Empirical Security has closed a $25m Series A round as it looks to arm security teams against the accelerating wave of AI-driven exploits.
Brightmind Partners led the investment, which builds on prior backing from Costanoa Ventures, Hyde Park Angels (HPA) and other investors, lifting the company’s total capital raised to $37m.
The fresh funds will be channelled into scaling the firm’s two core products. The first, Foundation, is a global model that tracks more than 18,000 exploited CVEs to help organisations anticipate threats.
The second, Radiant, is a bespoke predictive engine that is built and fine-tuned for each customer, surfacing the risks most pertinent to that organisation’s specific environment.
The raise comes as AI dramatically widens the volume and sophistication of cyber attacks, leaving security teams under growing strain to identify which potential exploits genuinely matter. Many security leaders have grown weary of legacy exposure management tools, which lean on generic risk scoring shaped by expert assumptions that go untested against real-world outcomes.
Empirical Security argues its models let lean teams separate authentic danger from noise and act more quickly on evidence rather than guesswork. Its customers span sectors where mistaken prioritisation carries heavy consequences, notably technology, healthcare and financial services.
The urgency is underlined by Verizon’s 2026 Data Breach Investigations Report, which drew on analysis from Empirical Security.
The study found vulnerability exploitation overtook stolen credentials as the top initial access route for breaches for the first time, with exploited software flaws behind 31% of confirmed incidents, a sharp climb from 20% a year earlier.
The business is steered by three founders credited with inventing risk-based vulnerability management and predictive intelligence. CEO Ed Bellis previously co-founded Kenna Security and remained CTO through its sale to Cisco, while CTO Michael Roytman was formerly Kenna Security’s chief data scientist.
The third founder, chief data scientist Jay Jacobs, co-created the Exploit Prediction Scoring System (EPSS), a threat model trained and maintained by Empirical Security, whose scores are published daily and freely available. Hundreds of firms, including Tenable, Qualys, Crowdstrike, Microsoft and Wiz, have integrated EPSS into their platforms.
Unlike conventional exposure platforms that apply identical threat data across every customer, the company constructs AI-enhanced predictive models tailored to each organisation, delivering evidence-based risk analysis that helps teams defend remediation choices to stakeholders without adding headcount.
Empirical Security co-founder and CEO Ed Bellis said, “I had unfinished business from my time building and selling Kenna Security. We helped pioneer the category of risk-based vulnerability management, but it became clear that defending against AI-driven threats and the growing volume of potential exploits would require a fundamentally new approach. Today, we finally have the technology to give security teams predictive capabilities that weren’t possible before, and we came together to build that future.”
Stay ahead of the market with the intelligence 120,000+ industry leaders rely on. Subscribe to the FinTech Global newsletter.
Copyright © 2026 FinTech Global









