SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
United Kingdom
Cytix launches risk platform after GBP £5.2m funding

Cytix launches risk platform after GBP £5.2m funding

Fri, 14th Aug 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Cytix has launched a software change risk platform and disclosed a USD $7 million Series A funding round. New survey data from the cybersecurity start-up points to growing concern among UK security leaders over AI-generated code.

The Manchester-based company said the round was led by Northern Gritstone, with participation from existing investors Auriga Cyber Ventures and NPIF II - PXN Equity Finance, managed by PXN Ventures as part of the Northern Powerhouse Investment Fund II.

Cytix also released research based on a survey of 250 UK IT security leaders at companies with more than 1,000 employees and in-house software development teams. The findings suggest many organisations have increased their use of AI-assisted software development faster than their security controls have adapted.

According to the survey, 78% of respondents said their organisation has mandated AI-assisted development, while 38% strongly agreed that it is prepared for the volume of AI-generated code entering its environment. A quarter said their organisation had experienced a security incident caused by a weakness introduced by AI-generated code.

Another 62% said the shift has turned security risk from a latent issue into an immediate one. The data points to a widening gap between the pace of software releases and the ability of security teams to assess changes before code goes live.

That tension is also visible in release decisions. While 28% of security leaders said security testing cannot keep pace with software change, 48% said they had signed off on a release they were not fully confident was secure.

Testing gap

The survey also examined what respondents saw as the main weaknesses in current software change management. Some 36% said security testing results are not connected to the specific change that introduced the risk, while 31% said testing is disconnected from the business context of the change being made.

Cost and evidence also featured. About 29% said the business sees it as too costly to test every software change, and 18% said there is no continuous evidence trail for auditors or customers.

Separately, 32% said security is viewed as a blocker to development speed in their organisation. That reflects a longstanding friction in software teams: businesses want faster deployment cycles, but security teams remain accountable when weak controls allow flaws into production systems.

Cytix said its new platform is designed to focus on software change itself rather than solely on known vulnerabilities. In practical terms, that means examining each change to code, configuration or release processes, assessing whether it alters risk, and documenting how that risk is handled.

According to the company, the platform sits between the software development lifecycle and risk, security and compliance functions. It is intended to act as a control point through which each software change passes so organisations can understand the change, decide what security action is needed, validate the result and retain evidence for compliance purposes.

Cytix defines a software change as any modification to a codebase or system, including new code, a bug fix or a configuration update. That broad definition matters because many security incidents stem not only from entirely new applications but also from small changes made within existing systems.

AI pressure

The growth of AI-assisted coding tools has intensified this challenge by making it easier for developers to generate and ship code quickly. Security teams have argued that code produced faster is not necessarily better understood, especially when organisations lack clear ways to trace which change introduced a particular weakness.

Ben Armstrong, Chief Executive Officer of Cytix, said the company is trying to address that problem.

"Software is changing," Armstrong said. "AI-assisted development means change now happens at machine speed. Meanwhile, very few security leaders have control over, or understanding of, those changes from a risk perspective. Right now, existing tools can tell you what vulnerabilities you have, but can't tell you about the risk. We launched Cytix's software change risk platform to get control of that risk."

The product is now generally available to customers, and Cytix said the platform is already used in continuous testing work with KPMG and NCC Group.

The company's focus places it in a part of the application security market that is shifting from periodic testing to continuous oversight of software releases. As AI tools become more common in engineering teams, investors and security buyers are paying closer attention to products that can link development activity to governance, audit and risk decisions.

The survey was conducted by Opinion Matters among UK security leaders, including Chief Information Security Officers, Heads and Directors of IT Security, Vice Presidents of IT Security, Directors of Application Security, Directors of Product Security, Heads of AppSec, AppSec Leads and Heads of IT Security Engineering.