Unfinished Mission: Empirical’s New Funding

Today, Empirical Security announced our $25 million Series A led by Brightmind Partners. I’m grateful for the support from our investors, our early customers, and the team that’s helping us build the company. But for me, this announcement is also a personal milestone: Empirical exists because I had unfinished business.

When Michael Roytman and I were building Kenna Security, we helped create what became known as risk-based vulnerability management. The idea was pretty straightforward: security teams shouldn’t treat every vulnerability the same way. They needed a better way to understand which vulnerabilities were most likely to be exploited, which assets mattered most, and where remediation would actually reduce risk.

That approach helped a lot of organizations move beyond endless scanner lists and static severity scores. It gave security teams a more practical way to prioritize their work, and it gave security leaders a better way to explain risk.

But even then it was clear the job wasn’t finished. The backlog kept growing even as the attack surface kept expanding. Cloud, SaaS, APIs, identity systems, third-party code, internet-facing assets, and more complex development environments all added new layers of exposure. Security teams were being asked to make thousands of prioritization decisions with limited people and incomplete context.

Over the last few years, that problem has become even harder. AI is accelerating the pace at which attackers and researchers can identify, analyze, and act on weaknesses. Defenders are now facing a world where the number of possible issues is far beyond what any team can manually evaluate, while the time available to respond keeps shrinking.

Michael and I realized we had to get back in the game. Together with Jay Jacobs, co-creator of the EPSS, we embarked on building something that couldn’t have existed even a few years ago but which was purpose-built for the coming crisis.

Three years ago, the technology wasn’t ready for the new rising tide of CVEs. The data was too fragmented and modeling wasn’t mature enough. MLops was immature and made it difficult to scale and maintain numerous models at once. You couldn’t really bring to bear a predictive model trained on an individual organization’s unique assets, configurations, and telemetry well enough to truly claim “exploit prediction.”

That’s changed. Modern security data lakes make it possible to collect and organize telemetry that used to live in separate systems. Advances in AI make it possible to mine, normalize, enrich, and reason over large volumes of security data in ways that would have been unrealistic only a few years ago. Predictive models have also improved to the point where we can move away from static assumptions and build systems that are trained, tested, and refined against real-world exploitation.

That combination creates a new opportunity for defenders, equipping them with a localized model that learns from what’s actually happening in the real world but then applies that intelligence to the context of an individual environment.

That last part is what I’m most excited about. Every organization is different. The assets, controls, adversaries, exposure patterns, and cloud footprints are all different. A vulnerability that needs immediate action in one company may be far less urgent in another. A generic model can’t see enough of that context.

Empirical was built to close that gap. Our first flagship model, Foundation, is our global predictive model, monitoring more than 18,000 CVEs with exploitation activity and helping organizations understand that exploit activity and likelihood at a scale that goes well beyond traditional sources. Foundation gives teams a stronger base layer for understanding what attackers are actually using and where the global signal is pointing.

Our second model, Radiant, takes that intelligence and makes it specific to each organization, a custom predictive engine that’s built and fine-tuned for an individual environment. It incorporates the organization’s own assets and applications, telemetry, configurations, vulnerabilities, cloud signals, and environmental context to identify the potential exploits most relevant to that company.

Foundation tells you what’s happening globally. Radiant helps you understand what’s most likely to matter locally. 

That’s the future we came back together to build, to give defenders the best predictive capabilities modern technology can create. We started Empirical because prediction has become a requirement for modern defense, and because the technology finally exists to build this the right way. And we started it because our peers in security deserve tools that give them an unfair advantage at prioritizing threats and managing risk. Want to see more? Reach out to us.

Previous
Previous

Teaming Up Against Exposure

Next
Next

Country Roads, Take Me Home