Empirical Security Raises $25M Series A to Advance AI-Native Exposure Management
Empirical Security, a Chicago-based AI-native cybersecurity company, has raised $25M in a Series A round led by Brightmind Partners, with returning participation from Costanoa Ventures and Hyde Park Angels. The financing brings the company's total disclosed funding to $37M.
Founded by Ed Bellis (CEO), Michael Roytman (CTO), and Jay Jacobs (Founder & Chief Data Scientist), Empirical Security is building predictive exposure management software that helps enterprises identify which vulnerabilities are most likely to be exploited instead of treating every security finding as equally urgent.
The funding reflects growing investor conviction that enterprise cybersecurity is shifting from static vulnerability scoring toward AI-driven, context-aware risk prioritization. Rather than asking security teams to patch everything, Empirical Security is focused on predicting what attackers are most likely to exploit first.
For enterprise security leaders, investors, and startup operators, the financing represents more than another venture round. It signals that measurable decision quality is becoming one of the most valuable currencies in cybersecurity.
What Happened
Empirical Security raised a $25M Series A round led by Brightmind Partners, with returning investors Costanoa Ventures and Hyde Park Angels. The investment increases the company's total disclosed funding to $37M and will support continued development of its AI-powered exposure management platform, including its Foundation and Radiant models. On paper, this looks like another cybersecurity financing. In practice, it represents something far more interesting.
Empirical Security was not founded by entrepreneurs chasing the latest AI trend. The company was built by leaders who spent years helping define modern vulnerability management before launching another venture. Ed Bellis, Michael Roytman, and Jay Jacobs previously helped pioneer Risk-Based Vulnerability Management at Kenna Security while also contributing to the Exploit Prediction Scoring System (EPSS), an industry framework used to estimate the likelihood that known software vulnerabilities will be exploited.
That history matters because enterprise cybersecurity does not suffer from a shortage of alerts. It suffers from a shortage of confidence about which alerts deserve immediate attention. Empirical Security is betting that prediction, not accumulation, becomes the next competitive advantage.
Why This Matters
Cybersecurity has developed an unhealthy relationship with quantity. Organizations collect more vulnerability scans, more dashboards, more threat intelligence feeds, more alerts, and more severity scores than ever before. Yet many security teams continue fighting the same battle: deciding what deserves attention before attackers make the decision for them. More information does not automatically create better decisions.
Empirical Security approaches the problem from a different direction. Rather than treating every vulnerability as equally urgent, its platform attempts to determine which vulnerabilities are statistically most likely to be exploited within a specific organization. That distinction may sound subtle. Operationally, it is enormous. The difference between fixing 100 vulnerabilities and fixing the 10 that actually matter first can determine whether a security team prevents a breach or simply documents one after the fact.
The Technology Behind Empirical Security
The company's architecture reflects the philosophy embedded in its name. Empirical Security relies on evidence rather than assumptions. Its Foundation model analyzes more than 18,000 known exploited CVEs and has been trained on approximately 2M exploitation events. That broad intelligence establishes a baseline understanding of attacker behavior across the internet. The second layer, known as Radiant, becomes organization-specific. Instead of applying identical risk calculations to every enterprise, Radiant incorporates assets, infrastructure, security controls, telemetry, and operational behavior unique to each customer.
Two companies may face identical vulnerabilities while carrying dramatically different levels of actual risk. Empirical Security is building around that reality rather than pretending every enterprise operates under identical conditions.
Perhaps equally notable is the company's emphasis on transparency. Empirical Security states that it measures and publishes its own false positive rate. In cybersecurity, where vendors often compete through increasingly ambitious marketing claims, voluntarily exposing model performance demonstrates an unusual degree of confidence. Confidence backed by measurable evidence tends to age better than confidence backed by PowerPoint.
Why Investors Are Paying Attention
The financing itself tells a broader story. Returning participation from Costanoa Ventures and Hyde Park Angels signals continued conviction from investors already familiar with the company's trajectory, while Brightmind Partners leading the Series A adds another layer of institutional confidence behind Empirical Security's approach.
Early-stage venture investors frequently invest in markets. Growth investors increasingly invest in execution. Empirical Security benefits from both. The founders have already demonstrated their ability to influence enterprise cybersecurity through Kenna Security, which Cisco acquired in 2021. Investors are not simply underwriting an idea. They are backing a leadership team with a documented history of shaping how organizations prioritize cyber risk. That distinction becomes increasingly valuable as enterprise AI transitions from experimental demonstrations to measurable operational outcomes.
The Bigger Industry Shift
Artificial intelligence has become cybersecurity's favorite headline. Prediction may become its most valuable capability. The industry spent years optimizing detection. More recently, attention shifted toward automation. The next phase appears increasingly focused on prioritization, helping security teams understand not only what exists but what actually deserves immediate action.
This shift aligns with broader market realities. According to the Verizon Data Breach Investigations Report, exploitation of vulnerabilities continues to be a significant contributor to confirmed breaches, reinforcing the need for predictive vulnerability prioritization rather than reactive remediation.
Businesses are not struggling because they lack information. They are struggling because they lack context. Companies capable of converting overwhelming amounts of data into defensible decisions will likely define the next generation of cybersecurity infrastructure. Empirical Security is positioning itself directly within that transition.
What This Signals for Enterprise Cybersecurity
The strongest signal from this financing is not simply that investors wrote another large check. It is that cybersecurity economics continue shifting toward measurable decision quality. Organizations increasingly expect AI systems to justify recommendations, reduce operational noise, and improve security outcomes rather than simply generate additional alerts. That changes how enterprise buyers evaluate platforms. It changes how investors evaluate startups. And it changes how founders think about building cybersecurity companies.
Markets reward products that reduce complexity. Enterprise customers reward products that reduce uncertainty. Those objectives are similar, but they are not the same. Empirical Security appears focused on the second. That may ultimately prove to be the more durable business.
Frequently Asked Questions
What does Empirical Security do?
Empirical Security is a Chicago-based cybersecurity company that develops AI-powered exposure management software to help organizations prioritize vulnerabilities based on exploit probability rather than severity alone.
How much funding has Empirical Security raised?
Empirical Security has raised $37M in disclosed funding, including a $25M Series A led by Brightmind Partners.
Who founded Empirical Security?
Empirical Security was founded by Ed Bellis, Michael Roytman, and Jay Jacobs, veterans of Kenna Security and contributors to the Exploit Prediction Scoring System (EPSS).
What is the Exploit Prediction Scoring System (EPSS)?
EPSS is an industry framework developed through FIRST that estimates the likelihood that a known software vulnerability will be exploited, helping organizations prioritize remediation.
What makes Empirical Security different?
Empirical Security combines its Foundation model with its customer-specific Radiant model to prioritize vulnerabilities based on predicted exploit likelihood within each organization's unique environment instead of relying solely on generalized severity scores.









