Root Evidence Rethinks Vulnerability Management
Techstrong TV Interviews
•
23m
Vulnerability Management Needs Better Evidence
Alan Shimel speaks with Jeremiah Grossman and Robert Hansen during Techstrong TV’s Black Hat coverage. The discussion focuses on vulnerability management, exploitability and the long-running challenge of deciding what security teams should fix first. Grossman and Hansen argue that the industry has spent years chasing too many vulnerabilities. Root Evidence is designed to shift that work toward breach-backed evidence.
The conversation starts with the guests’ deep cybersecurity backgrounds. Hansen has spent decades in offensive security, red teaming and CTO roles. Grossman has focused on solving hard security problems across large enterprises. Together, they explain why vulnerability management still feels unresolved after more than 25 years. Security teams can find huge numbers of issues. The harder problem is knowing which ones matter.
Only a Small Set of Vulnerabilities Drive Loss
Grossman and Hansen describe research based on cyber insurance and incident response data. Their conclusion is direct. Only a small percentage of vulnerabilities have led to breach or financial loss. Hansen says that figure has stayed around 1.4% in their analysis. That means most vulnerabilities may be software bugs, but they are not the same as proven breach drivers.
This matters because security teams have limited capacity. If every vulnerability appears urgent, teams can waste time on work that does not reduce real risk. Root Evidence aims to focus attention on vulnerabilities that adversaries actually use. That approach gives defenders a clearer way to prioritize remediation.
Attack Surface Mapping Becomes Part of the Warranty
The discussion also covers external attack surface management. Hansen explains that teams need to know what assets they have before they can scan them. Root Evidence maps the external attack surface first. It then scans those assets for the vulnerabilities tied to real-world breach and loss data.
The company also offers a warranty model. If a breach occurs because of a vulnerability or exposed asset that was missed, the customer can receive a payout. That makes the warranty more than a sales promise. It creates a feedback loop that pushes the system to improve over time.
Security Teams Need Fewer Guesses
Grossman and Hansen frame their work as an effort to end guessing in vulnerability management. Instead of relying only on broad scores or theoretical exploitability, they want teams to act on evidence from real incidents. That could help security leaders reduce noise, focus remediation and measure risk in a more practical way.
For organizations overwhelmed by vulnerability backlogs, the message is simple. Not every issue deserves the same response. Root Evidence makes the case that breach-backed data, daily scanning and external attack surface visibility can help teams fix what matters first.
Up Next in Techstrong TV Interviews
-
Vega Brings AI Reasoning to Cyber Def...
AI Reasoning Changes the Cyber Defense Model
Alan Shimel speaks with Eli Rozen, co-founder and CTO of Vega, during Techstrong TV’s Black Hat coverage. Their conversation focuses on large language models and frontier AI reasoning. These tools are changing the balance between attackers and defender... -
SANS Brings AI Into Cybersecurity Tra...
Cybersecurity Training Evolves for the AI Era
Alan Shimel speaks with Ed Skoudis, president of the SANS Technology Institute, during Techstrong TV’s Hacker Summer Camp and Black Hat coverage. The conversation explores how SANS is evolving its cybersecurity training programs as AI changes the way ... -
The Case for Global Open Source Security
Global open source security is the debate of the summer. Mike Milinkovich, Executive Director of the Eclipse Foundation, joins Alan Shimel to unpack the European Cyber Resilience Act, the Mythos vulnerability wave and why the next chapter has to be a federated global effort, not another US-only i...