Skip to content

Why We Built the Evidence Platform

Why We Built the Evidence Platform

One year ago, the team at Root Evidence set out to solve one of cybersecurity’s biggest unsolved problems: vulnerability management.

Vulnerability management sits at the root of roughly one-third of all breaches. Solving that problem is no small feat, but doing so would have an extraordinary impact on organizations across every industry, and on cybersecurity as a whole.

That is our mission at Root Evidence.

Go as a team

One lesson we’ve learned over the years is that solving a problem becomes much easier once you truly understand it and can clearly articulate it. We started by studying every industry report, research paper, and dataset we could find. But that wasn’t enough. We needed to hear directly from the people living this problem every day.

After announcing Root Evidence, the support we received from friends and colleagues across the industry was overwhelming. We spent countless hours talking with CISOs, security teams, cyber insurers, incident responders, vulnerability researchers, and many others. Everyone was generous with their time, experience, and insights, helping us better understand the problem and narrow in on the solution. We asked a lot of questions, listened far more than we talked, and pressure tested our own assumptions every step of the way.

The platform we launched today is the result of those hundreds of conversations. To everyone who shared your experience, challenged our thinking, and believed this problem was worth solving, thank you. We couldn’t have built it without you.

Following the evidence

Depending on how you measure it, vulnerability exploitation accounts for roughly 20 to 40 percent of breaches. At the same time, the number of published vulnerabilities continues to grow every year, and advances in AI will only accelerate vulnerability discovery.

The reality is, security teams aren’t struggling because they lack visibility; they're struggling because they have too much of it.

In other words, the industry has become incredibly good at finding vulnerabilities. What we’ve struggled with is knowing which ones deserve our attention first.

This time, instead of asking how we could find more vulnerabilities, we challenged the premise. We asked a different question, because asking the right question is often more important than the answer.

Which vulnerabilities lead to financial loss?

As we dug into the data, it became clear that crucial information was missing to answer that question: There was very little actuarial evidence showing which vulnerabilities had ever resulted in financial loss. Not breach, but financial loss. Rather than guessing, we went right to the source: cyber-insurers and incident response investigators.

As we looked at their data, the insurance claims, digital forensics, and real-world breach data together, a pattern emerged. Today, there are more than 370,000 published CVEs, and that number grows by another 40,000 to 60,000 every year. Yet the vulnerabilities insurers are most concerned about because they’ve been tied to financial loss is only around 600.

That’s less than 0.2% — you would never go to Vegas with those odds. And knowing this changed everything.

With this piece of actuarial evidence in hand, it became clear what we needed to build.

Building for what matters

The Evidence Platform reflects everything we’ve learned, not just over the last year, but over a lifetime working in cybersecurity. The platform continuously discovers every internet-facing asset an organization owns, scans them daily to identify the vulnerabilities that have been proven to cause financial loss, and gives security teams a way to explain and defend their remediation decisions with evidence instead of guesswork.

This is important because we all know security teams are overwhelmed by vulnerability backlogs and don’t have unlimited time or resources to fix every vulnerability on every asset. Every remediation decision is a tradeoff. Choosing to fix one vulnerability means choosing not to spend that same time on something else.

That is why prioritization matters. By focusing on the vulnerabilities that have been proven to cause financial loss, organizations can reduce risk while making the best use of their limited resources. Security is not about fixing everything. It’s about fixing what matters most. For us, that means reducing financial loss.

To validate our approach, we went back to our trusted community and asked for feedback. The response was remarkably consistent. We heard, over and over, “This just makes sense.” Occasionally someone would add, “This is genius.”

Those conversations reminded us that cybersecurity is full of optimists. We all look at hard problems and ask, “How can we make this better?”

Still, this alone was not enough. Customers deserved something that would make this a no-brainer.

Putting money where our mouth is

This is something I am particularly passionate about and have been advocating for years. If a security vendor is bold enough to make a claim about the efficacy of their product, they should also be bold enough to stand behind it financially. They should share in the risk with their customers.

That’s why we introduced our Mythos Warranty, a first for vulnerability management. Root Evidence reimburses customers up to $5 million for financial losses resulting from the exploitation of a CVE that Root Evidence failed to notify them about. Coverage applies to all CVEs, subject to the warranty’s terms and conditions, not just those discovered by Mythos.

The warranty isn’t just a promise from us. It is backed by our cyber insurance partners. We didn’t ask them to take a leap of faith. They evaluated the same actuarial evidence and methodology we use to prioritize risk and agreed to underwrite the warranty. To us, that is independent validation. It demonstrates that the same evidence used to assess and insure cyber risk can also be used to make better cybersecurity decisions.

In the end, we weren’t asking insurers to agree with us. We were agreeing with them.

The work continues

Vulnerability management is a problem built up for more than 30 years, so it won’t be solved in one. We’ve made a huge leap forward, but still have a long road ahead. And we’re excited for it. To us, the platform is proof of what Security Optimism can accomplish together.

Our goal is helping organizations focus on the vulnerabilities that have the greatest impact on reducing risk and make better decisions using evidence instead of guesswork, and real-world loss data instead of theoretical severity scores. If we can do that, organizations will experience fewer breaches, less financial loss, and fewer people affected.

Thank you to everyone who helped us get this far.

← All posts