Empirical Security secures $25M to anticipate your next breach.
Many security teams encounter a similar challenge: there are significantly more vulnerabilities than can be addressed, and no straightforward way to determine which ones are most critical. Empirical Security aims to provide a solution to this issue.
The Chicago-based startup recently completed a Series A funding round led by Brightmind Partners, as reported by Axios. This round brings the total funding to $37 million, with previous investors Costanoa Ventures and Hyde Park Angels participating again.
A familiar story
The concept has a background. Ed Bellis, the CEO, along with Chief Technology Officer Michael Roytman, previously established Kenna Security, a company that contributed to the rise of risk-based vulnerability management. The principle was clear: rather than treating every vulnerability equally, focus on the ones that are more likely to be exploited.
While this approach was beneficial, the task was never fully accomplished. As new threats emerged from cloud services, SaaS, APIs, and third-party code, the backlog continued to expand. Bellis refers to Empirical as his “unfinished business” and has brought in Jay Jacobs, co-creator of the widely recognized EPSS exploit-scoring system.
Two distinct models
Empirical offers two predictive models. The Foundation model operates on a global scale, monitoring over 18,000 CVEs with actual exploitation activity and tracking what attackers are utilizing across the internet.
The Radiant model is tailored to individual organizations. It analyzes an organization's own assets, telemetry, and cloud configurations to predict the most pertinent threats to that specific environment. According to Bellis, Foundation provides insights into global trends, while Radiant focuses on what is most relevant to the user.
Why the urgency
The current timing is strategic. AI is accelerating the speed at which attackers identify and exploit vulnerabilities, narrowing the response window. In some cases, it can even automate breaches.
Attackers are now able to convert newly revealed vulnerabilities into functional exploits at unprecedented speeds. Bellis contends that defense mechanisms have only recently caught up, as three years ago, the data was too fragmented, and the modeling methods were underdeveloped for effective application.
That situation has evolved. Security data lakes now consolidate telemetry that once resided in various separate systems. Advanced AI can analyze and interpret vast amounts of data, and models can now be developed based on real-world exploitation rather than just static severity ratings.
A competitive landscape
Empirical is not the only entity offering AI-driven defense solutions. Numerous security startups have emerged, intending to tackle risks associated with the AI era, contributing to a broader initiative to safeguard the age of AI agents. The market for exposure management is highly competitive, and a $25 million round is relatively modest by current benchmarks.
Currently, the company's performance claims are based on customer feedback. One user expressed that their engineers are “addicted” to using the tool daily, a promising statement that still requires independent verification. The hope is that a prediction model tailored to each organization will surpass generic risk assessments.
According to Bellis, prediction has shifted from being a luxury to an essential aspect of modern defense.
Другие статьи
Empirical Security secures $25M to anticipate your next breach.
Empirical Security secured $25 million in a Series A funding round to anticipate which vulnerabilities attackers are likely to exploit, founded by the team behind Kenna Security and EPSS.
