Back Morningstar Root Evidence Launches Full Platform to Help Security Teams Stop Chasing Millions ...
Root Evidence Launches Full Platform to Help Security Teams Stop Chasing Millions of Vulnerabilities and Start Preventing Financial Loss
Company introduces a new way to measure cyber risk, one grounded in evidence instead of assumptions
Root Evidence , the cybersecurity startup championing evidence-based security, launched its full platform today with a simple premise: The cybersecurity industry has been measuring the wrong thing.
For decades, organizations have measured cyber risk by the number of vulnerabilities discovered, severity scores assigned, and critical findings remediated. Yet despite more tools, more alerts, and more data than ever before, organizations continue to suffer costly ransomware attacks, business disruption, and record cyber insurance losses. Root Evidence believes it's time for a different approach.
Today, the company introduced the Evidence Platform, the industry’s first evidence-based approach to vulnerability management. Instead of prioritizing vulnerabilities based primarily on theoretical severity, Root Evidence helps security teams focus on the small percentage of vulnerabilities that have consistently resulted in real-world financial loss.
“The cybersecurity industry has become exceptionally good at finding vulnerabilities, but it has not become significantly better at preventing financial loss,” said Jeremiah Grossman, CEO and co-founder of Root Evidence. “As a whole, we’ve optimized for finding problems instead of proving which ones actually matter. Security leaders require better evidence rather than another tool that will simply increase their workload.”
Recent research from Omdia found that growing numbers of threats and exposures are leaving many organizations unable to remediate everything, increasing demand for technologies that provide greater context for security decisions and risk reduction.
“Security teams have no shortage of vulnerability data; the challenge is determining which exposures are most likely to affect business outcomes,” said Theresa Lanowitz, principal analyst, vulnerability and risk management at Omdia. “Organizations are increasingly looking for approaches that combine technical evidence, operational context, and financial impact so they can make more informed risk decisions.”
Evidence over assumptions
Built on cyber insurance claims, actuarial analysis, digital forensics intelligence, attack surface intelligence, and real-world breach data, Root Evidence introduces an evidence-based operating model for cybersecurity that helps organizations reduce noise, prioritize remediation, and focus resources where they will have the greatest business impact.
“For years, the industry has forced security teams to make critical remediation decisions using theoretical severity scores and assumptions,” said Robert Hansen, CTO and co-founder of Root Evidence. “We believe organizations should prioritize vulnerabilities using evidence: real-world financial loss, cyber insurance claims, digital forensics, and observed attacker behavior. That’s a fundamentally different way to think cyber risk.”
The result is a simple new decision framework: Stop prioritizing vulnerabilities by severity and start prioritizing them by evidence of financial loss.
Confidence backed by Evidence
To reinforce confidence in its methodology, Root Evidence is also introducing the Mythos Warranty. Under the warranty, customers receive up to $5 million in financial loss protection for covered events resulting from a CVE Root Evidence did not identify and report. The warranty is backed by cyber insurance underwriting partners that independently evaluated Root Evidence's methodology and agreed to underwrite the risk.
“The Mythos Warranty isn’t simply Root Evidence making a promise,” said Grossman. “Independent cyber insurance underwriters evaluated our methodology and agreed to stand behind it financially. This isn’t an indication of confidence in our evidence; it’s validation by the same industry that pays for cyber losses every day.”
The Evidence Platform combines continuous attack surface visibility, evidence-based vulnerability prioritization, executive reporting, and risk communication to help organizations make faster, more confident remediation decisions. The full platform includes:
Today’s launch also marks the beginning of a broader industry education initiative focused on challenging long-held assumptions vulnerability management. Through original research, educational content, and its inaugural report, “ Stop Counting CVEs: What Actually Mattered ,” Root Evidence will examine why more vulnerability findings haven’t reduced breaches, what actually drives financial loss, and how organizations can make more effective remediation decisions using evidence instead of assumptions.
“We’re introducing a better way to make cybersecurity decisions,” said Grossman. “We believe the future of cybersecurity will be defined by who provides the best evidence for what to fix first. The generation of cybersecurity products will measure risk using actuarial evidence, financial outcomes and real-world loss data. We believe that this is the direction that the industry is headed and we are building towards that future.”
Grossman details how today's launch will positively impact the cybersecurity industry on the Root Evidence blog . For more the Evidence Platform, visit the website or meet Grossman, Hansen and t he Root Evidence team week at Black Hat in Las Vegas, August 4-6.
Root Evidence is a cybersecurity company pioneering evidence-based vulnerability management to help organizations focus on the small percentage of vulnerabilities that are actually exploited in the wild, have caused reported breaches, and led to material financial losses. With Root Evidence, security teams can measurably reduce financial risk, prioritize remediation efforts where they have the greatest impact, and reduce the likelihood of breaches. Founded in 2025 by Jeremiah Grossman, Robert Hansen, Heather Konold, and Lex Arquette, the company is headquartered in Boise and backed by Ballistic Ventures , Grossman Ventures, and leading cybersecurity experts.
Media : Kylie Heintz [email protected]
View source version on businesswire.com:
The articles, information, and content displayed on this webpage may include materials prepared and provided by third parties. Such third-party content is offered for informational purposes only and is not endorsed, reviewed, or verified by Morningstar.
Morningstar makes no representations or warranties regarding the accuracy, completeness, timeliness, or reliability of any third-party content displayed on this site. The views and opinions expressed in third-party content are those of the respective authors and do not necessarily reflect the views of Morningstar, its affiliates, or employees.
Morningstar is not responsible for any errors, omissions, or delays in this content, nor for any actions taken in reliance thereon. Users are advised to exercise their own judgment and seek independent financial advice before making any decisions based on such content. The third-party providers of this content are not affiliated with Morningstar, and their inclusion on this site does not imply any form of partnership, agency, or endorsement.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
