Empirical Security raises $25m to predict which cyber flaws hackers exploit
A Chicago startup has raised $25 million to build AI models that predict which software vulnerabilities attackers will actually weaponise, a potential lifeline for overstretched corporate security teams facing a surge in automated threats.
Empirical Security has closed a $25 million Series A funding round to tackle a persistent problem in corporate cybersecurity: identifying which software vulnerabilities attackers will actually exploit. The round was led by Brightmind Partners, with participation from earlier backers Costanoa Ventures and Hyde Park Angels. It brings the company's total funding to $37 million.
Corporate security teams are routinely overwhelmed by volume. As businesses adopt more cloud infrastructure, software-as-a-service applications, and third-party code, the backlog of potential flaws grows faster than IT departments can patch them. Traditional methods rely on static severity scores that treat every vulnerability equally, often leaving firms blindly prioritising generic alerts.
Empirical Security is betting that artificial intelligence can cut through this noise by forecasting real-world attacks. The company sells two predictive models. Foundation tracks active exploitation across more than 18,000 known vulnerabilities (CVEs) to monitor global threat trends. Radiant operates locally, training on an individual organisation's specific assets, cloud setup, and telemetry to forecast which threats pose the greatest danger to that particular environment.
The company's leadership brings relevant experience. Chief executive Ed Bellis and chief technology officer Michael Roytman previously founded Kenna Security, a firm that helped pioneer risk-based vulnerability management. Bellis has referred to his new company as his "unfinished business." He has also recruited Jay Jacobs, the co-creator of the widely used EPSS exploit-scoring system.
The company's pitch capitalises on a critical shift in the cyber threat landscape. Attackers are now using artificial intelligence to discover and weaponise software flaws faster than ever before, significantly shrinking the window for corporate defence. Bellis argues that until recently, security data was too fragmented and machine learning models were too immature to make accurate predictions.
That calculus is changing. Corporate security systems now aggregate vast amounts of telemetry into centralised data lakes. Advancements in AI allow these models to reason over massive datasets and train on actual exploitation rather than theoretical risk.
Empirical is entering a crowded market for AI-driven defence and exposure management, and a $25 million raise is relatively modest by sector standards. The company's performance claims currently rely on its own data, though it notes that one customer reported its engineers are "addicted" to checking the tool daily. For investors and corporate risk managers, the broader bet is that tailored prediction will now beat generic risk scores, making proactive AI a baseline requirement for modern defence.