In a blog post announcing $25 million in new funding on July 20, 2026, Ed Bellis reached for an unusual phrase for a funding announcement: unfinished business. “Empirical exists because I had unfinished business,” he wrote, describing a feeling that had followed him for years after selling his last cybersecurity company to Cisco.
That sentence is the shortest possible summary of Ed Bellis Empirical Security, a startup built by the same team that pioneered an entire category of cybersecurity once before, now trying to solve the part of the problem they never quite finished.
Bellis is the co-founder and CEO of Empirical Security, a Chicago-based cybersecurity company building predictive AI models that tell security teams which vulnerabilities attackers will actually exploit, rather than treating every flaw as equally urgent.
The new Series A funding, led by Brightmind Partners, brings Empirical’s total funding to $37 million just two years after its founding.
Where Ed Bellis Came From
Long before founding Empirical Security, Bellis built his cybersecurity credentials from the inside of two very different organizations: as vice president of corporate information security at Bank of America, and later as chief information security officer at Orbitz, the online travel company. It was at Orbitz that Bellis has said he first realized that staying ahead of the next threat would be impossible without a way to know which vulnerabilities actually posed the greatest risk to the business, rather than treating every flaw on a list as equally dangerous.
That realization led him to found HoneyApps, which became Risk I/O, and eventually Kenna Security, the company that came to define an entire cybersecurity category known as risk-based vulnerability management. Bellis became known in security circles as “the father of risk-based vulnerability management,” and co-authored the book “Modern Vulnerability Management” with his future Empirical Security co-founder, Michael Roytman, who served as Kenna’s chief data scientist. Cisco acquired Kenna Security in 2018, and Bellis went on to lead data science and AI for Cisco’s Threat Detection and Response organization.
Why Cybersecurity Needed Empirical Security
Security teams today face a familiar, worsening problem: far more known vulnerabilities than anyone has time to fix, and no reliable way to know which ones attackers will actually use. Generic, one-size-fits-all risk scores, the kind Kenna Security helped popularize a decade earlier, have started to show their age as AI accelerates both the volume and sophistication of attacks, according to Empirical’s own funding materials.
Bellis has described the founding of Empirical as picking up work he and Roytman started at Kenna but couldn’t fully finish with the technology available at the time. “When Michael Roytman and I were building Kenna Security, we helped create what became known as risk-based vulnerability management,” he wrote, before explaining that defending against AI-driven threats now demands a fundamentally more predictive, organization-specific approach than even Kenna could offer.
How Empirical Security Actually Works
Empirical Security’s product line centers on two models. Foundation is a global predictive model that monitors more than 18,000 exploited CVEs (Common Vulnerabilities and Exposures) to identify emerging attack patterns across the broader threat landscape. Radiant is a custom predictive engine, fine-tuned on each customer’s own infrastructure and data, designed to surface the vulnerabilities most relevant to that specific organization’s environment rather than relying on industry-wide averages.
The company’s technical credibility runs deeper than its two co-founders. Empirical’s chief data scientist, Jay Jacobs, co-created the Exploit Prediction Scoring System, known as EPSS, a widely adopted industry standard for estimating the probability that a given vulnerability will be exploited in the wild. Having one of EPSS’s original creators on the founding team gives Empirical Security a level of technical authority in exploit prediction that is difficult for newer entrants to match.
The Money Behind Empirical Security: $37 Million
Ed Bellis Empirical Security raised a $25 million Series A, announced July 20, 2026, led by Brightmind Partners, with returning participation from earlier backers Costanoa Ventures and Hyde Park Angels. The round follows a $12 million seed round closed in July 2025, bringing the company’s total funding to $37 million within roughly two years of its founding.
The company says the new capital will accelerate development and deployment of both Foundation and Radiant, as organizations increasingly need to defend against threats generated or accelerated by AI itself, a dynamic that didn’t exist in the same form when Bellis and Roytman were building Kenna Security a decade earlier.
What Empirical Security Has Proven So Far
Unlike many Series A cybersecurity startups still validating their core technology, Empirical Security enters this funding round with a founding team that has already built and sold a company built on a closely related thesis. That track record functions as a form of proof independent of Empirical’s own customer traction, which the company has kept largely private; reporting on the round has noted that Empirical has not disclosed a valuation or named specific enterprise customers.
What is publicly verifiable is the technical pedigree behind the product: Bellis and Roytman’s prior work defined an entire vulnerability management category at Kenna, and Jacobs’ EPSS system is independently used across the security industry today, giving outside observers a way to evaluate the team’s credibility even without customer-specific data points.
