-

Cybersecurity Experts Jeremiah Grossman and Robert Hansen Call for the End of Guesswork in Cybersecurity

New book ‘The End of Guessing’ argues the cybersecurity industry must replace theoretical risk scores with evidence-based decision making

LAS VEGAS--(BUSINESS WIRE)--After decades spent helping define modern cybersecurity, Root Evidence Co-founders Jeremiah Grossman and Robert (RSnake) Hansen are challenging one of the industry’s most deeply held assumptions: that finding more vulnerabilities makes organizations more secure.

“For years we’ve accepted guessing as the cost of doing business in cybersecurity. We don’t think that's necessary anymore."

Share

Their new book, “The End of Guessing,” debuts this week at Black Hat USA, making the case that vulnerability management has become an exercise in managing volume rather than reducing risk. The authors argue that security teams are overwhelmed by millions of findings while lacking the evidence needed to determine which vulnerabilities actually lead to breaches

“The cybersecurity industry has spent decades optimizing for visibility,” said Grossman. “We’ve built better scanners, better dashboards, and more sophisticated scoring systems. What we've never done is focus on whether or not we have enough evidence to know whether we’re fixing the vulnerabilities that actually matter. That’s our focus at Root Evidence and the argument we make in this book.”

Drawing on decades of experience in vulnerability research, attack surface management, digital forensics, and cyber insurance, the book argues that security teams have spent years making remediation decisions in the dark, and without access to the evidence to know which vulnerabilities actually lead to breaches that cause financial loss and they will continue to flounder under the weight of meaningless vulnerabilities and industry’s increasing demands to fix them all.

The book introduces a new framework for understanding vulnerability management, one centered on external attack surface visibility, real-world exploitation, and the economics of cybercrime. Rather than treating every vulnerability as equally urgent, the authors argue that organizations should prioritize the small percentage of exposures that have consistently led to successful attacks and financial loss.

“For years we’ve accepted guessing as the cost of doing business in cybersecurity,” said Hansen. “We don’t think that's necessary anymore. Today we have enough evidence from incident response, threat intelligence, and cyber insurance to fundamentally change how organizations prioritize risk.”

Grossman and Hansen will be signing free copies of “The End of Guessing this week at Black Hat at the Nucleus Security booth (#5533):

  • Wednesday, Aug. 5: 2:00 p.m. to 3:00 p.m.
  • Thursday, Aug. 6: 10:00 a.m. to 11:00 a.m.

Attendees are invited to meet the authors, discuss the ideas behind the book, and learn how evidence-based vulnerability management is reshaping the future of cyber risk reduction.

Hansen shares his thoughts on why they wrote the book in a blog post – “The Story Behind ‘The End of Guessing’ – published today on the Root Evidence blog.

About ‘The End of Guessing’

“The End of Guessing” explores why vulnerability management has reached a breaking point and presents a practical framework for prioritizing cyber risk using evidence drawn from real-world exploitation, attack surface intelligence, digital forensics, and cyber insurance. The book is intended for security leaders, practitioners, and executives seeking a more effective approach to reducing cyber risk in an era of rapidly expanding attack surfaces. “The End of Guessing” is now available on Amazon in paperback format and on Kindle.

About Root Evidence

Root Evidence is a cybersecurity company pioneering evidence-based vulnerability management to help organizations focus on the small percentage of vulnerabilities that are actually exploited in the wild, have caused reported breaches, and led to material financial losses. With Root Evidence, security teams can measurably reduce financial risk, prioritize remediation efforts where they have the greatest impact, and reduce the likelihood of breaches. Founded in 2025 by Jeremiah Grossman, Robert Hansen, Heather Konold, and Lex Arquette, the company is headquartered in Boise, Idaho and backed by Ballistic Ventures, Grossman Ventures, and leading cybersecurity experts.

Contacts

Media Contact:
Kylie Heintz
kylie@rootevidence.com

More News From Root Evidence

Root Evidence Launches Full Platform to Help Security Teams Stop Chasing Millions of Vulnerabilities and Start Preventing Financial Loss

BOISE, Idaho--(BUSINESS WIRE)--Root Evidence, the cybersecurity startup championing evidence-based security, launched its full platform today with a simple premise: The cybersecurity industry has been measuring the wrong thing. For decades, organizations have measured cyber risk by the number of vulnerabilities discovered, severity scores assigned, and critical findings remediated. Yet despite more tools, more alerts, and more data than ever before, organizations continue to suffer costly ranso...

Root Evidence Research Finds Only 1.4% of Vulnerabilities Are Known to Be Exploited in Real-World Attacks

BOISE, Idaho--(BUSINESS WIRE)--Root Evidence, the cybersecurity startup championing evidence-based security, today released new research showing that the cybersecurity industry’s current approach to vulnerability management is overwhelmingly focused on the wrong problems. The report, Stop Counting CVEs: What Actually Mattered in Q1 2026, analyzed publicly available vulnerability and exploitation data from Q1 2026 and found that only a small fraction of vulnerabilities are actually tied to real-...

Root Evidence Launches Evidence Scan Enterprise Preview

BOISE, Idaho--(BUSINESS WIRE)--Root Evidence today announced the Enterprise Preview of Evidence Scan....
Back to Newsroom