<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url><loc>https://rootevidence.com/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/5-000-000-mythos-era-warranty/</loc><lastmod>2026-06-19T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/a-post-vm-warranty-world/</loc><lastmod>2025-10-12T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/ai-and-cves-a-contrarian-view/</loc><lastmod>2026-08-24T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/ai-and-the-acceleration-of-cves/</loc><lastmod>2025-11-20T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/ai-and-the-artisan-vulnerability-researcher/</loc><lastmod>2026-05-04T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/ai-failure-mode-lie-and-how-will-that-impact-vulnerability-management/</loc><lastmod>2026-05-14T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/ai-malware-woes/</loc><lastmod>2026-04-22T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/ai-security-will-be-bolted-on/</loc><lastmod>2026-04-16T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/announcing-the-evidence-scan-enterprise-preview/</loc><lastmod>2026-03-09T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/application-security-won-the-industry-missed-it/</loc><lastmod>2026-04-09T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/at-the-risk-of-cvss/</loc><lastmod>2025-10-20T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/companies-buried-in-vulnerabilities-still-get-insured-how/</loc><lastmod>2026-03-24T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/cvss-9-8/</loc><lastmod>2026-06-25T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/cvss-base-scores/</loc><lastmod>2025-10-27T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/cvss-v4-vs-v3/</loc><lastmod>2025-12-22T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/cyber-security-incentives/</loc><lastmod>2026-01-26T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/datasources-are-not-created-equal/</loc><lastmod>2026-02-06T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/do-financially-motivated-hacking-groups-innovate-the-numbers-say-no/</loc><lastmod>2025-08-20T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/does-epss-first-make-sense/</loc><lastmod>2025-09-03T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/evaluating-ai-in-infosec/</loc><lastmod>2026-06-11T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/evidence-2025-year-in-review/</loc><lastmod>2025-12-30T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/explaining-the-myth-of-mythos/</loc><lastmod>2026-05-05T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/exploitation-vs-loss/</loc><lastmod>2025-09-10T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/fast-scanning-and-dwell-time/</loc><lastmod>2025-12-04T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/from-aristotle-to-cvss-why-first-principles-matter-in-cyber-risk/</loc><lastmod>2026-01-22T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/how-do-you-explain-your-vulnerability-prioritization-strategy-post-breach/</loc><lastmod>2025-08-28T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/its-not-their-fault-they-did-the-best-they-could-at-the-time/</loc><lastmod>2026-04-21T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/just-fix-everything/</loc><lastmod>2026-06-09T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/millions-of-vulns/</loc><lastmod>2026-02-11T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/moneyball-in-infosec/</loc><lastmod>2026-01-13T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/mythos-preview-vs-vm-reality-what-changes-when-ai-finds-everything/</loc><lastmod>2026-05-01T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/nulns/</loc><lastmod>2025-09-23T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/oems-are-licensing-the-same-vm-tool-in-different-colors-and-its-a-credibility-problem/</loc><lastmod>2026-06-30T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/paradoxes-of-vulnerability-management/</loc><lastmod>2025-08-26T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/patching-rosi-math/</loc><lastmod>2025-12-11T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/peak-patch-management-and-busy-work/</loc><lastmod>2026-01-20T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/removing-3rd-party-cves/</loc><lastmod>2026-05-12T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/replacing-security-theatre-with-real-risk-reduction/</loc><lastmod>2025-11-19T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/stop-chasing-cves/</loc><lastmod>2026-10-01T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/stoplight-infosec/</loc><lastmod>2025-09-13T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/subrogation-lawsuits-as-peer-pressure/</loc><lastmod>2026-04-01T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/the-ai-vulnerability-surge-that-doesnt-change-a-thing/</loc><lastmod>2026-04-07T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/the-biggest-challenges-of-100-vulnerability-management-practitioners/</loc><lastmod>2025-09-18T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/the-blue-team-is-a-losing-mans-game/</loc><lastmod>2026-04-29T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/the-cognitive-bias-behind-cyber-risk-scoring/</loc><lastmod>2026-01-09T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/the-conjoined-triangles-of-evidence-based-prioritization/</loc><lastmod>2025-09-12T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/the-cost-of-cybersecurity-will-exceed-the-cost-of-breach/</loc><lastmod>2026-04-14T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/the-dark-energy-of-orphaned-external-it-devices/</loc><lastmod>2026-01-29T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/the-difference-between-vuln-severity-and-financial-