Exploring Cybersecurity Innovations with Root Evidence | Black Hat 2025
Cybersecurity experts Robert Hansen and Jeremiah Grossman, with Root Evidence, share their backgrounds and recent developments in the field. They discuss the evolution of their companies, focusing on attack surface management and the need for comprehensive data. The concept of evidence-based vulnerability management is introduced, along with insights from the insurance industry. The CISO Summit and Investors and Innovators Summit are highlighted as key networking platforms.
Transcript
Hey everyone. We're back here. We're on the floor of Black Hat, though you really can't tell.
'cause we, we went with a black screen here, but I couldn't think of two better people I'd like to introduce you to, if you read Security Boulevard, if you've been in the security world for more than a minute, you probably know both of these guys, though you may not know them, you know them. Let me introduce you to two friends. I know them both 20, 25 years to my immediate right.
Robert Hansen. A lot of you may know him as our snake though. Look, as we get more gray or less hair, we, we go by real name.
So it's Robert Hansen. It's my far right. Is a really good friend.
I, I've known him for a really long 25 years too. He could tell you about his history. It's my friend Jeremiah Grossman.
Jeremiah, Robert, thanks for joining us on Textron tv. Always a pleasure. So guys, you know, you're like cyber royalty to me, cyber security royalty to me.
But you guys made a big announcement about a week before, a couple days before the, uh, event this year. Why don't we dive right into that and then we could come back and talk about what's up in your lives and everything else. Sure.
Um, Robert and I, we've been running companies together for a long, long time. What we care about most of the industry is keeping people safe, keeping people from getting hacked. And the way we do that is we try to find the world's most important cybersecurity problem.
The one that has to be solved. We learn everything we can about it. Once you find a solution, then we start a company and we go after it.
So we don't start with a technology looking for a problem, we find the problem and we go after it for as long as hard as it takes. Absolutely. And I mean, just for people who aren't familiar, companies you've done together.
So look, the first, I think I met you, you were still at Yahoo. Yeah. You had, or maybe just leaving Yahoo.
You did White hat. Yeah. I, I started my career, uh, 25 years ago at Yahoo.
I was one of those kids that hacked Yahoo Mail and they gave me a job instead of calling the FBI. Yeah, Lucky you, For you. I took what I learned there and I learned that web security was a problem.
Mm-hmm. And I wanted to solve it. So we created White Hat Security to, uh, scale and mechanize application security and vulnerability assessments.
And of course you had to get the other best in the World Apps asset guy out there. And that was Robert. Absolutely.
Right. And, and look, white hat kind of invented, uh, you know, uh, pen test or AppSec testing as a service almost, if you will. Um, but then that was one company.
What came next. Uh, the next one was, uh, when, when, uh, we left a, let's say a white hat. I, I did a short time at Sendel one in the early days to focus on ransomware, which wasn't a thing yet, and, uh, go after, uh, endpoint.
But, uh, that was two years. In the meantime, while we were working on something for attack surface management, what we were learning was a significant number of the breaches were having to do it a previously unknown asset, that they would've secured it if they know it, they owned it. And so I'll have to have to pass it to Robert here, but I said, Robert, the we only where we're gonna solve the attack surface management problem is to download a copy of the internet first.
And, uh, so Robert, true to what he is, he goes, okay. Yeah. Yeah.
I think, I think, uh, people when they hear that, they're like, that can't be possible. But we were processing by the end, like multi petabytes a month. And uh, I remember, and when people think of the word internet, they're thinking Google, that's just the web, that's a searchable web.
What we really needed was a copy of every piece of metadata, every Ip, I Just, everything, everything, every ip, telephone and printer and whatever. So that was a pretty big challenge, but it enabled us to answer the question, what do people own? And uh, so that kind of took us down this path.
I, I remember you working on that. You know, one of the before I did still secure my friend Raj, who's one of the co-founders with me, is still secure. He started a company Kova, which was IP Geolocation, very similar thing.
You had to geolocate every IP address. So figure out, you know, which IP address went where. It's a huge undertaking.
It was simpler then, 'cause it was smaller then it was bigger by the, a lot bigger by the time you did it. And of course, that led to another company, and I'm blanking on the name right now. Oh, that our most recent one.
Uh, so, uh, so Bit Discovery, the attack source management company. So we raised money and, uh, during the pandemic and uh, the company lasted a whopping three years. So it was a very fast moving company.
