Six million euros is a modest Series A by the standards of a market where a single AI company can raise several hundred million in a morning. The interesting part of Cytix‘s round is not the size. It is the specific bet it makes about what has gone wrong in enterprise software security.
The Manchester company, founded in 2020, has raised €6 million led by Northern Gritstone, with existing backers Auriga Cyber Ventures and NPIF II taking part, as reported by EU-Startups. Its argument is that software now changes faster than anyone can assess whether the changes are safe.
What change risk actually means
Most security tooling answers a static question: what vulnerabilities exist in this system right now. Scanners produce a list, the list is prioritised by severity, and teams work down it.
Cytix is selling against a different question. When a development team ships two hundred changes in a week, which of those changes altered the organisation’s risk position, and by how much? A change can introduce no new vulnerability at all and still be dangerous, because it has exposed an internal service, altered who can reach a database, or removed a check that another system quietly relied on.
Chief executive Ben Armstrong put the gap precisely: “Existing tools can tell you what vulnerabilities you have, but can’t tell you about the risk.”
The platform is built to answer three questions in sequence: whether security should care about a given change, what risk it introduces, and what action follows. That framing is closer to how an experienced security engineer thinks than to how a scanner reports, which is the point.
Why AI broke the old model
The reason this is a business now rather than five years ago is that the volume of change has moved by an order of magnitude.
AI-assisted development, agentic workflows and continuous delivery have together removed most of the friction from shipping code. Armstrong’s description is that change now happens “at machine speed”, while “very few security leaders have control over, or understanding of, those changes from a risk perspective”.
The security models most organisations use were designed when a release was a scheduled event. A change advisory board met, a change was reviewed by people who understood the system, and the review had time to happen because releases were infrequent. Every part of that assumption has been removed except the board.
Duncan Johnson, chief executive of Northern Gritstone, framed it as a race: “The explosion of AI-assisted software development has led to a race to ensure software implementation remains secure.”
This is the uncomfortable second-order effect of AI coding tools. The productivity gain is real and measurable in output. The review capacity did not scale with it, because reviewing requires understanding the system rather than producing text, and that remains a human bottleneck. We found the same shape when UK AI adoption reached 35% of firms but only 1.6 tools deep: adoption has run considerably ahead of the governance around it.
The problem this is really solving
There is a reason a risk-ranking product is a harder sell than a vulnerability scanner, and it is the same reason the security market keeps producing lists nobody can act on.
The official breach data shows why. As we reported, four in ten UK businesses were breached and the median cost was nothing, while the top 5% of incidents cost thousands. Security spending is fundamentally a problem of finding the small number of things that matter inside a very large number of things that do not.
A scanner that returns four thousand findings has not solved that problem; it has restated it. What a security team needs is the ranking, and ranking requires knowing what each system is worth and what depends on it, which is context a scanner does not hold.
Applying that logic to changes rather than to static vulnerabilities is a genuinely different product. Whether it can be done well enough to trust is the open question, because a tool that tells you which changes to ignore is only useful if it is right about the ones it dismisses.
Selling through other people’s relationships
The distribution detail is worth as much attention as the technology. Customers can reach Cytix directly, or through managed service partnerships with NCC Group and KPMG.
For a company of this size, that is the difference between a long sales cycle and a short one. Enterprise security buyers are conservative by profession, and a small supplier asking a regulated bank to route its change governance through an unfamiliar platform faces an extremely slow procurement process. Arriving inside an existing NCC Group or KPMG engagement removes most of that friction, because the relationship, the contract and the trust already exist.
The round is explicitly aimed at enterprise and regulated businesses, where change governance is not a preference but a regulatory obligation. That is the segment where a tool of this kind has a compliance budget to be bought from rather than a discretionary one.
Why regulated industries are the right first customers
Choosing enterprise and regulated businesses as the beachhead is a more deliberate decision than it looks, and it follows from how these organisations already work.
In an unregulated company, change control is an engineering preference. Somebody argues for more review, somebody else argues it slows delivery, and the outcome depends on which argument the executive team finds more persuasive that quarter. A tool sold into that debate is competing against the option of doing nothing, which is free.
In a regulated firm the calculation is different. Change governance is an obligation, the process has to be documented, and a regulator or auditor can ask to see evidence that changes were assessed before they were released. The question stops being whether to assess changes and becomes how to do it without hiring proportionally more people as deployment frequency rises.
That is the gap AI-assisted development has opened. An organisation that shipped weekly and now ships hourly has the same obligation and vastly more events to satisfy it against. Meeting that manually means either slowing delivery back down, which nobody will accept, or growing the security team faster than the engineering team, which nobody will fund.
A product that automates the assessment and leaves an audit trail addresses both constraints at once, and it gets paid from a compliance budget rather than a discretionary one. Compliance budgets are more resilient in a downturn, because the obligation does not soften when revenue does.
It is also the segment where being wrong is most expensive, which raises the accuracy bar the product has to clear before anyone will trust it with the decision.
The Northern Gritstone thesis
Northern Gritstone invests in science and technology companies in the North of England, and Johnson noted it was backing “another ambitious Manchester-based business”.
That word, another, is the part worth noticing. Regional investment matters far less as individual cheques than as a repeated pattern, because what makes a cluster is a fund that has done this before, knows the local universities and can introduce a founder to the last three companies it backed.
The presence of NPIF II, part of the Northern Powerhouse Investment Fund, alongside a private investor is the intended shape of that policy: public money reducing the risk of early rounds so private capital will follow, then stepping back.
It sits against a stark national backdrop. When we looked at the half-year investment map, Wales grew its investment 530% while London still gained twenty times more in cash, and the North West’s headline growth rested heavily on a single very large round. A €6 million Series A does not shift those totals. What it does is add another company to the small population that has to exist before a regional total stops depending on one deal.
What has to be true
Two things need to hold for this to work, and neither is settled.
The first is that change risk becomes a category security teams budget for separately, rather than a feature absorbed into the platforms they already buy. Security tooling consolidates aggressively, and independent products in this market are frequently acquired or out-featured before they reach scale.
The second is that the assessment is accurate enough to be relied on. A product whose value is telling you which changes to ignore carries an asymmetric risk: it is judged not on the calls it gets right but on the one it waves through.
The thesis behind it, though, is difficult to argue with. Organisations have adopted tools that write code faster than their existing processes can review it. Something has to close that gap, and at present very little does.


More Stories
UK House Prices Rose 2% and London Fell for a Tenth Month
Trusted Payments Holds 10% in Escrow Until You Sign Off
UK Manufacturing Hired at a Two-Year High While Output Slowed