# Security's Prediction Problem Just Got $25 Million Worth of Investor Attention
The cybersecurity industry has spent twenty years perfecting the art of cleaning up after the fact. Alerts, incident response, forensics, post-breach remediation — an entire economy built around the assumption that attackers get in, and then you deal with it. Empirical Security thinks that's backwards, and this week it has $25 million in Series A funding to prove it.
The San Francisco-based startup raised the round to accelerate development of its threat prediction and discovery products — language that sounds anodyne until you think about how hard that problem actually is.
## What "Prediction" Actually Means Here
Threat prediction is one of those terms the security industry has abused into near-meaninglessness. Every SIEM vendor promises it. Every threat intelligence platform implies it. Most of what they deliver is pattern matching with extra steps: if we saw this indicator before, flag it again.
Real predictive capability — knowing where attackers are likely to go before they move — is a different animal. It requires modeling adversary behavior, understanding your own attack surface with unusual clarity, and correlating that against the current threat landscape in something close to real time.
The "discovery" half of Empirical's pitch is equally load-bearing. Organizations consistently overestimate how well they know their own perimeter. Shadow IT, forgotten cloud assets, exposed credentials in code repositories, subdomains that predate anyone currently on staff — the average enterprise attack surface contains assets nobody in security knows exist. Discovery isn't glamorous, but it's foundational to everything else.
Empirical's bet appears to be that prediction without complete discovery is guesswork, and discovery without prediction is just building a map you'll never use. Connecting those two workflows is the product thesis.
## Why $25 Million Now
Cybersecurity funding tightened significantly through 2023 and 2024 as the broader VC market corrected. Categories that had attracted frothy valuations — XDR platforms, identity security, cloud-native tools — saw consolidation and down rounds. Investors who had written blank checks on "AI-powered security" watched a lot of those companies fail to differentiate.
The Series A environment in 2025 and into 2026 has been more selective. Capital is still moving, but it's moving toward startups with defensible technical differentiation rather than marketing positioning. A $25 million Series A for a threat prediction company signals that investors see Empirical as the former.
The timing also reflects broader anxiety in enterprise security teams. The major breach patterns of the past two years — compromised credentials, supply chain attacks, legitimate tools weaponized for lateral movement — share a common thread: they're hard to detect in progress because they look like normal activity. Detection-centric tools struggle by design. Prediction tools, if they work, change the question from "what just happened?" to "where is the exposure before it gets exploited?"
Whether Empirical's approach actually delivers that is still unproven at scale. But the demand signal is real.
## The Crowded Perimeter of an Uncrowded Idea
The attack surface management space Empirical operates adjacent to has several established players — Axonius in asset management, Censys and Shodan for internet exposure scanning, Bitsight and SecurityScorecard for vendor risk. Threat intelligence platforms like Recorded Future and Mandiant Advantage offer their own flavor of prediction. CrowdStrike and SentinelOne have acquisition-fueled their way into threat discovery.
What none of them fully solves is the hand-off problem. Discovery happens in one tool. Threat intelligence lives in another. Prioritization gets done manually by an analyst who is probably already exhausted. The $25 million question is whether Empirical can close that gap into a single coherent workflow — and whether it can do so for organizations that don't have a twenty-person security team to operate it.
The enterprises that need this most are mid-market companies: large enough to have complex attack surfaces, too small to have dedicated threat intelligence analysts. That's a viable market if you can build something that works without heavy customization.
## What Investors Are Betting On
The underlying technology trend this funding tracks is the application of large-scale data analysis to adversary behavior — not just threat indicators, but the structural patterns that precede attacks. Where are attackers probing? What credentials are showing up in dark web markets? What configurations make organizations statistically more likely to be successfully phished, ransomed, or compromised through a third party?
If Empirical can aggregate and model that data reliably, the product pitch writes itself to CISOs who are tired of explaining breaches to boards. "We had visibility" is table stakes. "We saw it coming and closed the window" is a different conversation.
The risk is that threat prediction remains perpetually eighteen months from reliable. The adversary landscape shifts fast, training data goes stale, and the edge cases — novel threat actors, zero-day campaigns, supply chain vectors that haven't been seen before — are exactly where prediction models fail.
## HackWire Analysis
Twenty-five million dollars for threat prediction sounds like exactly the kind of thing the security industry loves to fund and then quietly struggle to operationalize. But there are a few reasons this particular moment may be different.
The first is compute. The machine learning models required to do genuine behavioral prediction — not just indicator matching — have become dramatically cheaper to train and run over the past two years. A company building this in 2019 would have faced infrastructure costs that made the unit economics unworkable for mid-market customers. That constraint has relaxed substantially.
The second is data scale. The major breach patterns of the past five years have created an unusually rich corpus of adversary behavior that didn't exist a decade ago. Ransomware-as-a-service groups follow playbooks. Initial access brokers advertise specific target types. The footprint of modern attacker infrastructure is measurably larger and more consistent than it used to be. That makes prediction more tractable.
The third is market pressure. Regulatory requirements — NIS2 in Europe, SEC disclosure rules in the US, a dozen sector-specific frameworks — are pushing organizations toward demonstrating proactive security posture rather than just reactive capability. Threat prediction tools let CISOs make that case in board presentations and regulatory filings in a way that endpoint detection alone cannot.
What to watch: whether Empirical's "discovery" capability genuinely finds unknown assets or just resurfaces things good organizations already know about. The differentiation lives in that detail. If their discovery is table stakes and their prediction is genuinely novel, this is a company worth tracking. If it's the reverse, they're the fifth ASM vendor in a slide deck comparison.
The security industry doesn't lack for tools. It lacks for tools that connect the dots before the breach rather than after. Empirical has eighteen months and fresh capital to show whether it can be one of the companies that actually does that.
— HackWire Editorial
---
## Related Coverage