It was very successful, very fast. And it was acquired by Tenable, right? So, uh, you know, so Robert and I were, we have a background in application vulnerability management, but not, uh, so network or CDE vulnerability management was, uh, familiar to us.
And so what we learned there was that this is a very big 25-year-old problem. Everybody has a vulnerability management problem. They were sick of it.
Everybody was buried in vs. Didn't know what to fix first. And everybody was still getting hacked.
So we're like, okay, we gotta set out and solve this problem. So Robert and I have TA taken hundreds of meetings to learn everything we can from everybody we could about this problem to figure out what the problem was before we could solve it. So two years later, we were ready to launch the company 'cause we think we had some answers.
And that company is, That's rude evidence. Uh, also known as just evidence. We go by that as well.
But I think one of the cool things is, um, we pulled in tons and tons and tons of data. We, instead of like, most people are just like anecdotal evidence only, but we pulled in information from every source we could possibly find just to see if there's anybody who agreed. And it turns out no one agrees.
And that was sort of the premise that got us thinking down this path is like, well, if everyone is disagreeing, that probably means that everyone is, at least everybody, but one is wrong, but probably everybody's wrong. And so we gotta think of a ti entirely new tack. Like how do we, how do we tackle that?
Fortunately we've been talking to the insurance industry for years and years and years. So we had really, really good relationships with them and they started sharing with us some, some details about claims. And it turns out you don't need to look for 300,000 CVEs.
It's a much, much more finite number. Much easier to do. Absolutely.
So I have a little experience in this, right? I started a vulnerability management product. It's still secure.
In 2003, you a lesson I learned in business. If there was a really good solution, there'd be one, maybe three. There's a reason why there's dozens of v vulnerability solutions.
And I would say, Robert, it's not that one is right or one is wrong, they're all a little wrong and a little right? That's right. Everybody, right?
Everybody has kind of nippled on the edges here, but no one, no one's really solved it. So, And, and enterprises feel that, so, Oh, Absolutely. So the one observation that, uh, you can reference this, um, only 1% of all known vulnerabilities have ever been exploited.
And that has been the case for quite some time. So if the prioritization models are working, why is it always 1% of vulnerabilities? So that's something to, uh, something could contend with.
So the concept that we're bringing forward is a evidence-based vulnerability management. And the way to describe it is, any given vulnerability could have evidence of exploitability, it could have evidence of attacker activity and evidence of attacker breach and loss, financial loss. If you have all those three, those are the ones Fix first you got.
That's right. If you don't have breach and loss data, you have effectively a Kev list vulnerability, which is fine, but that's the next down the list. You remove evidence of, uh, attacker activity, then you get into prediction and prioritization.
So what we wanna do is concern ourselves with the ones you absolutely must fix. Now, no ratings, no scoring, no color codings. You fix these and if you do that, you're better than 99% of everybody and you're not going to get hacked.
You know, I'm reminded, I don't know, you guys know Giddy, giddy Cohen? Oh, he sold the company, but it's not 20 years old. Giddy was the first one I saw who generated attack maps of vulnerabilities.
So it would find a vulnerability and then work backwards from there out to the internet to see is it reachable? Is it exploitable, is it fixable? And how is it fixable?
Is it patchable? Can you close a port down? You know, what's the remediation path?
And darn, I can't remember the name of his company, but Giddy Co was the founder. And I thought that was one of the best things I've ever seen. And, and how do we tackle this?
Now, we didn't have ai, we didn't have the, the reams of data that you guys had, but it was a, it was a holistic approach to saying, let's get out of the hamster wheel of just giving you a phone book of CVEs in South Sea next year. Right? Which is was the kind of state of the art when I was doing this in 2003, right?
Well imagine, imagine that's what you get, right? You have like 50, a hundred thousand vulnerabilities. Some of these companies have millions of vulnerabilities.
You go fix, fix a bunch of vulnerabilities the next day you have more vulnerabilities, you're not actually really moving the needle at all. And we, we spent a lot of time thinking about like, like what, what if you have 10 vulnerabilities equal chance of a bad thing happening to each one of 'em, and you have a million dollars in the pot in the middle. Any one of 'em gets you there.
If you only fix nine, but you leave the last one there, like you've actually just wasted time. You Probably shouldn't have fixed. You Probably should.
Well, shouldn't have fixed any of them, which is a weird concept. And I think security is gonna have a really tough time, like really thinking through that. And of course there's a lot of variables there, but, but I think one of the cool things about looking at the insurance industry is we're like, here is loss.
We are actively seeing loss in these places. Why don't we fix these first? Right?
