All News
Portfolio9 September 2026

The Builder's Chair: Felix Nagy & Harold de Vries on Why the Whole Attack Surface Beats Point Solutions, and What Stops the Big Players From Catching Up

By Critical Ventures

Share
The Builder's Chair: Felix Nagy & Harold de Vries on Why the Whole Attack Surface Beats Point Solutions, and What Stops the Big Players From Catching Up

The Builder's Chair is Critical Ventures' founder interview series — conversations with the people building the companies in our portfolio. We go deep on the decisions that shaped the business, the hard years that didn't make the press release, and the bets they're making on the future of their industry.

Hackurity is a Rotterdam-based cybersecurity company founded in 2021 by CEO Felix Nagy and CCO Harold de Vries. Its ART Stack combines four capabilities — Managed Autonomous Reconnaissance, Managed Autonomous Pentesting, Autonomous Threat Intelligence, and Autonomous Brand Defense — into one continuous, autonomous red-teaming service covering applications, networks, embedded and IoT systems, and dark-web exposure, with every automated finding reviewed by a human expert before it reaches the customer.

The platform integrates with tools security teams already run, including Rapid7, Tenable, CrowdStrike, and ServiceNow, and counts customers such as Redmayne Bentley, RNHB, EMCI TV, VIOOH, and Smartvatten.

Critical Ventures backed Hackurity because it covers the entire attack surface — web and mobile applications, internal and external networks, embedded and IoT systems, and deep- and dark-web exposure — as one managed, autonomous service, where most organisations would otherwise need three or four specialist vendors stitched together.

Felix Nagy (CEO) leads the product vision and direction. While studying software engineering in Hungary in 2011, he built and ran a VPN and gaming infrastructure business, an early lesson in how easily digital trust breaks down. He later worked red-team roles across Dutch banks and financial institutions, where he saw the same gap repeatedly: point-in-time penetration tests went stale within days, and automated scanners produced noise without clear priorities. That gap is what led him to found the company in 2021 with Harold de Vries.

Harold de Vries (CCO) leads commercial strategy, partnerships, and market expansion. He co-founded Hackurity to translate Felix's red-team insight into a product enterprise security teams could actually adopt.

Felix — back in 2011, while studying software engineering in Hungary, you built and ran a VPN and gaming infrastructure business, well before you ever worked in cybersecurity professionally. What's a lesson from running that early, unrelated business that still shows up in how you think about Hackurity today?

My first business just happened to be an offensive security project that happened to have a business model; because the dorm network in question was explicitly built to stop us gaming and getting around that was the whole point.

Three things from that still stand out that I use today.

The first is that I learned network security bottom-up: routing, filtering, how blocks actually get built and how they fail.

Second, the go-to-market was pure word of mouth: someone would see me gaming on a network that wasn't supposed to allow it and the "how" sold itself. That's the warmest lead you can get before you even say a word.

The third is that we never scaled beyond the dorms in that one city, and that's its own lesson. Proof-driven word of mouth is a great lead engine and a terrible distribution strategy on its own.

That's the throughline to Hackurity. Autonomous pentesting sells the same way — show the hole, and the "how" sells itself — except now we've built the machine to do that at scale instead of running it out of one dorm room.

Harold — you come from a B2B strategy background, "turning technical outcomes into business value," rather than a hands-on security or red-team background like Felix. What's the most humbling thing about explaining pentest findings to customers who don't speak the technical language?

Translating technical findings of our tests to not technical people fits rights into my skills. I don't have a technical background, which makes it easier for me to explain the results into business risks rather than technical details. Translating the results into real risk levels is what often makes non-technical people understand the results, but mostly also how to prioritise remediation.

You two founded Hackurity together in 2021 with product vision and go-to-market split fairly cleanly between you. What's a moment where those two instincts pulled in different directions, and how did you resolve it?

I think our relationship with each other and trust in each other's capabilities is what makes the partnership work and strong. We always joke that we disagree with each other a lot less than with our spouse. But in reality, I think there's been a point where we were not fully aligned, and that's during the early stages of expanding the team. Despite we had paying customers, providing cash flow, we chose to expand the tech team first and with that prioritising development over hiring sales people to expand sales before growing tech. It's a lesson we've learned from, now building proper financial models before our next recruitment drive and calculate what's the best way forward.

Hackurity's ART Stack packages reconnaissance, pentesting, threat intelligence, and brand defense into one autonomous platform, where most competitors specialise in just one slice. What convinced you a single vertically-integrated platform would win over the industry default of stitching together point solutions?

Offering a fully integrated solution with ART rather than a deep focus on only one part of cybersecurity is a question that's asked often. Although a deep focus on one area seems logical and allows for creating a strong expertise, it also is a threat if that area is disrupted. In that case you'll have to pivot quickly and your team might not be the best fit for that pivot. Additionally, we have to realise that all these individual areas of cybersecurity focus on something in isolation. Threat actors, cybercriminals or hackers, however you want to call them, they don't stick to these silos. They'll throw everything at an organization they want to attack. With ART, this is exactly what we do. We replicate the process and tactics that threat actors use and that way we can string vulnerabilities together, as threat actors do, to build an attack path. And that's exactly why we chose for the fully integrated ART stack.

Your model keeps a human expert reviewing every automated finding before it reaches a customer. As AI models get better at security analysis, does that human-review layer stay fixed, or is it something you expect to evolve?

The human review and expertise remains an essential part of ART, now and in the future. New regulations, amongst which CRA, NIS2, require human oversight. The same for many cyber insurance providers. Despite automation and AI evolve fast, it still misses human intuition, and proper context understanding. On top of that, there are plenty of legal and ethical questions and boundaries related to AI that will need to be refined in coming years. We're actively monitoring the development of AI, how we can utilise and how that will impact or affect how we utilise the human expertise within ART.

Hackurity's pitch is built around continuous, always-on testing replacing the traditional annual or point-in-time pentest. Is that shift already how most of the market buys security today, or are you still convincing procurement teams to think differently?

There is a growing understanding in our target market that security testing cannot remain periodical and that frequency needs to be increased. We have seen with new regulations, but also through ECB the requirements of continuous or daily proactive testing is a requirement. This starts to land with procurement and security teams more and more. However, unfortunately there are still plenty of mid-size organisations who believe they're not an interesting target for threat actors or have the budget to enhance security.

You built Hackurity specifically for small IT teams that can't afford three or four specialist vendors. As larger, well-funded competitors expand their own coverage, what actually stops them from closing that same gap?

Established competitors can expand their coverage, however they have exactly the challenge we described earlier. They have gone deep in one or two specific areas of cybersecurity, grown and now pivot to expanding their offering makes them slow. Larger organisations become slower to pivot and adopt. For now our competitors are fending off the threat of enhanced AI security tools. On top of that, our team consists of some of the best Red Team Specialists who share the intrinsic drive to build Hackurity to one of the world's leading cybersecurity companies in Europe, and the world.