AI & TechArtificial IntelligenceCybersecurityNewswireStartups

Empirical Security secures $25M to predict data breaches

▼ Summary

– Empirical Security raised a $25 million Series A led by Brightmind Partners, bringing total funding to $37 million, to predict which software flaws pose the most risk.
– The company was founded by Ed Bellis and Michael Roytman, who previously built Kenna Security, a firm that popularized risk-based vulnerability management.
– Empirical offers two predictive models: Foundation tracks global exploitation activity across over 18,000 CVEs, while Radiant trains on a single organization’s own assets to predict local threats.
– The timing is driven by AI accelerating attackers’ ability to exploit flaws, with better data lakes and AI models now enabling more accurate predictions than three years ago.
– Empirical faces competition in the crowded exposure management market, and its performance claims currently rely on customer testimonials rather than independent proof.

Security teams across the industry share a persistent headache: an overwhelming number of vulnerabilities, with no reliable method to determine which ones demand immediate attention. Empirical Security is stepping in with a data-driven solution to forecast the answer.

The Chicago-based company has closed a $25 million Series A funding round led by Brightmind Partners, according to CEO Ed Bellis, who first shared the news with Axios. This brings the startup’s total capital raised to $37 million. Returning investors Costanoa Ventures and Hyde Park Angels also participated in the round.

A familiar mission, unfinished

This isn’t Bellis’s first attempt at solving the vulnerability prioritization puzzle. Alongside CTO Michael Roytman, he previously built Kenna Security, a firm that pioneered risk-based vulnerability management. The core concept was straightforward: stop treating every security flaw with equal urgency and instead concentrate resources on the weaknesses most likely to be weaponized by attackers.

That approach made a difference, but it didn’t eliminate the problem. The vulnerability backlog continued to balloon as cloud environments, SaaS platforms, APIs, and third-party code introduced new exposure points at a relentless pace. Bellis describes Empirical as his “unfinished business.” To strengthen the team, he brought on Jay Jacobs, co-creator of the widely adopted EPSS (Exploit Prediction Scoring System).

Two predictive engines

Empirical offers two distinct predictive models designed to address different scales of threat intelligence. The first, called Foundation, operates at a global level. It monitors over 18,000 CVEs with active exploitation data, tracking which vulnerabilities attackers are actually leveraging across the internet in real time.

The second model, Radiant, is tailored to individual organizations. It trains on a company’s specific assets, telemetry, and cloud configuration, then forecasts the threats most relevant to that unique environment. “Foundation tells you what is happening globally,” Bellis explains, “and Radiant tells you what is likely to matter to you.”

Why the timing works now

The launch comes at a critical moment. Artificial intelligence is accelerating the speed at which attackers discover and exploit weaknesses, compressing the response window for defenders. AI can now even automate entire breach processes.

Attackers are converting newly disclosed vulnerabilities into working exploits faster than ever before. Bellis argues that defense strategies have only recently caught up to this reality. Three years ago, the necessary data was too scattered, and the modeling techniques too immature, to attempt this kind of prediction effectively.

That has changed. Security data lakes now aggregate telemetry that once lived in isolated systems. More advanced AI can mine and reason across enormous datasets, and models can be trained on actual exploitation behavior rather than static severity scores.

A competitive landscape

Empirical enters a crowded field of startups offering AI-driven security solutions. A steady stream of companies has raised capital on the promise of managing AI-era risk, part of a broader race to secure the emerging AI-agent era. Exposure management is a highly competitive market, and $25 million is a relatively modest sum by current standards.

For now, the company’s performance claims are largely self-reported. One customer describes its engineers as “addicted” to checking the tool daily, a compelling anecdote that still awaits independent validation. The central bet is that predictive analytics, fine-tuned to each organization’s specific environment, will prove more effective than another generic risk score.

Prediction, Bellis argues, has shifted from a luxury to a requirement for modern defense, not an optional add-on.

(Source: The Next Web)

Topics

vulnerability management 95% predictive security models 92% ai in cybersecurity 90% startup funding 88% risk-based prioritization 85% attack exploitation speed 83% epss exploit scoring 82% exposure management market 81% cloud and saas exposure 80% customized threat prediction 79%