Research

Our team (formerly of Kenna Security as well as co-creators of the EPSS) invented risk-based vulnerability management. But we believe there's areas of exposure management that haven't even been tapped, and they need to be explored urgently given the monumental challenges facing security teams. We're excited to publish our research (including ongoing benchmarks of our global and local models) and present them here.

Jay Jacobs, Chief Data Scientist

View Research

Michael Roytman, CTO

View Research

Dr. Benjamin Edwards, Head of Modeling

View Research

Jerry Gamblin, Head of Research

View Research

Chris Peltz Chris Peltz

Teaming Up Against Exposure

Having focused the last decade on Exposure Management, I can’t help but feel we are in unprecedented times. The moment we’re trying to meet is an impending future marked by an explosion in the scale, velocity, and complexity of exploitation. Meeting this moment requires focusing on the core values of exposure reduction—which is why I am truly honored to join Empirical Security as Head of Platform.

Read More
Ed Bellis Ed Bellis

Unfinished Mission: Empirical’s New Funding

Today, Empirical Security announced our $25 million Series A led by Brightmind Partners. We started Empirical because prediction has become a requirement for modern defense, and because the technology finally exists to build this the right way.

Read More
Jerry Gamblin Jerry Gamblin

Country Roads, Take Me Home

If you have been watching the World Cup this summer, you have probably heard stadiums full of fans belting out John Denver's "Take Me Home, Country Roads." There is something undeniable about that song. It taps into a universal pull toward the places, the people, and the work where we truly belong. For me, the last few weeks have felt exactly like that. A homecoming.

That is why I am incredibly excited to finally announce that I have joined Empirical as their Head of Research.

Read More
Jay Jacobs Jay Jacobs

The Vulnerability Identity Crisis

Art Manion and I have been spending roughly an hour a week for the past couple of years working through what sounds like a simple question: What are the minimum viable elements needed to define and identify a vulnerability?

Read More
Michael Roytman Michael Roytman

EPSS V5 Is Here

It’s an exciting day at Empirical: we’ve released V5 of EPSS, the scoring system that our team helped create and which was recently recommended by Anthropic to help teams prepare for an AI-accelerated tsunami of vulnerabilities.

Read More
Michael Roytman Michael Roytman

Accurate Representation

For most of the last decade, the question we have spent our research time on at Empirical Security is some version of the same one. Given a vulnerability, what is the probability it will be exploited? Given an organization, how much risk does it carry? Given a remediation strategy, how much better does it perform than the alternatives? These are measurement questions. They have answers, even if the answers are imperfect.

Read More
Michael Roytman Michael Roytman

Predict, Don’t Enumerate

Michael Roytman wrote an article for O’Reilly that makes it clear: the new frontier in exposure management is knowing what’s dangerous, not remediating vulns by volume.

Read More
Ed Bellis Ed Bellis

Anthropic Is Right About EPSS. That Still Leaves the Hard Part.

Anthropic’s security team recently gave defenders sensible advice for an AI-accelerated world, which is to patch KEV then use EPSS to prioritize the rest. The team wrote: “EPSS provides a daily-updated probability that a given Common Vulnerability and Exposure (CVE) will be exploited in the next 30 days. Patching the KEV list first and then everything above a chosen EPSS threshold will help you turn thousands of open CVEs into a manageable queue.”

Read More
Michael Roytman Michael Roytman

The Knowing Machine

Dan Geer posed the right question at Black Hat in 2014: are vulnerabilities sparse or dense? If sparse, you can patch your way to safety. If dense, patching without prioritization is the myth of Sisyphus, but the boulder is growing in size. Eleven years later, writing with Dave Aitel in Lawfare, he conceded the terms and moved to the next problem. What the industry needs, he argued, is a "knowing machine" that converts hazards into risks, not a "pointing machine" that merely enumerates flaws and screams equally at all of them.

Read More
Michael Roytman Michael Roytman

The 500 Organization Reality Check

This is part five of our series on empirical exposure management. Data from 500+ organizations in P2P Vol. 8 showed that 95% of enterprise assets already carried a top-tier exploitable vulnerability when the CVE firehose was 18,000 a year; at 48,000+ in 2025 and climbing, that exposure has only compounded while remediation capacity has not.

Read More
Michael Roytman Michael Roytman

Using ServiceNow? We’ve got you covered.

Empirical Security’s new ServiceNow Vulnerability Response app brings predictive exploit intelligence directly into ServiceNow workflows so security teams can move from reactive vulnerability management to forward-looking remediation.

Read More
Michael Roytman Michael Roytman

When Headcount Doesn’t Help

The practical implication is a reframe of how programs are governed. Most teams measure remediation volume—tickets closed, patch compliance rates, mean time to remediate. These metrics describe throughput. They do not measure the marginal risk reduction of each remediation slot. Under constrained optimization, what matters is not how many findings you close but whether each slot is allocated to the vulnerability that reduces exploitability probability the most at the margin.

Read More