Find and fix hidden risk. The operating system for your security products.

At UC Irvine’s Digital Leadership Agenda 2026, moderated by Nicole Perlroth, Garrett Hamilton illustrates what those blind spots can look like: “We believed it was deployed.” “It was turned on.” “It should have stopped this.” Except one exception, one policy gap, one control not applied at scale — and assumptions replace reality. The real problem isn’t visibility. It’s continuously validating intent against execution. Learn more about Reach → reach.security/ Shift thinking left of boom → reach.security/blog/security… #Cybersecurity #ExposureManagement #SecurityLeadership
1
151
Every security configuration has a backstory. Drift History takes you down memory lane. See what changed, when it changed, who made the change, and how your team responded along the way. Then fix what still needs attention. Learn more at f.mtr.cool/n8spnm6la0
2
A configuration change should never leave you guessing. What actually happened? Who changed it? What happened before? Was the risk accepted? Has it already been fixed? What still needs action? New Reach Drift capabilities turn configuration changes into living investigations. Multiple Events. One Investigation. Related events stay together instead of becoming disconnected alerts. See the Whole Story Behind the Change. Drift History preserves configuration changes, comments, decisions, actors, and timestamps. Know What Still Needs Action. Fix It Fast. Reach automatically recognizes when configurations return to a healthy state so teams can focus on the risk that remains. One alert. The full history. The current truth. See how Reach follows a configuration change from detection to resolution: f.mtr.cool/8bbr8pwc16 #configurationdrift #reachsecurity
5
"The problems we solve are not sexy." But they are hyper-relevant and important. Garrett Hamilton joined Moudy Elbayadi, Ph.D. on Inflection Point: Digital Intelligence Podcast. He explains why Reach goes after problems that have been around for decades, that matter, and that nobody wants to own. He covers why these problems have lasted so long and why they are now possible to fix at scale. Full episode: f.mtr.cool/1wqd6d7llz #Cybersecurity #ReachSecurity #SecurityOperations
6
Defend the Bay 49ers vs. Dolphins on Sunday, at Levi's Stadium. Reach co-sponsored alongside WitnessAI and Oligo Security, and Leah represented Reach. Niners 35, Dolphins 13. Found an exploit on the first drive and ran it four more times.  Thanks to WitnessAI for putting it together, and to Esfandiyar Alaee for being a great host. #Cybersecurity #ReachSecurity
17
Leah Paul and Denise Tcheng spent last Wednesday evening at Kodi Connect in Palo Alto. The roundtable format made room for real dialogue, and we appreciated how openly people shared what they're working through. Thank you to everyone who pulled up a chair, and to Khloe and Kodi Connect for bringing the room together. #Cybersecurity #ReachSecurity #SecurityLeadership
12
Nearly 1,000 vulnerabilities in a single Microsoft security release. Microsoft's September release addressed 972 vulnerabilities, including two exploited zero-days. Two vulnerabilities with the same severity score can carry very different risk, depending on whether a control in front of the asset is enforcing, in the traffic path, current, and capable of stopping the exploit. Reach checks those conditions and marks each vulnerability as mitigated, partially mitigated, not mitigated, or unknown, with evidence behind every determination. In an environment with 1,000 vulnerabilities where controls are effectively mitigating 950, the immediate list is 50. Keep exploits out until patches go in. Get the guide: f.mtr.cool/lcei3he161 #Cybersecurity #ReachSecurity #PatchTuesday
14
Riptide Technology's annual charity golf event in Portsmouth, NH. Tim Schippmann and Allyson Butler attended on Reach's behalf.  Beautiful day for golf and a cause worth showing up for.  Thanks to Riptide and to Paul Moughan for the invite. DM Tim for his official score.
