San Francisco, CA
2021
  |  By John Dominguez
Security information and event management, or SIEM, remains one of the foundational technologies in the security operations center. Gartner defines SIEM as a configurable system of record that collects, aggregates, and analyzes security event data from on-premises and cloud environments to support threat detection, investigation, and response, along with compliance requirements.
  |  By John Dominguez
If you're comparing vendors, our guide to the top Exposure Assessment Platforms in 2026 looks at how leading platforms approach discovery, prioritization, and remediation.
  |  By John Dominguez
Security controls change constantly. Firewall rules are modified, endpoint exclusions are added, identity policies are adjusted, and temporary exceptions appear as teams respond to new business and operational requirements. Some of those changes are expected. Some turn out to be harmless. Others quietly weaken the defenses organizations depend on. Detecting that a configuration changed is really important for security teams, but it’s just the beginning of the investigation.
  |  By John Dominguez
If your vulnerability management program runs on a fixed scan-and-patch cadence, whether monthly, quarterly, or tied to a compliance deadline, you are measuring your response time against an attacker timeline that continues to accelerate. Vulnerability management remains a foundational security discipline. It identifies real, exploitable flaws and gives teams a structured way to prioritize and remediate them.
  |  By CP Morey
Security posture is one of the most used yet misunderstood concepts in cybersecurity. For some, it means being audit-ready. For others, it’s shorthand for how many tools are deployed across endpoints, identities, and cloud environments. But in practice, posture is something deeper. It’s the ability of your environment to withstand real-world threats, not just meet compliance requirements. Strong posture doesn’t just reflect what’s present.
  |  By CP Morey
Zero Trust is often summarized as “never trust, always verify.” More precisely, it is a security model built on the premise that trust should never be granted implicitly based on where a user, device, workload, or resource sits. That makes Zero Trust much bigger than deploying a particular product or turning on a handful of access policies.
  |  By Reach Security
Twelve months of production telemetry reveal the scale, causes and security impact of configuration drift, pointing to firewall and EDR tool risk.
  |  By Bharath Rangamannar, SVP Engineering
Network security protects the nervous system of modern businesses. Highly connected and widely distributed throughout the corporate body, it keeps applications regulated, tools performing, and operations stable when functioning well. But like the human nervous system, it is vulnerable to drifting away from an optimal state and becoming weaker, leaving it open to attack. While the human nervous system is affected by stress, lack of sleep, and poor nutrition, digital network security is prone to accidental misconfigurations, ungoverned rule changes, and controls that drift away from their intended state.
  |  By John Dominguez
An Exposure Assessment Platform (EAP) discovers assets, identifies exposures such as vulnerabilities and misconfigurations, prioritizes them with threat and business context, and helps drive remediation. Gartner formalized EAPs as a distinct market in November 2025, and the category has quickly become the technology backbone of Continuous Threat Exposure Management (CTEM) programs.
  |  By John Dominguez
Security teams researching CTEM vendors in 2026 tend to run into the same problem. Search results mix analyst reports, vendor marketing, and outdated "top 10" lists that treat the framework like a single tool category instead of the five-stage program Gartner designed it to be. This guide breaks down what CTEM actually covers, where Gartner's research currently stands, and which vendors are worth evaluating depending on where your program needs the most help.
  |  By Reach Security
Point an AI model at a security stack it doesn't fully understand and you get confident, wrong answers faster. Reach gives your AI a source of truth for security controls. The MCP Server connects MCP-compatible AI tools directly to Reach. The Public API brings Reach findings and evidence into SIEM, ticketing, and GRC workflows. The MCP Server is intentionally read-only, so your team decides when recommendations become actions.
  |  By Reach Security
Every security configuration has a backstory. Drift History takes you down memory lane. See what changed, when it changed, who made the change, and how your team responded along the way. Then fix what still needs attention.
  |  By Reach Security
"The problems we solve are not sexy." But they are hyper-relevant and important. Garrett Hamilton joined Moudy Elbayadi, Ph.D. on Inflection Point: Digital Intelligence Podcast. He explains why Reach goes after problems that have been around for decades, that matter, and that nobody wants to own. He covers why these problems have lasted so long and why they are now possible to fix at scale.
  |  By Reach Security
Reach analyzed a year of telemetry from more than 50 production environments. The average organization generated 13 configuration drift alerts per day. 12 of them traced to a genuine, risk-prioritized exposure. A 92% signal rate on a category of alert most teams treat as background noise. The full report is out now. Security Intent vs. Security Reality: Configuration Drift in the Age of AI.
  |  By Reach Security
The problems we solve are not sexy. That is Garrett Hamilton on Inflection Point: Digital Intelligence Podcast, and he means it as a badge of honor. Problems that have been around for 30 years are rarely glamorous. They are also the ones that take the business down when they go wrong. Why is it more important than ever to tackle these problems?
  |  By Reach Security
Security used to mean locking the doors and the windows. Networks are open now, and every new tool, integration, and workflow adds another way in. A device can report EDR installed and still carry an exclusion someone added on a Sunday two years ago. Deployment is easy to confirm. How the control is running is the harder question. Garrett Hamilton and Moudy Elbayadi get into it on Inflection Point: Digital Intelligence.
  |  By Reach Security
AI-powered attacks, meet AI-powered defense. Reach Security's rebranded site is live today. Most of what changed came from customers. Security leaders have been telling us they need a faster, more continuous way to know where their controls are weak, understand what matters most, and close the gaps before attackers exploit them. Our new website reflects that signal. It brings greater clarity to the problem we solve, the category we are building, and how Reach helps security teams identify blind spots, prioritize action, guide remediation, and continuously validate the controls they already own.
  |  By Reach Security
Close control gaps before AI attacks find them Reach connects to the security tools you already own, finds the controls that are misconfigured or sitting unused, and watches for drift so gaps get closed before an attacker gets there.
  |  By Reach Security
A firewall rule set to allow any source to any destination can stay live for months. It cancels out the rules beneath it and lets traffic pass unchecked. That kind of drift sets off no alarm. It builds up between quarterly reviews, while small teams govern 50 or more firewalls and hundreds of rule changes a week. Reach Network Security Assurance finds these controls, shows how long each has been open, ties the finding to real exposure, and guides the fix.
  |  By Reach Security
Firewalls are the single most common source of misconfiguration-related breaches, yet they get changed a hundred times a week and audited once a quarter. This is the network security gap AI attackers exploit first. Endpoint gets the budget. Identity gets the roadmap. The firewall gets changed constantly and reviewed rarely. It is also the control most tied to breaches: 42% of security teams pinned a firewall misconfiguration to a breach or near miss last year, ahead of EDR at 40% and identity at 39%.

Reach helps you get the most from your existing security stack by uncovering exposure, misconfigurations, and weaknesses that tools often miss. Using AI agents, it prioritizes and drives remediation based on real exposure, reducing operational costs and enabling measurable, preventive action, all from the leader in AI-Native Exposure Management.

Expose and eliminate hidden risk within your security stack:

  • Threat Exposure Management: Reach identifies exposure that is actually reachable, like those on end-user devices that enable ransomware delivery. By focusing on real exposure, it helps you prioritize actions that measurably reduce risk.
  • Security Posture Management: Weak controls create protection gaps like those that allow session hijacking or lateral movement. Reach helps you strengthen your posture by continuously validating whether your security controls are working as intended.
  • Configuration Management: Misconfigurations leave systems open to attack. Reach finds these weaknesses across your stack and recommends precise, context-aware fixes that simplify remediation and reduce friction for your team.

AI Agents for Security Architects.