Who’s Betting on Ed Bellis
Brightmind Partners’ decision to lead Empirical’s Series A, with Costanoa Ventures and Hyde Park Angels both returning from the seed round, signals sustained investor conviction in the founding team specifically, not just the category. Returning seed investors leading into a Series A is generally a stronger signal than fresh investor interest alone, since it reflects continued confidence built on information those investors already had access to as company insiders.
That pattern, repeat investors deepening their bet rather than a company needing to win over an entirely new investor base, mirrors the kind of quiet, credentialed confidence that has also shaped investor decisions in other repeat-founder cybersecurity stories, including Ben Volkow’s fourth company, QIZ Security, which Bessemer Venture Partners backed for a fourth consecutive time earlier in 2026.
Empirical Security Against the Competition
Ed Bellis Empirical Security operates inside the exposure management category, competing against both established vulnerability management vendors and newer AI-driven entrants. According to Tracxn, Empirical’s listed competitors include Darktrace, Enkrypt AI, and Protect AI, though Empirical’s specific focus on organization-specific, custom-trained exploit prediction differentiates it from more general-purpose AI security platforms.
The broader exposure management and AI-agent security funding environment has been active in 2026, with well-funded new entrants like Neo emerging from stealth with $100 million in combined seed and Series A funding the same week as Empirical’s own announcement, underscoring how much capital is chasing the specific problem of securing systems against AI-accelerated threats.
Where Ed Bellis Takes It From Here
With fresh Series A capital in hand, Empirical Security’s near-term priorities center on scaling both Foundation and Radiant and converting the credibility built at Kenna Security into real enterprise adoption for a genuinely different product built for a different threat landscape. Bellis has framed the moment as one where the technology to build predictive, organization-specific security intelligence finally exists in a way it didn’t when he and Roytman first attempted a version of this idea.
Longer term, Empirical’s bet is that exposure management will keep shifting away from static, generic scoring toward continuously updated, organization-specific prediction, a shift the founding team is betting its combined credibility, rather than a first-time pitch, can help it win.
What Other Founders Can Take From This
Bellis’s path offers a clear lesson for founders who feel they left a problem only partially solved at a previous company: returning to that exact problem with a reunited team and new technology can be a stronger pitch than starting fresh with an unrelated idea. Second, recruiting Jay Jacobs, a genuine co-creator of an industry-standard scoring system, gave Empirical technical credibility that exists independently of the founders’ own reputations, a distinct asset separate from Bellis and Roytman’s Kenna Security pedigree.
Third, framing Empirical’s founding around “unfinished business” rather than a purely new opportunity gave investors already familiar with Kenna Security a clear, low-friction way to understand exactly what had changed and why now was the right time to back the same team again.
Frequently Asked Questions
Who is Ed Bellis? Ed Bellis is the co-founder and CEO of Empirical Security. He previously founded Kenna Security, which Cisco acquired in 2018, and is known in the cybersecurity industry as “the father of risk-based vulnerability management.”
What does Empirical Security do? Empirical Security builds AI models that predict which cybersecurity vulnerabilities are most likely to be exploited, using a global model called Foundation and a custom, organization-specific model called Radiant, rather than relying on generic risk scores.
How much funding has Empirical Security raised? Empirical Security has raised $37 million total: a $12 million seed round in July 2025, and a $25 million Series A announced July 20, 2026, led by Brightmind Partners with participation from Costanoa Ventures and Hyde Park Angels.
Who co-founded Empirical Security with Ed Bellis? Empirical Security was co-founded by Ed Bellis, Michael Roytman, who serves as chief technology officer and previously was chief data scientist at Kenna Security, and Jay Jacobs, chief data scientist and co-creator of the Exploit Prediction Scoring System (EPSS).
What is the connection between Empirical Security and Kenna Security? Empirical Security’s CEO and CTO, Ed Bellis and Michael Roytman, previously co-founded Kenna Security, which pioneered risk-based vulnerability management before Cisco acquired it in 2018. Empirical was built to solve problems the founders felt Kenna’s technology couldn’t fully address at the time.
Where is Empirical Security based? Empirical Security is headquartered in Chicago, Illinois, and was founded in 2024.
Conclusion
Whether Empirical Security’s specific bet on organization-specific, AI-driven exploit prediction becomes the next Kenna Security or simply one credible entrant in an increasingly crowded exposure management category will likely take a few years to become clear. What’s harder to dispute is the credibility of the team making the bet: a founder who literally helped name the category he’s now trying to improve, reunited with a co-founder from the same original company, plus one of the actual creators of the industry’s standard exploit-prediction scoring system.
For readers following other repeat founders betting on unfinished business, Ben Volkow’s fourth company, QIZ Security, and Mahesh Sathiamoorthy’s reunion with his own former mentor at Bespoke Labs, are worth a look on Denote Press, alongside Mahdi Abdulrazak’s own security-by-design startup, Dawnguard.