exposure/</loc><lastmod>2026-03-05T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/the-epoch-theory-of-cybersecurity/</loc><lastmod>2025-10-13T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/the-importance-of-prebuilt-easm/</loc><lastmod>2025-12-18T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/the-kpi-weve-been-missing-in-vulnerability-management/</loc><lastmod>2025-08-27T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/the-lion-isnt-always-in-the-bushes/</loc><lastmod>2026-09-03T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/the-myth-of-objective-security-scoring-models/</loc><lastmod>2025-08-23T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/the-rational-rejection-of-vulnerability-management/</loc><lastmod>2025-11-04T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/the-story-behind-the-end-of-guessing/</loc><lastmod>2026-08-04T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/the-unit-cost-of-infosec/</loc><lastmod>2025-11-13T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/the-vulnerability-management-warranty/</loc><lastmod>2026-01-06T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/vars-arent-making-the-money-they-used-to-selling-vulnerability-management/</loc><lastmod>2026-07-27T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/vulnerability-management-has-always-been-about-evidence/</loc><lastmod>2025-11-07T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/we-are-security-optimists/</loc><lastmod>2025-08-18T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/what-does-defensibility-mean-to-a-ciso/</loc><lastmod>2026-06-01T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/what-due-care-actually-means-in-vulnerability-management/</loc><lastmod>2026-05-20T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/what-enterprises-get-wrong-about-vulnerability-management-roi/</loc><lastmod>2025-09-30T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/what-infosec-doesnt-understand-about-cyber-insurance/</loc><lastmod>2025-12-15T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/what-is-the-remediation-cut-off-point-in-vulnerability-management/</loc><lastmod>2025-09-03T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/when-old-assumptions-move-aside-and-evidence-takes-over/</loc><lastmod>2025-12-09T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/who-measures-risk-better/</loc><lastmod>2026-02-04T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/why-mssps-are-getting-fired-and-probably-know-it/</loc><lastmod>2026-06-16T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/why-we-built-evidence-scan-the-way-we-did/</loc><lastmod>2026-03-12T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/why-we-built-the-evidence-platform/</loc><lastmod>2026-07-28T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/why-zero-day-doesnt-belong-in-a-vulnerability-management-discussion/</loc><lastmod>2025-09-02T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog-posts/zero-day-is-not-what-you-think/</loc><lastmod>2026-09-22T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/blog/</loc></url>
  <url><loc>https://rootevidence.com/claims/</loc></url>
  <url><loc>https://rootevidence.com/company/about/</loc></url>
  <url><loc>https://rootevidence.com/contact/</loc></url>
  <url><loc>https://rootevidence.com/dealreg/</loc></url>
  <url><loc>https://rootevidence.com/get-started/demo/</loc></url>
  <url><loc>https://rootevidence.com/media/</loc></url>
  <url><loc>https://rootevidence.com/news/</loc></url>
  <url><loc>https://rootevidence.com/news/root-evidence-launches-evidence-scan-enterprise-preview/</loc><lastmod>2026-03-10T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/news/root-evidence-launches-full-platform/</loc><lastmod>2026-07-28T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/news/root-evidence-launches/</loc><lastmod>2025-09-25T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/news/root-evidence-report-q1-2026/</loc><lastmod>2026-06-11T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/news/the-end-of-guessing-book-debut/</loc><lastmod>2026-08-04T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/news/root-evidence-finds-the-vulnpocalypse-isnt-showing-up-in-the-data/</loc><lastmod>2026-09-03T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/privacy-policy/</loc></url>
  <url><loc>https://rootevidence.com/products/platform/</loc></url>
  <url><loc>https://rootevidence.com/products/reporting/</loc></url>
  <url><loc>https://rootevidence.com/products/scan/</loc></url>
  <url><loc>https://rootevidence.com/products/surface/</loc></url>
  <url><loc>https://rootevidence.com/products/warranty/</loc></url>
  <url><loc>https://rootevidence.com/report/</loc></url>
  <url><loc>https://rootevidence.com/reports/</loc></url>
  <url><loc>https://rootevidence.com/resources/reports/vulnpocalypse-report-2026/</loc><lastmod>2026-09-03T00:00:00+00:00</lastmod></url>
  <url><loc>https://rootevidence.com/resources/webinars/</loc></url>
  <url><loc>https://rootevidence.com/resources/webinars/vulnpocalypse-2026/</loc></url>
  <url><loc>https://rootevidence.com/resources/webinars/where-attacks-actually-come-from/</loc></url>
  <url><loc>https://rootevidence.com/resources/webinars/ai-and-nation-states/</loc></url>
  <url><loc>https://rootevidence.com/scanners/</loc></url>
  <url><loc>https://rootevidence.com/security-commitments/</loc></url>
  <url><loc>https://rootevidence.com/security-txt/</loc></url>
  <url><loc>https://rootevidence.com/solutions/enterprise/</loc></url>
  <url><loc>https://rootevidence.com/solutions/insurance-carriers/</loc></url>
  <url><loc>https://rootevidence.com/solutions/mssps-mdrs/</loc></url>
  <url><loc>https://rootevidence.com/subprocessors/</loc></url>
  <url><loc>https://rootevidence.com/terms/</loc></url>
</urlset>
