atcroft

atcroftatcroftatcroft
  • Home
  • Works
    • Cybersecurity Guesswork
    • The Art of Jerry Garcia
    • Barish on Mental Health
    • Advocacy from Dr Kelley
    • Duffy on Feminine Gospels
    • A Debut Novel from Mehiel
    • Ishiguro's Unconsoled
  • Writs
  • More
    • Home
    • Works
      • Cybersecurity Guesswork
      • The Art of Jerry Garcia
      • Barish on Mental Health
      • Advocacy from Dr Kelley
      • Duffy on Feminine Gospels
      • A Debut Novel from Mehiel
      • Ishiguro's Unconsoled
    • Writs

atcroft

atcroftatcroftatcroft
  • Home
  • Works
    • Cybersecurity Guesswork
    • The Art of Jerry Garcia
    • Barish on Mental Health
    • Advocacy from Dr Kelley
    • Duffy on Feminine Gospels
    • A Debut Novel from Mehiel
    • Ishiguro's Unconsoled
  • Writs

Cybersecurity Experts Call for the End of Guesswork

Replacing theoretical risk scores with evidence-based decision making

After decades spent helping define modern cybersecurity, Root Evidence co-founders Jeremiah Grossman and Robert (RSnake) Hansen are challenging one of the industry’s most deeply held assumptions: that finding more vulnerabilities makes organisations more secure.

Their new book, 'The End of Guessing', debuts this week at Black Hat USA, making the case that vulnerability management has become an exercise in managing volume rather than reducing risk. The authors argue that security teams are overwhelmed by millions of findings while lacking the evidence needed to determine which vulnerabilities actually lead to breaches
“The cybersecurity industry has spent decades optimising for visibility,” said Grossman. “We’ve built better scanners, better dashboards, and more sophisticated scoring systems. What we've never done is focus on whether or not we have enough evidence to know whether we’re fixing the vulnerabilities that actually matter. That’s our focus at Root Evidence and the argument we make in this book.”
Drawing on decades of experience in vulnerability research, attack surface management, digital forensics, and cyber insurance, the book argues that security teams have spent years making remediation decisions in the dark, and without access to the evidence to know which vulnerabilities actually lead to breaches that cause financial loss and they will continue to flounder under the weight of meaningless vulnerabilities and industry’s increasing demands to fix them all.
The book introduces a new framework for understanding vulnerability management, one centred on external attack surface visibility, real-world exploitation, and the economics of cybercrime. Rather than treating every vulnerability as equally urgent, the authors argue that organisations should prioritise the small percentage of exposures that have consistently led to successful attacks and financial loss.
“For years we’ve accepted guessing as the cost of doing business in cybersecurity,” said Hansen. “We don’t think that's necessary anymore. Today we have enough evidence from incident response, threat intelligence, and cyber insurance to fundamentally change how organizations prioritise risk.”

'The End of Guessing' explores why vulnerability management has reached a breaking point


Copyright © 2026 atcroft - All Rights Reserved.

Powered by

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

DeclineAccept