engineering and compliance, watching each update, judging what risk it introduces and recording how that risk was handled for regulators. Three questions structure it — whether security needs to care about a given change at all, what exposure it creates, and what action follows.
Why the round is worth noting
Funding announcements in cybersecurity are frequent and rarely instructive. This one is useful because of what it implies about the buying side: enterprises are apparently prepared to pay for evidence that AI-generated code was reviewed, which is a governance purchase rather than a threat-detection one.
Distribution supports that reading. Managed services reach customers via two partners — KPMG and NCC Group — both selling into regulated British sectors where an auditor eventually asks how a change was approved.
Looking forward
There is a public-money component here through the Northern Powerhouse fund, so this also counts as regional industrial policy meeting AI risk — a Manchester company, backed in part by a state-supported vehicle, selling assurance about code that machines wrote.
The demand signal is credible for a simple reason. Firms have spent this year watching autonomous agents behave unpredictably inside supposedly controlled tests. Knowing what changed, and being able to prove who sanctioned it, is becoming the baseline expectation rather than a maturity milestone.