Empirical Security, a prominent CyberTech firm specializing in the development of foundational and predictive models for enterprise exposure management, has successfully closed a $25 million Series A funding round. This significant capital injection comes at a critical juncture for the cybersecurity industry, as the rapid proliferation of artificial intelligence has dramatically accelerated the scale, speed, and sophistication of threats facing global enterprises. The funding round was led by Brightmind Partners and included substantial participation from existing backers, including Costanoa Ventures and Hyde Park Angels (HPA), alongside several strategic individual investors. This latest round brings the company’s total capital raised to $37 million, providing a robust financial foundation for its next phase of growth and technological innovation.
The primary objective of this fresh capital is the scaling and enhancement of Empirical Security’s two flagship offerings: Foundation and Radiant. These platforms are designed to address the systemic inefficiencies in how modern organizations identify, prioritize, and remediate digital vulnerabilities. As the volume of Common Vulnerabilities and Exposures (CVEs) continues to grow at an exponential rate, security teams are increasingly overwhelmed by a "noise-to-signal" ratio that prevents timely intervention against the most critical threats. Empirical Security’s approach leverages advanced machine learning to move beyond traditional, static risk assessments toward a dynamic, predictive model of exposure management.
A New Paradigm in Vulnerability Management
The core of Empirical Security’s value proposition lies in its ability to provide evidence-based risk analysis. For years, Chief Information Security Officers (CISOs) have relied on legacy exposure management tools built on generic, opinion-based risk models. These models often fail to account for the unique architecture of a specific organization or the real-world likelihood of a vulnerability being exploited. Consequently, security teams frequently find themselves "chasing ghosts"—expending resources on vulnerabilities that pose little actual risk while missing critical flaws that are being actively targeted by threat actors.
To solve this, Empirical Security has developed Foundation, a global intelligence model that meticulously tracks and analyzes more than 18,000 exploited CVEs. By monitoring how vulnerabilities are weaponized in the wild, Foundation provides organizations with a comprehensive view of the global threat landscape. However, the company recognizes that global data is only one piece of the puzzle. To provide truly actionable intelligence, Empirical offers Radiant, a bespoke predictive engine. Radiant is fine-tuned to each customer’s specific environment, accounting for internal network configurations, asset importance, and existing security controls. This allows the engine to surface the specific exploits most likely to impact that individual organization, effectively filtering out the noise and allowing lean security teams to focus on the highest-priority risks.
Leadership and the Legacy of Innovation
The pedigree of Empirical Security’s founding team has been a major factor in attracting high-profile investors. The company was established by three industry veterans who are widely credited with inventing the concepts of risk-based vulnerability management (RBVM) and predictive intelligence in cybersecurity.
CEO Ed Bellis is a well-known figure in the CyberTech space, having previously co-founded Kenna Security. Under his leadership, Kenna Security defined the RBVM category before being acquired by Cisco in 2021. Bellis remained with Cisco as a Chief Technology Officer until departing to launch Empirical Security, citing "unfinished business" in the realm of predictive defense. Joining him is CTO Michael Roytman, who served as the chief data scientist at Kenna Security and is regarded as one of the foremost experts in applying data science to cybersecurity.
The third co-founder, Chief Data Scientist Jay Jacobs, brings a deep academic and practical background to the firm. Jacobs is the co-creator of the Exploit Prediction Scoring System (EPSS), a vulnerability threat model that has become a standard in the industry. The EPSS model, which is now maintained by Empirical Security, publishes daily scores that are free for the public to use. Its importance is underscored by the fact that hundreds of major cybersecurity firms—including industry giants like Microsoft, Crowdstrike, Tenable, Qualys, and Wiz—have integrated EPSS data into their own platforms. This deep-rooted involvement in industry standards gives Empirical Security a unique vantage point and an unparalleled level of credibility within the enterprise security market.
The Shifting Threat Landscape: Insights from the 2026 Verizon DBIR
The urgency of Empirical Security’s mission is supported by alarming trends highlighted in the 2026 Verizon Data Breach Investigations Report (DBIR). For the first time in the history of the report, vulnerability exploitation has overtaken stolen credentials as the primary initial access vector for data breaches. According to the analysis, which utilized data and insights provided by Empirical Security, exploited software flaws were the root cause of 31% of confirmed security incidents. This represents a significant jump from the 20% recorded just one year prior.

This shift suggests that attackers are becoming more efficient at identifying and weaponizing unpatched vulnerabilities, often aided by AI tools that can scan for weaknesses at a scale previously impossible for human hackers. In this environment, the traditional "patch everything" approach is no longer viable. Organizations are discovering that they cannot hire enough security professionals to keep up with the volume of alerts. Empirical Security’s models are designed to provide a force-multiplier effect, allowing organizations to defend their digital perimeters without necessarily increasing their headcount.
Targeted Impact on Critical Infrastructure Sectors
While Empirical Security’s technology is applicable across various industries, the company has seen particularly strong adoption in sectors where the cost of a breach is catastrophic. Technology firms, healthcare providers, and financial services organizations are the primary adopters of the Empirical platform. In these sectors, guesswork is not an option; a single missed vulnerability can lead to the exposure of sensitive patient data, the disruption of global financial transactions, or the theft of proprietary intellectual property.
In the healthcare sector, for instance, the integration of IoT devices and legacy medical systems has created a massive, fragmented attack surface. Empirical’s Radiant engine allows hospital IT teams to identify which specific medical devices or database servers are at the highest risk of exploitation, ensuring that life-critical systems remain protected. Similarly, in the financial sector, where regulatory compliance and data integrity are paramount, Empirical’s evidence-based analysis provides CISOs with the data they need to justify security expenditures and remediation priorities to boards of directors and regulatory bodies.
Strategic Implications and Future Outlook
The $25 million Series A funding will allow Empirical Security to expand its engineering and data science teams, further refining the algorithms that power Foundation and Radiant. The company also plans to expand its go-to-market operations, targeting larger global enterprises that are struggling with the transition to AI-driven security environments.
From a strategic standpoint, Empirical Security is positioning itself not just as a tool provider, but as a foundational layer of the modern security stack. By maintaining and distributing the EPSS scores, the company has embedded itself into the workflows of its competitors and partners alike. This "co-opetition" model ensures that Empirical remains at the center of the conversation regarding vulnerability prioritization.
Industry analysts suggest that the success of Empirical Security reflects a broader trend toward "autonomic" security—systems that can perceive threats and suggest or implement defenses with minimal human intervention. As AI continues to lower the barrier for entry for cybercriminals, the defensive side must respond with equally sophisticated, data-driven tools.
Ed Bellis, CEO of Empirical Security, emphasized the necessity of this shift during the funding announcement. "We helped pioneer the category of risk-based vulnerability management, but it became clear that defending against AI-driven threats and the growing volume of potential exploits would require a fundamentally new approach," Bellis stated. "Today, we finally have the technology to give security teams predictive capabilities that weren’t possible before, and we came together to build that future."
As the company moves forward, the focus will remain on proving the efficacy of its models through real-world outcomes. In an industry often criticized for "security theater" and over-promising, Empirical Security’s commitment to evidence-based analysis and transparency through the EPSS project provides a refreshing and necessary change. With $37 million in total funding and a leadership team with a proven track record of successful exits and industry-standard innovations, Empirical Security is well-positioned to lead the next generation of exposure management.



