Empirical Security has raised $25 million in a Series A funding round as the cybersecurity company works to help security teams respond to the growing threat of AI-driven exploits.
The round was led by Brightmind Partners and follows earlier investment from Costanoa Ventures, Hyde Park Angels (HPA) and other backers. The latest funding brings Empirical Security’s total capital raised to $37 million.
The company plans to use the new capital to scale its two core products: Foundation and Radiant.
Foundation is a global model that monitors more than 18,000 exploited CVEs, helping organisations identify and anticipate emerging cyber threats. Radiant, meanwhile, is a customised predictive engine designed and fine-tuned for each customer. It identifies the risks most relevant to an organisation’s specific technology environment.
The funding comes as artificial intelligence continues to increase both the volume and sophistication of cyber attacks. As a result, security teams are under mounting pressure to determine which potential vulnerabilities represent genuine threats. Many security leaders have become increasingly frustrated with traditional exposure management tools that rely on generic risk scores based largely on expert assumptions rather than real-world evidence.
Empirical Security says its predictive models enable smaller security teams to distinguish genuine risks from background noise and respond more quickly using evidence-based insights. Its customer base includes organisations operating in sectors such as technology, healthcare and financial services, where incorrectly prioritising cyber risks can have significant consequences.
The growing urgency of vulnerability exploitation was highlighted in Verizon’s 2026 Data Breach Investigations Report, which included analysis from Empirical Security.
According to the report, vulnerability exploitation surpassed stolen credentials as the leading initial access method in breaches for the first time. Exploited software vulnerabilities were linked to 31% of confirmed incidents, up from 20% the previous year.
Empirical Security was founded by three cybersecurity experts credited with pioneering risk-based vulnerability management and predictive threat intelligence.
CEO Ed Bellis previously co-founded Kenna Security and served as its chief technology officer until the company was acquired by Cisco. CTO Michael Roytman previously worked as Kenna Security’s chief data scientist.
The company’s third co-founder, Chief Data Scientist Jay Jacobs, co-created the Exploit Prediction Scoring System (EPSS). The threat model is trained and maintained by Empirical Security, with scores published daily and made freely available. Hundreds of companies, including Tenable, Qualys, CrowdStrike, Microsoft and Wiz, have integrated EPSS into their cybersecurity platforms.
Unlike traditional exposure management platforms that typically apply the same threat intelligence across customers, Empirical Security develops AI-enhanced predictive models tailored to each organisation. The approach provides evidence-based risk analysis, helping security teams prioritise remediation and support their decisions with data without requiring additional staff.
