{"slug": "empirical-security-raises-25m-to-tailor-exploit-predictions-to-each-customer", "title": "Empirical Security raises $25M to tailor exploit predictions to each customer", "summary": "Empirical Security has raised a $25 million Series A led by Brightmind Partners to tailor exploit predictions to each customer's environment, bringing its disclosed funding to $37 million. The Chicago-based company sells two models—Foundation and Radiant—that combine global exploitation telemetry with customer-specific data to prioritize which software vulnerabilities security teams should repair first, addressing a gap in global vulnerability scores as Verizon's 2026 Data Breach Investigations Report found exploitation of software vulnerabilities became the most common initial-access route, accounting for 31% of breaches.", "body_md": "[Ed Bellis, Michael Roytman and Jay Jacobs](https://www.empiricalsecurity.com/about) have raised a $25 million Series A for [Empirical Security](https://www.empiricalsecurity.com/), their Chicago-based attempt to predict which software vulnerabilities attackers will exploit inside each customer's environment. [Brightmind Partners](https://www.brightmindpartners.com/) led the round, according to an [announcement published July 20th](https://www.einnews.com/pr_news/927250809/empirical-security-raises-25m-series-a-to-defend-against-ai-accelerated-exposures).\n\nThe financing brings Empirical Security's disclosed funding to $37 million. Empirical Security previously raised a [$12 million seed round](https://www.prnewswire.com/news-releases/empirical-security-raises-12m-to-stop-attacks-with-custom-cybersecurity-ai-models-302507339.html) led by [Costanoa Ventures](http://www.costanoa.vc/), with DNX Ventures, Sixty Degree Capital, Hyde Park Angels and several security executives participating. Empirical Security did not disclose a valuation for the Series A.\n\nThe founders are returning to a problem they helped define. Bellis co-founded Kenna Security and served as its chief technology officer before [Cisco completed its acquisition of Kenna on June 30th, 2021](https://www.cisco.com/site/us/en/about/corporate-development/acquisitions/kenna-security/index.html). Roytman was Kenna's chief data scientist and later a distinguished engineer at Cisco. Jacobs leads the Exploit Prediction Scoring System, or EPSS, which estimates the probability that a vulnerability will be exploited in the wild during the next 30 days.\n\nEPSS scores are published daily and have been integrated into products from vendors including Microsoft, Qualys, Tenable and Wiz, according to [FIRST's registry of EPSS users](https://www.first.org/epss/who_is_using/). Bellis said he had \"unfinished business from my time building and selling Kenna Security.\" Empirical Security is his second attempt to turn vulnerability data into a manageable remediation queue.\n\n### From global scores to local predictions\n\nEmpirical Security sells two related models. [Foundation](https://www.empiricalsecurity.com/foundation) combines internet exploitation telemetry with EPSS and covers more than 180,000 common vulnerabilities and exposures, including more than 18,000 that Empirical Security classifies as confirmed exploited. Empirical Security says its database updates hourly.\n\n[Radiant](https://www.empiricalsecurity.com/radiant) adds customer-specific information, including scanned assets, endpoints, cloud configurations, ticketing systems, attack alerts and past incidents. The model is continuously retrained as an organization's environment changes, according to Empirical Security.\n\nThe distinction addresses a limitation in global vulnerability scores. The same software flaw can present different risks on an isolated internal system and an unpatched, internet-facing server processing payments. Radiant is designed to account for those differences when deciding what a security team should repair first.\n\nThat design positions Empirical Security as a decision layer above vulnerability scanners, cloud-security platforms and asset inventories. Those systems identify weaknesses and infrastructure. Empirical Security wants to determine which findings deserve immediate remediation inside a particular network.\n\nThe timing reflects a widening gap between vulnerability volume and remediation capacity. Verizon's [2026 Data Breach Investigations Report](https://www.verizon.com/business/resources/reports/dbir/?msockid=011bb2393d7a6bdc15d6a4563cbb6af2) found that exploitation of software vulnerabilities had become the most common initial-access route in its dataset, accounting for 31% of breaches, up from 20% in the previous report. The report used 2025 data and analyzed more than 22,000 confirmed breaches.\n\nVerizon also found that organizations fully remediated 26% of critical vulnerabilities in the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog during 2025. Median resolution time increased to 43 days from 32 days. Empirical Security contributed analysis to the report, according to Empirical Security's announcement.\n\n### The proof gap\n\nEmpirical Security has published [internal benchmarks for Foundation](https://www.empiricalsecurity.com/performance) covering January 1st through May 31st, 2026. Empirical Security says nine out of every 10 vulnerabilities in the model's top 2% showed exploitation activity after scoring, while that group covered 75% of observed exploited vulnerabilities. Those results were published by Empirical Security and do not establish Radiant's performance across customer environments.\n\nPublic materials provide no independent evaluation of Radiant's false-negative rate, calibration across industries or performance against simpler prioritization methods. Empirical Security also has not disclosed revenue, customer count, contract values, retention or named customers.\n\nRadiant's product page says customer models receive full data isolation and remain accessible only to the customer. Empirical Security provides little public detail on data residency, whether customer telemetry can be reused for broader model training, or how customers can audit the factors behind a prediction. Those controls will matter if Empirical Security is to ingest the asset, configuration and incident data required to make its local models useful.\n\nThe Series A gives Bellis, Roytman and Jacobs capital to deploy their model inside more customer environments and collect the outcomes needed to test their thesis. Their previous work helped move vulnerability management away from patching every severe flaw. Empirical Security is betting that the next useful score will be specific to the organization reading it.", "url": "https://wpnews.pro/news/empirical-security-raises-25m-to-tailor-exploit-predictions-to-each-customer", "canonical_source": "https://runtimewire.com/article/empirical-security-raises-25m-series-a-exploit-predictions", "published_at": "2026-07-20 18:44:55+00:00", "updated_at": "2026-07-20 19:15:21.295393+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-startups", "ai-products"], "entities": ["Empirical Security", "Brightmind Partners", "Ed Bellis", "Michael Roytman", "Jay Jacobs", "Kenna Security", "Cisco", "Costanoa Ventures"], "alternates": {"html": "https://wpnews.pro/news/empirical-security-raises-25m-to-tailor-exploit-predictions-to-each-customer", "markdown": "https://wpnews.pro/news/empirical-security-raises-25m-to-tailor-exploit-predictions-to-each-customer.md", "text": "https://wpnews.pro/news/empirical-security-raises-25m-to-tailor-exploit-predictions-to-each-customer.txt", "jsonld": "https://wpnews.pro/news/empirical-security-raises-25m-to-tailor-exploit-predictions-to-each-customer.jsonld"}}