San Francisco, CA
2021
  |  By CP Morey
The constant evolution of today's threat landscape has organizations counting on security controls to keep the bad actors out and safeguard their people, sensitive data, critical infrastructure, operations, and brand. However, even the most sophisticated security tools can present a risk when improperly configured. And unfortunately, even the best security teams can make mistakes.
  |  By Bharath Rangamannar
Modern enterprises depend on a complex network of interconnected systems, applications, identities, and security controls. This infrastructure has become the nervous system of the business, enabling critical operations, supporting applications, and enforcing the boundaries that protect sensitive data. When these systems function correctly, they become invisible.
  |  By Garrett Hamilton
Some of the most serious network security weaknesses develop gradually through routine operational changes. Firewall rules are adjusted to support business needs, exceptions remain in place longer than planned, and controls are modified during troubleshooting. Over time, those decisions can push the live environment away from the security posture the organization believes it has.
  |  By John Dominguez
Firewalls remain one of the most foundational controls in any security program. Nearly every organization has at least one, and in many cases, hundreds. Despite widespread deployment, firewalls are frequently a source of unintended exposure rather than protection. The reason is almost always in how firewall rules are maintained over time, not the technology itself.
  |  By John Dominguez
Firewall configuration is the set of rules, policies, and settings that define how a firewall behaves. Without configuration, a firewall is hardware and software waiting for instructions. With configuration, it becomes a control that determines what traffic is permitted, what is blocked, and what gets inspected before a decision is made. Get the configuration right, and the firewall does its job. Let it drift, and you have the appearance of protection without the substance of it. This is not an edge case.
  |  By Garrett Hamilton
Every security leader can describe their network security architecture in confident detail: how traffic should flow, where segmentation boundaries sit, which access should never be permitted. What almost none can tell me with certainty is whether their live controls are actually enforcing that design right now, at this very hour. That gap between what we intend and what is actually running in production is where modern breaches live, and it widens with every change we make.
  |  By Reach Security
Firewalls are the most common source of configuration-related breaches or near misses, with 42% of security professionals reporting a breach or a near miss tied to firewall misconfigurations.
  |  By John Dominguez
Every security leader has a version of the network in their head. They know which systems should be segmented, which applications should be reachable, which ports should never be open, and which access paths should not exist. They know how the architecture is supposed to work. The harder question is whether the live environment is actually enforcing that design right now. That question is getting more difficult to answer.
  |  By CP Morey
Vulnerability management has long been seen as one of the most straightforward areas in security. Scan your assets, identify vulnerabilities, prioritize the findings, and patch what you can. On paper, it looks like a repeatable process. But in reality, vulnerability mitigation is anything but simple. Environments are constantly changing. Assets come and go. New integrations, temporary exceptions, and incomplete inventories make it hard to know what is truly at risk.
  |  By John Dominguez
Security teams spend enormous energy responding to threats, but many of the most damaging incidents trace back to a surprisingly simple failure: the organization didn't have an accurate picture of what it owned, what was exposed, and what its tools were actually doing about it. That gap between assumed coverage and actual coverage is where attackers operate, and adding more tools doesn't fix the underlying visibility problem.
  |  By Reach Security
AI-powered attacks, meet AI-powered defense. Reach Security's rebranded site is live today. Most of what changed came from customers. Security leaders have been telling us they need a faster, more continuous way to know where their controls are weak, understand what matters most, and close the gaps before attackers exploit them. Our new website reflects that signal. It brings greater clarity to the problem we solve, the category we are building, and how Reach helps security teams identify blind spots, prioritize action, guide remediation, and continuously validate the controls they already own.
  |  By Reach Security
Close control gaps before AI attacks find them Reach connects to the security tools you already own, finds the controls that are misconfigured or sitting unused, and watches for drift so gaps get closed before an attacker gets there.
  |  By Reach Security
A firewall rule set to allow any source to any destination can stay live for months. It cancels out the rules beneath it and lets traffic pass unchecked. That kind of drift sets off no alarm. It builds up between quarterly reviews, while small teams govern 50 or more firewalls and hundreds of rule changes a week. Reach Network Security Assurance finds these controls, shows how long each has been open, ties the finding to real exposure, and guides the fix.
  |  By Reach Security
Firewalls are the single most common source of misconfiguration-related breaches, yet they get changed a hundred times a week and audited once a quarter. This is the network security gap AI attackers exploit first. Endpoint gets the budget. Identity gets the roadmap. The firewall gets changed constantly and reviewed rarely. It is also the control most tied to breaches: 42% of security teams pinned a firewall misconfiguration to a breach or near miss last year, ahead of EDR at 40% and identity at 39%.
  |  By Reach Security
Network security controls change constantly. As rules are altered, controls drift from baselines and risk gets buried in the rulebase. Stale firewall rules stay live, shadowed rules obscure exposure, and overly permissive any/any rules sneak in.
  |  By Reach Security
Which of your users can reach a sensitive app without ever hitting MFA? Most security teams can't answer that with confidence. Microsoft Entra ID and Conditional Access is powerful. But exclusions stack up, MFA coverage drifts, and risk-based protections go unused. This creates openings for fast-moving AI-powered attackers. Reach continuously validates your controls against your security intent, closes the gaps, and proves the risk reduction.
  |  By Reach Security
Microsoft Defender for Endpoint ships with serious firepower. But most of it is sitting idle. ASR rules get stuck in audit mode. Devices never get fully onboarded. Exploit protection is switched off. Security baselines drifting across device groups. You're paying for protection that isn't turned on. Reach analyzes your Defender deployment, surfaces every gap, prioritizes the fixes by real risk reduced, and keeps your controls aligned as you scale.
  |  By Reach Security
A firewall's entire job is to control what gets in. In Reach's research, it was the most common source of a configuration-related near miss or exposure, ahead of EDR and identity controls. It does not take much. One rule broadened for a project, one exception that outlived its reason, one change that shipped without anyone checking it against intent. A single overly permissive rule, sitting live between quarterly reviews, is enough.
  |  By Reach Security
Observability is not the problem anymore. The data that tells you a change will break something usually already exists. Most teams have the events, the logs, the configuration history. What is missing is the step that turns all of it into a clear yes or no on a specific change, while there is still time to pull it. Garrett Hamilton, CEO of Reach Security, on objective data and the changes that get made before anyone checks.
  |  By Reach Security
72% of security budgets still go to detection and response, not prevention. That is the thread running through the latest episode of The Security Strategist, where EM360Tech's Shubhangi Dua talks with Garrett Hamilton, CEO of Reach Security, and Jay Wilson, CIO and CISO at Insurity. With the majority of budgets still pointed at detection and response, the conversation makes the case for swinging the pendulum back toward prevention, and why the tech can finally back it up.

Reach helps you get the most from your existing security stack by uncovering exposure, misconfigurations, and weaknesses that tools often miss. Using AI agents, it prioritizes and drives remediation based on real exposure, reducing operational costs and enabling measurable, preventive action, all from the leader in AI-Native Exposure Management.

Expose and eliminate hidden risk within your security stack:

  • Threat Exposure Management: Reach identifies exposure that is actually reachable, like those on end-user devices that enable ransomware delivery. By focusing on real exposure, it helps you prioritize actions that measurably reduce risk.
  • Security Posture Management: Weak controls create protection gaps like those that allow session hijacking or lateral movement. Reach helps you strengthen your posture by continuously validating whether your security controls are working as intended.
  • Configuration Management: Misconfigurations leave systems open to attack. Reach finds these weaknesses across your stack and recommends precise, context-aware fixes that simplify remediation and reduce friction for your team.

AI Agents for Security Architects.