<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url><loc>https://rootevidence.com/</loc></url>
  <url><loc>https://rootevidence.com/404.html</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/5-000-000-mythos-era-warranty/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/a-post-vm-warranty-world/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/ai-and-the-acceleration-of-cves/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/ai-and-the-artisan-vulnerability-researcher/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/ai-failure-mode-lie-and-how-will-that-impact-vulnerability-management/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/ai-malware-woes/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/ai-security-will-be-bolted-on/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/announcing-the-evidence-scan-enterprise-preview/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/application-security-won-the-industry-missed-it/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/at-the-risk-of-cvss/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/companies-buried-in-vulnerabilities-still-get-insured-how/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/cvss-9-8/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/cvss-base-scores/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/cvss-v4-vs-v3/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/cyber-security-incentives/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/datasources-are-not-created-equal/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/do-financially-motivated-hacking-groups-innovate-the-numbers-say-no/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/does-epss-first-make-sense/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/evaluating-ai-in-infosec/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/evidence-2025-year-in-review/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/explaining-the-myth-of-mythos/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/exploitation-vs-loss/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/fast-scanning-and-dwell-time/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/from-aristotle-to-cvss-why-first-principles-matter-in-cyber-risk/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/how-do-you-explain-your-vulnerability-prioritization-strategy-post-breach/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/its-not-their-fault-they-did-the-best-they-could-at-the-time/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/just-fix-everything/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/millions-of-vulns/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/moneyball-in-infosec/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/mythos-preview-vs-vm-reality-what-changes-when-ai-finds-everything/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/nulns/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/oems-are-licensing-the-same-vm-tool-in-different-colors-and-its-a-credibility-problem/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/paradoxes-of-vulnerability-management/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/patching-rosi-math/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/peak-patch-management-and-busy-work/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/removing-3rd-party-cves/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/replacing-security-theatre-with-real-risk-reduction/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/stoplight-infosec/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/subrogation-lawsuits-as-peer-pressure/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/the-ai-vulnerability-surge-that-doesnt-change-a-thing/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/the-biggest-challenges-of-100-vulnerability-management-practitioners/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/the-blue-team-is-a-losing-mans-game/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/the-cognitive-bias-behind-cyber-risk-scoring/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/the-conjoined-triangles-of-evidence-based-prioritization/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/the-cost-of-cybersecurity-will-exceed-the-cost-of-breach/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/the-dark-energy-of-orphaned-external-it-devices/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/the-difference-between-vuln-severity-and-financial-exposure/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/the-epoch-theory-of-cybersecurity/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/the-importance-of-prebuilt-easm/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/the-kpi-weve-been-missing-in-vulnerability-management/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/the-myth-of-objective-security-scoring-models/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/the-rational-rejection-of-vulnerability-management/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/the-unit-cost-of-infosec/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/the-vulnerability-management-warranty/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/vulnerability-management-has-always-been-about-evidence/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/we-are-security-optimists/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/what-does-defensibility-mean-to-a-ciso/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/what-due-care-actually-means-in-vulnerability-management/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/what-enterprises-get-wrong-about-vulnerability-management-roi/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/what-infosec-doesnt-understand-about-cyber-insurance/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/what-is-the-remediation-cut-off-point-in-vulnerability-management/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/when-old-assumptions-move-aside-and-evidence-takes-over/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/who-measures-risk-better/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/why-mssps-are-getting-fired-and-probably-know-it/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/why-we-built-evidence-scan-the-way-we-did/</loc></url>
  <url><loc>https://rootevidence.com/blog-posts/why-zero-day-doesnt-belong-in-a-vulnerability-management-discussion/</loc></url>
  <url><loc>https://rootevidence.com/blog/</loc></url>
  <url><loc>https://rootevidence.com/claims/</loc></url>
  <url><loc>https://rootevidence.com/company/about/</loc></url>
  <url><loc>https://rootevidence.com/company/contact/</loc></url>
  <url><loc>https://rootevidence.com/contact/</loc></url>
  <url><loc>https://rootevidence.com/dealreg/</loc></url>
  <url><loc>https://rootevidence.com/get-started/demo/</loc></url>
  <url><loc>https://rootevidence.com/media/</loc></url>
  <url><loc>https://rootevidence.com/news/</loc></url>
  <url><loc>https://rootevidence.com/news/root-evidence-launches-evidence-scan-enterprise-preview/</loc></url>
  <url><loc>https://rootevidence.com/news/root-evidence-launches/</loc></url>
  <url><loc>https://rootevidence.com/news/root-evidence-report-q1-2026/</loc></url>
  <url><loc>https://rootevidence.com/pages/warranty/</loc></url>
  <url><loc>https://rootevidence.com/privacy-policy/</loc></url>
  <url><loc>https://rootevidence.com/products/platform/</loc></url>
  <url><loc>https://rootevidence.com/products/reporting/</loc></url>
  <url><loc>https://rootevidence.com/products/scan/</loc></url>
  <url><loc>https://rootevidence.com/products/surface/</loc></url>
  <url><loc>https://rootevidence.com/report/</loc></url>
  <url><loc>https://rootevidence.com/reports/</loc></url>
  <url><loc>https://rootevidence.com/scanners/</loc></url>
  <url><loc>https://rootevidence.com/security-txt/</loc></url>
  <url><loc>https://rootevidence.com/solutions/enterprise/</loc></url>
  <url><loc>https://rootevidence.com/solutions/insurance-carriers/</loc></url>
  <url><loc>https://rootevidence.com/solutions/mssps-mdrs/</loc></url>
  <url><loc>https://rootevidence.com/terms/</loc></url>
  <url><loc>https://rootevidence.com/thank-you/</loc></url>
</urlset>
