Empirical Raises $25 Million to Predict Cyber Attacks Before They Happen

A Chicago startup says its AI tools can spot which security flaws are most likely to be exploited next. Investors just bet $25 million that it's right.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
Share

Key points

  • Empirical, a Chicago-based cybersecurity startup founded in 2024, raised $25 million in a Series A funding round led by Brightmind Partners.
  • The round brings Empirical's total funding to $37 million.
  • Empirical's flagship product, Foundation, watches more than 18,000 known exploited software flaws for signs of imminent attack.
  • The company's second product, Radiant, tailors threat predictions to each individual organisation's systems.
  • The founding team previously built Kenna Security and co-created EPSS, a widely used scoring system that estimates how likely a given software flaw is to be attacked.

Most security teams already know they have too many problems to fix and not enough time. The real question is: which ones will criminals actually exploit this week? Empirical, a startup that launched in 2024, says it can answer that.

The company announced a $25 million Series A round, meaning the first large institutional investment after early seed money. Brightmind Partners led the round, with Costanoa Ventures and Hyde Park Angels also participating. Total funding now sits at $37 million.

What does Empirical's software actually do?

It watches known software vulnerabilities, which are flaws in programs that criminals can use to break in, and predicts which ones are most likely to be weaponised next. The Foundation product monitors more than 18,000 CVEs (Common Vulnerabilities and Exposures, the standard catalogue of publicly known software flaws) at any given time. Radiant then narrows that global picture down to the specific risks that matter for a particular company's setup.

The pitch is prediction over reaction. Rather than waiting for an attack to start and then scrambling, Empirical wants security teams to patch the right things first, before criminals get there.

The team behind it is not new to this problem. CEO Ed Bellis and CTO Michael Roytman both co-founded Kenna Security, an earlier company that pioneered risk-based vulnerability management, meaning ranking security problems by likely real-world impact rather than treating every flaw as equally urgent. Chief Data Scientist Jay Jacobs co-created the Exploit Prediction Scoring System (EPSS), a freely available model that estimates the probability of a given flaw being exploited within 30 days.

Bellis told SecurityWeek that defending against the current volume of threats "would require a fundamentally new approach," and that AI now makes predictive capabilities possible that simply were not viable before.

Empirical is targeting security teams in healthcare, financial services, and technology. All three sectors carry high stakes: a hospital hit by ransomware (malicious software that locks files until a ransom is paid) cannot afford downtime the way a slow software patch can create.

For ordinary people, this kind of tool sits in the background. You will never see it. But if it works, the companies holding your medical records or bank details patch the right holes before criminals find them, rather than after.

The practical takeaway for individuals stays the same regardless: keep software updated, use strong unique passwords, and turn on two-step verification, meaning a second login check beyond just a password, wherever it is offered. Predictive tools help the people guarding your data. Those habits help you guard your own.

© 2026 Threat Vectr