After decades spent helping define modern cybersecurity, Root Evidence co-founders Jeremiah Grossman and Robert (RSnake) Hansen are challenging one of the industry’s most deeply held assumptions: that finding more vulnerabilities makes organisations more secure.
Their new book, 'The End of Guessing', debuts this week at Black Hat USA, making the case that vulnerability management has become an exercise in managing volume rather than reducing risk. The authors argue that security teams are overwhelmed by millions of findings while lacking the evidence needed to determine which vulnerabilities actually lead to breaches
“The cybersecurity industry has spent decades optimising for visibility,” said Grossman. “We’ve built better scanners, better dashboards, and more sophisticated scoring systems. What we've never done is focus on whether or not we have enough evidence to know whether we’re fixing the vulnerabilities that actually matter. That’s our focus at Root Evidence and the argument we make in this book.”
Drawing on decades of experience in vulnerability research, attack surface management, digital forensics, and cyber insurance, the book argues that security teams have spent years making remediation decisions in the dark, and without access to the evidence to know which vulnerabilities actually lead to breaches that cause financial loss and they will continue to flounder under the weight of meaningless vulnerabilities and industry’s increasing demands to fix them all.
The book introduces a new framework for understanding vulnerability management, one centred on external attack surface visibility, real-world exploitation, and the economics of cybercrime. Rather than treating every vulnerability as equally urgent, the authors argue that organisations should prioritise the small percentage of exposures that have consistently led to successful attacks and financial loss.
“For years we’ve accepted guessing as the cost of doing business in cybersecurity,” said Hansen. “We don’t think that's necessary anymore. Today we have enough evidence from incident response, threat intelligence, and cyber insurance to fundamentally change how organizations prioritise risk.”

'The End of Guessing' explores why vulnerability management has reached a breaking point