Configure → Drift → Breach → Repeat: The Cycle of Cybersecurity Control Configuration Risk
Get the reportCP Morey brings over 20 years of cybersecurity expertise to his role as Chief Marketing Officer at Reach Security. Previously, he led security marketing at Splunk, driving growth across a portfolio representing over half the company’s revenue. CP joined Splunk through the acquisition of Phantom, where he helped define a new market category and establish the company as a leader. His career includes leadership roles at Cisco, Sourcefire, and ISS.
The constant evolution of today's threat landscape has organizations counting on security controls to keep the bad actors out and safeguard their people, sensitive data, critical infrastructure, operations, and brand. However, even the most sophisticated security tools can present a risk to organizations when they are improperly configured. And unfortunately, even the best security teams can make mistakes. Whether it’s a firewall rule left too permissive, a mismanaged IAM rule, or an EDR process monitoring bypass, the implications can range from severe financial loss to risks with the customer base that can lead to significant and sometimes irreparable reputational damage.
Vulnerability management has long been seen as one of the most straightforward areas in security. Scan your assets, identify vulnerabilities, prioritize the findings, and patch what you can. On paper, it looks like a repeatable process. But in reality, vulnerability mitigation is anything but simple.
Upgrading Microsoft enterprise licensing from E3 to E5 or P1 to P2? Whether your company is upgrading or considering the move, you may be facing questions about how to leverage this shift for your security team’s advantage.
To join the community of customers enjoying the benefits of Reach and learn more about how it can transform your security posture, visit:
© 2026 Reach Security.
Terms of use