Country Roads, Take Me Home
If you have been watching the World Cup this summer, you have probably heard stadiums full of fans belting out John Denver's "Take Me Home, Country Roads." There is something undeniable about that song. It taps into a universal pull toward the places, the people, and the work where we truly belong. For me, the last few weeks have felt exactly like that. A homecoming.
That is why I am incredibly excited to finally announce that I have joined Empirical as their Head of Research.
When Ed Bellis hired me at Kenna Security years ago, it fundamentally shaped my approach to this industry. It showed me the impact of a team singularly focused on the math and reality of risk. Over the years, I have continued to work hand in hand with the Empirical cofounders, collaborating on open source projects and wrestling with the same hard data problems. Stepping into this new role is not just a new job; it is reuniting with the people who share that original vision.
To explain why this move is so important right now, we have to look at the current state of vulnerability management. The landscape is shifting in ways that leave many practitioners in a tough spot. When Cisco announced the end-of-life for Cisco Vulnerability Management, it marked a clear exit from the independent vulnerability management space. Without a direct replacement, and with confirmation that the platform will not support CVSS 4.0 or the just-released EPSS v5, a massive gap is opening in the market.
Beyond product sunsets, this reflects a fundamental divergence in how vulnerability data is being handled and prioritized. Cisco's decision to bundle multiple CVEs into single advisories or proprietary identifiers reveals a specific outlook on the vulnerability management space as a whole. While abstracting data this way might simplify initial reporting for a vendor, it breaks the 1-to-1 mapping required for accurate risk scoring. You cannot apply predictive models effectively or run a data-driven VM program when the underlying vulnerability data is artificially grouped. Good math requires granular data, and treating CVE data as a secondary concern limits a practitioner's ability to accurately measure and mitigate risk downstream.
I have always believed that you cannot fix what you cannot accurately measure. The future of exposure management will not be won by abstracting the data further. It will be won by getting into the weeds of CVE data quality and embracing transparent, predictive scoring models.
At Empirical, we are doing exactly that. We are not just fully supporting EPSS. We are actively building a Foundational Model for vulnerability management, alongside local models that no one else in the industry is even close to offering. We are building the tools necessary to reflect the reality of modern vulnerability management.
This is about getting back to the core of what actually moves the needle in our industry. It feels good to be back to the data, back to building, and back home.