Most security teams face the same problem. There are far more flaws than anyone can fix, and no clear way to know which ones matter. Empirical Security wants to predict the answer.

The Chicago startup’s Series A was led by Brightmind Partners, chief executive Ed Bellis told Axios, which first reported the round. It takes total funding to $37 million. Earlier backers Costanoa Ventures and Hyde Park Angels returned for the round.

Unfinished business

The pitch has history. Bellis and his chief technology officer, Michael Roytman, built Kenna Security, the firm that helped popularise risk-based vulnerability management. The idea was simple: stop treating every flaw the same, and focus on the ones most likely to be exploited.

It helped, but the job was never done. The backlog kept growing as cloud, SaaS, APIs, and third-party code piled on new exposure. Bellis calls Empirical his “unfinished business.” He has brought in Jay Jacobs, co-creator of the widely used EPSS exploit-scoring system.