And and the nice part about that is now we're talking dollars and cents. We're no longer talking about, you know, some prediction model that, I mean, and no offense to those guys 'cause I think that is really very tricky and interesting. It's just that it's very hard to predict when there's only a handful of phones.
And depending on who you talk to and we have reasons to believe some of these numbers, it's definitely less than a thousand, let's call it that. So we're talking a fraction of a percent. So if you're gonna make a prediction, you have better be perfect if you're gonna get exactly those vulnerabilities.
Absolutely. Look, no one manages risk better than the insurance industry. That's what they do.
And I've never met a poor insurance company. Right? Um, so I think that's a great model.
My my question though to you guys is does it wind up being like the OAS pop 20 where it's like a static list and, and right, this is a list that needs to be constantly cared for and guarded. That's, uh, that's a great question. Um, to lead into that, what we learned, uh, what we've learning is about 50% of the breaches that lead to loss have something to do with a remote exploitable CVE.
So if we wipe those out, the ones that Robert was mentioning, we can reduce 50% of the losses. That's huge. That's the impact that, that we wanna have.
Does that list is a thousand vulnerabilities? How does that get updated? So right now it's generally speaking a static list.
That's why we know the vuln management industry is getting it wrong. Because if it's only 1% of VULs, that means the adversary is not forced to innovate to take on the next one. So if we get the prioritization right, we should expect the list to change over time, right.
And that's our gonna be our bellwether if we're doing it right. So if we see that list starting to That's right, that's a good thing. So, so if the list changes, we're doing it right and that's what our intent is.
Increasing costs. Yep. Let me ask you another question.
So this finding vulnerabilities and this fixing vulnerabilities, I get what you're doing to help find the, the right vulnerabilities. Let's call it that. What, what is evidence hub to fix those vulnerabilities?
So ultimately that's not our job, that's the customer's job. Uh, but we can make it easier. Uh, and I think the major way we make it easier is we help them make their own business case to their own executive team about why they should prioritize both by reducing the amount of, you know, chaff, a bunch of vulnerabilities that'll never be exploited, have never been exploited by anyone.
Now if it's a much small, a much more definitive list with known attribution, um, to claims data and we know what the claims losses are, now it's just a matter of how much, what kind of cost it is. So if it's like a million dollars to fix a vulnerability, that'll cost you 5 million if you don't fix it. Well that's a $4 million ROI That's, that is a very easy business case to make to your CFO who make no mistake, that is the real risk officer of the company.
Not not the C Not the CSO or any Of those people. Exactly. Exactly.
So I think that's really where our main focus is. Now, we could always pivot more into that area later, but just by starting talking dollars and cents, I think that's a big win for the customer. Absolutely.
I, I, you know, another, another piece of this though is I used to call job security, right? The vulnerability, the guy who's responsible or gal whatever, the person responsible for vulnerabilities, vulnerability management, the team, they've gotta be incented to hit the right stuff. You know, you know what they say, right?
If nothing happens, we did our job. That's not a hundred percent true, to tell you the truth. Nothing happens 'cause it didn't happen yet.
That doesn't mean you're doing your job. How do you, how do you help that work or show metrics that hey, I am doing my job and we're doing a damn good job with evidence. So that's a fantastic question.
One we contend with all, all the time. 'cause if we're gonna reduce the set of vulnerabilities that matter, then we should get to VUL zero really, really quick. Yep.
So what we, what we want to be able to do right now, when, when companies get hacked, the standard PR answer is, the attacker was sophisticated. Please don't sue us. We did everything we possibly, it Was a zero day, of course.
Where we wanna move people to is if somebody gets breached, it will only be by a vulnerability that no one has ever exploited. Ever. That's a defensible position.
What more could they have done? They fixed every VM that has ever gotten anybody breached. Right?
That's pretty good. That's better than It's the zero day argument. Correct.
And not even a zero day, it just, no one exploited that one. For whatever reason, zero day was Uhhuh. It happens.
Now, let me just business model a little bit. Uh, back in the day we used to sell it by how many hosts we were scanning. 'cause it was scanning, right?
How many hosts we were scanning, how many ips, how many nodes, how many vulnerabilities? I how do you want to, you know, skin the cat today? How, how is this packaged?
Uh, uh, the business model will be software as a service. You should be able to go to a website, put in your company name and it's scan. It's the straightforward thing around.
And what we want to be able to do is we don't want to wow the customer with look how many giant plates of red you have and all this red. No, no, no, no. We want to help them in terms of dollars and cents.