14
Day 2 at Cybr.Sec.Con Houston. The theme this year is wizards and castles. We brought Rubik's cubes. Close enough. Stop playing hide and seek with your misconfigured controls. Learn how Reach illuminates blind spots. Proactively hardens. At AI speed and scale. Booth 239, Hall B3, until 3:30. #Cybersecurity #ReachSecurity #CybrSecCon
9
Reach Security is sponsoring the SoCal CISO Inner Circle Dinner with Gartner and Evanta this Thursday in Anaheim. The evening zeroes in on a question security leaders are working through right now: how to redefine control when attackers and defenders both operate at machine speed, and how much authority to hand to automation. This is where we live. Reach uses cybersecurity domain-specific AI models to surface and prioritize risks, enabling faster, smarter hardening of your environment through automated recommendations and orchestration. You're never out of the fight. Reach continuously monitors your configurations to detect drift, validates that controls are working as intended, and ensures your defenses stay aligned with your evolving environment and threat landscape. *steps off soapbox* Denise Tscheg will be there for Reach. Thanks to Dennis Keenan and Zack Hellmann for bringing this group together. #Cybersecurity #ReachSecurity #CISO
15
AI is transforming your security operations. Ground it in the source of truth for security controls. Without security context, AI models can produce confident, wrong answers. Embed Reach into your AI tools to give them the security-control expertise, cross-vendor controls context, evidence, and remediation guidance they lack. Find the Reach team at Booth 239, Hall B3, at Cyber.Sec.Con Houston through Wednesday. #Cybersecurity #ReachSecurity #CyberSecCon
9
A firewall rule with source, destination, application, and service all set to Any can let through traffic that should be blocked. It also shadows every policy beneath it, so the rules written to stop that traffic never get the chance. Overly permissive access tends to slip into production as rules get added and changed. With hundreds of rule changes a week and months between audits, it can sit there without anyone seeing it. It's one of ten firewall weaknesses in the checklist: f.mtr.cool/oykv0s316t What You'll Learn: ☑︎ How to quickly identify misconfigured controls and drifted settings across your firewalls ☑︎ How unblocking suspicious categories (C2, malware, phishing) can leave the door unlocked for bad guys. ☑︎ Why overly permissive Any/Any rules are poison to your overall security policy #Cybersecurity #ReachSecurity #NetworkSecurity
10
Timbers vs. St. Louis City SC. Providence Park. Reach sponsored the Tevora suite last week and Matt was there to represent the team. Another great time with Tevora & friends. Thanks for having us and thanks for always putting on a solid event! #Cybersecurity #ReachSecurity
20
CISO Meet Seattle on Thursday. Coffee at eight, predictions about the future at nine twenty-five, steak by twelve thirty. Chad Ames and Brendan Toy joined from Reach.  Thanks to the CISO Meet team for hosting, and to our fellow sponsors Beazley Security, Salt Security, Oligo Security, Infoblox, Orca Security, dope.security, and Nudge Security. #Cybersecurity #ReachSecurity #CISOMeet
1
18
Scattered Spider compromises identity without an exploit. It calls the help desk and talks its way into an MFA reset. These gaps are not new. What changed is speed. The disclosure of Claude Mythos in April showed how quickly AI is changing the speed and scale of attacks. The Mythos Readiness Checklist scores 16 security controls across four sections. This is section one, identity and MFA hardening, and the four statements that decide whether a phone call can undo your authentication. The remaining three sections cover SaaS and OAuth access, network and edge exposure, and AI-era validation and drift. Each gets its own post over the coming weeks. Score your controls: f.mtr.cool/d08mdulj33 #Cybersecurity #ReachSecurity #IdentitySecurity
59
Reach is at Cybr.Sec.Con next week in Houston. Booth #239 September 15 and 16 George R. Brown Convention Center Dom Conte, Jonathan Wachsmann, Scott White, Ben Dean, and Nick Lerach will be on the floor. Stop by the booth to talk through configuration drift and what a source of truth for your security controls looks like in practice. Reach is also sponsoring the After After Party on Tuesday at 7pm at Fabian's Latin Flavors. Register here: join.paintthetownredinv.com/… #Cybersecurity #ReachSecurity
42
Reach sponsored Lone Wolf No More at Great Wolf Lodge in Grapevine with Crush Security. Nick and Scott went to present. Executive briefing in the morning, water park with the families in the afternoon. Reasonable trade. The Reach coolers and towels went home with them. Thanks to Crush Security for putting it together. #Cybersecurity #ReachSecurity
23
Congratulations to Carlos Balderrama, who won the WiFi Pineapple Pager at Booth 1128. Carlos put in the miles for it. Anyone who has done a passport program in Mandalay Bay knows exactly how far that is. Three days, a lot of good conversations with people who actually run these controls, and one very deserving winner. Thank you to everyone who stopped by and helped make this Fal.Con special. #Cybersecurity #ReachSecurity #FalCon2026
23
Fal.Con is not over yet. The conversation landing hardest at 1128 is the simplest one. Security teams need a source of truth for their controls. What is configured, how it all works together, where it has drifted from what was intended, and what that leaves exposed. Everything else follows from there. Knowing what to fix first, fixing it across the stack you already own, and closing gaps faster than adversaries can find them. Thanks to everyone who has stopped by, asked hard questions, and spun the wheel. No real money was won or lost on the roulette wheel, maybe. #Cybersecurity #ReachSecurity #FalCon2026
17
Two hard problems we are working on, both on display at Booth 1128. AI is making security decisions without knowing how your controls are configured. Teams are wiring frontier models into their stacks faster than those models can see what they are looking at. So we made Reach embeddable, and the model gets cross-vendor control context, evidence, and remediation guidance instead of a confident guess. Patching can no longer keep pace with discovery. Frontier models are finding vulnerabilities faster than any team can fix them, while patch cycles still move through testing, change control, and maintenance windows. So we built a way to read the controls already deployed around each asset and show which vulnerabilities are mitigated right now and which remain reachable. The backlog does not disappear. The urgent part of it gets small enough to work. Both are live with customers today. Come on by and park next to the roulette wheel. 📌 Booth 1128 📅 Through September 3 📍 Mandalay Bay #Cybersecurity #ReachSecurity #FalCon2026
15
Reach analyzed a year of telemetry from more than 50 production environments. The average organization generated 13 configuration drift alerts per day. 12 of them traced to a genuine, risk-prioritized exposure. A 92% signal rate on a category of alert most teams treat as background noise. The full report is out now. Security Intent vs. Security Reality: Configuration Drift in the Age of AI. f.mtr.cool/54m4g5d5s9 #Cybersecurity #ReachSecurity #ConfigurationDrift
17