Empirical Security bags $25m as exploit threats surge

Empirical Security

Empirical Security, a CyberTech company developing foundational and predictive models for exposure management, has secured $25m in Series A funding as AI accelerates the scale of cyber threats facing enterprises.

The round was led by Brightmind Partners and builds on previous backing from Costanoa Ventures, Hyde Park Angels (HPA) and other investors, lifting the firm’s total capital raised to $37m.

The fresh funds will be channelled into scaling the company’s two core offerings. The first, Foundation, is a global model that tracks more than 18,000 exploited CVEs to help organisations anticipate threats. The second, Radiant, is a bespoke predictive engine that is fine-tuned to each customer’s environment so it can surface the exploits most likely to affect that specific organisation.

The raise comes as security teams grapple with an expanding attack surface driven by AI, leaving them under growing pressure to prioritise the exploits that genuinely matter. Many leaders have grown weary of legacy exposure management tools built on generic, opinion-based risk models that are never tested against real-world outcomes.

Empirical Security claims its models help lean teams separate genuine risk from noise and act faster and with greater confidence.

The company serves enterprises where guesswork is not an option, with a particular focus on technology, healthcare and financial services organisations. It was founded by three executives credited with inventing risk-based vulnerability management and predictive intelligence.

CEO Ed Bellis previously co-founded Kenna Security and remained CTO through its sale to Cisco, while CTO Michael Roytman was formerly Kenna Security’s chief data scientist. The third co-founder, chief data scientist Jay Jacobs, co-created the Exploit Prediction Scoring System (EPSS), a vulnerability threat model maintained by Empirical Security with scores published daily and free to use. Hundreds of firms, including Tenable, Qualys, Crowdstrike, Microsoft and Wiz, have integrated EPSS into their platforms.

The urgency behind the raise is underlined by Verizon’s 2026 Data Breach Investigations Report, which drew on analysis from Empirical Security. It found vulnerability exploitation had overtaken stolen credentials as the top initial access vector for breaches for the first time, with exploited software flaws behind 31% of confirmed incidents, up from 20% a year earlier.

Unlike conventional platforms that apply the same generalised threat data to every customer, Empirical Security constructs AI-enhanced predictive models tailored to each organisation, giving security teams evidence-based risk analysis they can use to prioritise remediation and defend their decisions to stakeholders, all without adding headcount.

Empirical Security co-founder and CEO Ed Bellis said, “I had unfinished business from my time building and selling Kenna Security. We helped pioneer the category of risk-based vulnerability management, but it became clear that defending against AI-driven threats and the growing volume of potential exploits would require a fundamentally new approach. Today, we finally have the technology to give security teams predictive capabilities that weren’t possible before, and we came together to build that future.”

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2018 RegTech Analyst

Investors

The following investor(s) were tagged in this article.