This is what you need to fix. This is what it's gonna cost to fix and this is how much money you'll retire your retire risk. We want to get to VUL zero, at least for the VMs that matter.
That's the best anyone could ask for in this world. Hmm. So you don't, I know this sounds old fashioned, no agents, no internal sensors, pizza boxes or Any of that stuff.
We only need as much as the adversary does. Right? Which is effectively not that hack five View.
Yes. Right. Again, our background is breaking into things.
That's where we came from. So we want as little as possible, we want to see what the actual risk is. Let's talk a little bit rollout availability.
Robert, is it, can people go on right now? Uh, no. Uh, we, uh, we, yeah, yeah, we literally just started fundra.
We got our fundraise, whatever it was two weeks ago now. So, uh, it'll probably be a few months before we are ready for design partners to start really like actually using it. Uh, it'll probably take another six months, I'd guess before a fully rolled out UI is, you know, freely available to anybody.
Uh, it depends a little bit on what we, feedback we get from the customers. Um, 'cause one thing Jira and I really spent a lot of time doing is absolutely making sure our customers are just, this has solved the problem. If it doesn't, like we have to go back and fix it.
So that's the real question mark, is what rejiggering do we need to do to make it, you know, one of the things we really wanna focus on is speed, for instance. Uh, like being really, really, really fast. Well, if it turns out that causes problems, you know, we're gonna have to do workarounds, you know, for whatever reason.
So that's, uh, it's an unknown until we get there. But, uh, the good news is we do have a lot of experience building these kinds of things, so, sure. Uh, so, uh, for those that are, that are interested, so, uh, we have a really good idea of what needs to be built, where we're gonna need help from the industry.
You know, practitioners, bone management teams with the people we've been meeting with the last two years is what does it look like? What do you need it to look like? We know what needs to be done, what do you need it to look like?
So for those that are interested, reach out. We want to hear from you. We don't have all the answers.
We'll into that camera. Where did they reach out? Oh, reach out.
Um, root evidence, uh, dot com. Sign up for, uh, you know, the mailing list. And, uh, we will reach out.
We will, we will meet with you. We want to learn from you. We want to solve this problem.
We're not ever gonna have all the answers, but we'll build nonstop until we solve it. And with your track record, you got a good chance that's happening sooner than later. Guys, I can't wish you enough luck, success and, and you know, strong tailwinds as as you go forward here.
If you don't mind, I'd like to just pivot a little bit. Let's talk black hat. Yeah.
So I first met you in Black Hat I think in 2005. I got hacked on my iPhone three, I remember. Yep.
And it was, I, I forgot the dude's name. I think he's still in jail, not for hacking me, of course. But he was an idiot.
Anyway, but, and Jeremiah, I probably met you around the same time, but you started, I knew you more for black, half fifth, the Juujitsu stuff with Hoffman and everything. Right? That had to start also around 2005, 2007 maybe, something like that.
My, uh, my first black A was, uh, 2001. Imagine. Yeah.
Well mine, mine was 2003. I gotcha. Yep.
We used to be at Caesar's in the hallway. Yeah. I had a booth overlooking the, uh, the Venus pool.
And if you would take a briefing from my guys, I'd let you use the, uh, binoculars. That's how long ago and wrong that was. But anyway, black hat's changed over the years.
It's, in many ways it's not what it was, but it's something better different than what it was. You guys are both intimately involved in the whole week's worth of activities. Give give me share with the audience if you wouldn't mind a little background on this.
Yeah. Uh, I was probably memory serves. I think I might have been one of the very first board members for the main conference.
Uh, so helping select talks and make sure that they're of the quality that we want. Um, but gradually, Jeremiah and I, I think we, he was also on that with me. I think we decided it was better to spend more of our time on the CISO summit.
Uh, it is just really important to make sure that the CISOs are getting the kinds of information they need to get. Um, and so fortunately there's a lot of people backfilled and did a great job and that's why the main conference has done so well. But our focus has really been more on the CISO event.
Uh, the Cyber Insurance Summit. Uh, it's a micro summit and the Innovation and Investor Summit, uh, which is all these sort of micro summits kind of floated around the, the periphery of the con con, uh, conference, but are really important to sort of pushing the, the needle. No, I, I think that's the model whether you go to the cloud native like CubeCon Summit or RSA or black Hat.
It's these satellite conferences or what I call the more conference within the conference micros, that really, you really get a lot, if that's your thing, it's a deep dive, a deeper dive than you're going to get going to a keynote or walking the floor and getting, you know, distracted by lights and buzzers. So it's great that you do that. Give us kind of a metric.
