Root Evidence Rethinks Vulnerability Management
23m
Vulnerability Management Needs Better Evidence
Alan Shimel speaks with Jeremiah Grossman and Robert Hansen during Techstrong TV’s Black Hat coverage. The discussion focuses on vulnerability management, exploitability and the long-running challenge of deciding what security teams should fix first. Grossman and Hansen argue that the industry has spent years chasing too many vulnerabilities. Root Evidence is designed to shift that work toward breach-backed evidence.
The conversation starts with the guests’ deep cybersecurity backgrounds. Hansen has spent decades in offensive security, red teaming and CTO roles. Grossman has focused on solving hard security problems across large enterprises. Together, they explain why vulnerability management still feels unresolved after more than 25 years. Security teams can find huge numbers of issues. The harder problem is knowing which ones matter.
Only a Small Set of Vulnerabilities Drive Loss
Grossman and Hansen describe research based on cyber insurance and incident response data. Their conclusion is direct. Only a small percentage of vulnerabilities have led to breach or financial loss. Hansen says that figure has stayed around 1.4% in their analysis. That means most vulnerabilities may be software bugs, but they are not the same as proven breach drivers.
This matters because security teams have limited capacity. If every vulnerability appears urgent, teams can waste time on work that does not reduce real risk. Root Evidence aims to focus attention on vulnerabilities that adversaries actually use. That approach gives defenders a clearer way to prioritize remediation.
Attack Surface Mapping Becomes Part of the Warranty
The discussion also covers external attack surface management. Hansen explains that teams need to know what assets they have before they can scan them. Root Evidence maps the external attack surface first. It then scans those assets for the vulnerabilities tied to real-world breach and loss data.
The company also offers a warranty model. If a breach occurs because of a vulnerability or exposed asset that was missed, the customer can receive a payout. That makes the warranty more than a sales promise. It creates a feedback loop that pushes the system to improve over time.
Security Teams Need Fewer Guesses
Grossman and Hansen frame their work as an effort to end guessing in vulnerability management. Instead of relying only on broad scores or theoretical exploitability, they want teams to act on evidence from real incidents. That could help security leaders reduce noise, focus remediation and measure risk in a more practical way.
For organizations overwhelmed by vulnerability backlogs, the message is simple. Not every issue deserves the same response. Root Evidence makes the case that breach-backed data, daily scanning and external attack surface visibility can help teams fix what matters first.