New book ‘The End of Guessing’ argues the cybersecurity industry must replace theoretical risk scores with evidence-based decision making
After decades spent helping define modern cybersecurity, Root Evidence Co-founders Jeremiah Grossman and Robert (RSnake) Hansen are challenging one of the industry’s most deeply held assumptions: that finding more vulnerabilities makes organizations more secure.
Also Read: CIO Influence Interview with John Elliott, Cybersecurity Author Fellow at Pluralsight
“For years we’ve accepted guessing as the cost of doing business in cybersecurity. We don’t think that’s necessary anymore.”
Their new book, “The End of Guessing,” debuts this week at Black Hat USA, making the case that vulnerability management has become an exercise in managing volume rather than reducing risk. The authors argue that security teams are overwhelmed by millions of findings while lacking the evidence needed to determine which vulnerabilities actually lead to breaches
“The cybersecurity industry has spent decades optimizing for visibility,” said Grossman. “We’ve built better scanners, better dashboards, and more sophisticated scoring systems. What we’ve never done is focus on whether or not we have enough evidence to know whether we’re fixing the vulnerabilities that actually matter. That’s our focus at Root Evidence and the argument we make in this book.”
Drawing on decades of experience in vulnerability research, attack surface management, digital forensics, and cyber insurance, the book argues that security teams have spent years making remediation decisions in the dark, and without access to the evidence to know which vulnerabilities actually lead to breaches that cause financial loss and they will continue to flounder under the weight of meaningless vulnerabilities and industry’s increasing demands to fix them all.
The book introduces a new framework for understanding vulnerability management, one centered on external attack surface visibility, real-world exploitation, and the economics of cybercrime. Rather than treating every vulnerability as equally urgent, the authors argue that organizations should prioritize the small percentage of exposures that have consistently led to successful attacks and financial loss.
“For years we’ve accepted guessing as the cost of doing business in cybersecurity,” said Hansen. “We don’t think that’s necessary anymore. Today we have enough evidence from incident response, threat intelligence, and cyber insurance to fundamentally change how organizations prioritize risk.”
Catch more CIO Insights: How Are CIOs Aligning Technology with Workforce Agility?
[To share your insights with us, please write to psen@itechseries.com ]