So for instance, Jeremiah, the CISO Summit, how many people are in there? Uh, so the CISO summit is fantastic 'cause uh, we like talking to ciso, see what's top of, what's top of mind for them. And, uh, so the CISO summit, uh, this year was 400 CISOs all in the same room.
So the way we do the CISO summit is a little bit different than the briefings. The briefings take submissions and then the review board picks the best of the best. And, uh, you know, Robert and I have both given many talks there.
They do a fantastic job. The CISOs summit's different. The CISOs have an agenda, they know exactly what they want to learn.
So we get about 10 topics down to things that they wanna learn. And then the review board sources the world's leading experts in those topics. And we invite fight them in and just let them loose to, to speak their message and what they know.
So the content is, uh, super high quality. We have, uh, generals and, you know, all the people that are front line of the, uh, uh, the breach, uh, uh, salt typhoon breach and things like that. Right.
Things you can't get anywhere else. Absolutely. I I had friends at the Investors and Innovators Summit.
They said it was Greg Robert. Oh yeah. People who are home maybe didn't see it, don't know about It.
Yeah, it's, it's a brand new as of last year, uh, event. Uh, so this is the second time we've done it, and I think we learned a lot of lessons last year and it was really good. So the content is basically a mix of people who are, you know, entrepreneurs getting into the industry.
Maybe they have a company, but they haven't quite figured out how to take money or haven't figured out how to talk to customers, or they're sort of in that growth phase and they're just starting to figure their, their way through. And then the other half is a whole bunch of very seasoned VCs who are trying to meet those same people. So it's a really, it's a really kind of magical thing, you know, it's like everyone's just kind of coming together and sharing stories and kind of like, who are you?
And let me give your business card. It's like, just tons of deals getting made right and left. But, but it's also a lot of great advice.
Really well-meaning advice because there's a, there's a peer group there too. It's a whole bunch of other people who are struggling to meet the other people on the other side of the fence. It's great.
It's a great Conference. It is. No, it's great.
I I stopped by ly. I was, I was grabbing Michael Fardo out of there. But, um, so guys, what are you doing in your spare time?
You still doing your podcast? Occasionally? Yeah.
You got, sorry. Yeah, occasionally. Um, so I do, uh, demos, product demos.
So companies will come to me and, uh, and for free, you don't charge anybody anything, but they'll come on there and they'll do a, uh, about an hour long, uh, presentation, 45 minute presentation. I ask him questions with Trey Ford. He is my sort of co co-presenter and, uh, but we just, we ask him kind of, I wouldn't say elbows out hard questions, but the kinds of questions that if you're sitting on the other side of the fence and you're a security expert, you know, if that answer was a good answer or not, you know what I mean?
And the nice part is unlike having to put your email address in somewhere, you could just watch it and enjoy it. And, and if you want to do something with them, you reach out to them. And we've got a whole bunch of people who've wanted to meet that company.
So it's, it's ended up being a great sales channel for a lot of companies. Good for you, man. Where, where can people get that podcast?
Uh, just look for our snake show demo day. Beautiful. Thanks.
Robert, what about you, Jeremiah? Uh, for hobbies? So, uh, I guess, uh, for the blackout related hobbies.
So, um, a long time, a long time ago, you know, I started, uh, Brazilian jiujitsu like 20 years ago. And, uh, rather than go out to the vendor parties after blackout in the conferences where there's crowds and noise and things like that, I decided to get a workout in. So I would visit Jiujitsu Academy.
So at Blackhead, I'd rather go to the vendor parties. I would find a, an academy. And, uh, somebody saw me leave the conference once and they said, can we come?
That was Chris Hoff. And I said, yeah, sure. So we started trading them.
They, the next year more people wanted to come, and then it grew to a, a life of its own. Yeah. Where now I put a 60 plus, uh, computer security people on the mat with UFC fighters and we learn and spar.
It's like, it's a, it's a crazy event. Yeah. It's, It's really cool.
The pictures are fantastic. It's fun every time. So I love it guys.
Fantastic. It's great seeing both of you. com.
Check it out. This is gonna be something you can get, you can get in early here and, and watch it. Robert.
Pleasure man. Jeremiah, two of my heroes in, in security. Uh, we're live, well, we're not live.
You're watching this recorded, but we were live when we recorded it. We're a black hat. Stay tuned.
We'll have more. Bye-Bye.