Garrett HamiltonGarrett Hamilton

Garrett Hamilton

CEO & Founder

Expertise
  • SaaS product management
  • Threat analysis
  • Memory forensics
Education
  • BS in Economics, University of California, San Diego
Certifications
About the author

Garrett Hamilton brings deep expertise in SaaS product management, go-to-market strategy, and cybersecurity leadership. As CEO and Co-Founder of Reach Security, he draws on his experience at industry leaders like Palo Alto Networks, where he guided the WildFire product from launch to over 60,000 customers. With a hands-on background in threat analysis, training, and consulting, Garrett is committed to driving Reach's mission of transforming how organizations assess and remediate their security posture.

Articles by

Garrett Hamilton

All articles
arrow rightarrow right
The Missing Layer in Network Security: Continuous Assurance

Attackers operate continuously. Most network security controls are still reviewed periodically. Firewall rule management, change workflows, documentation, and compliance all matter. Yet they do not tell security teams whether live controls enforce policy as intended, every minute of every day. Continuous assurance across every security control is now essential in a world where the adversary is finding every needle in every haystack at AI-speed. Security teams need to continuously validate security controls, detect configuration drift and hidden exposure, and realign controls before attackers exploit hidden weaknesses.

Continuous Assurance Across Every Network Security Control

As rules are altered, controls drift from baselines and risk gets buried in the rulebase. Stale firewall rules stay live, shadowed rules obscure exposure, and overly permissive any/any rules sneak in. Periodic manual rule reviews rarely add value and fail to validate live enforcement posture. Months pass between audits, widening the gap for AI adversaries to exploit weaknesses and breach defenses. In fact, 42% of all configuration-related breaches, or near misses, are due to firewall rule misconfigurations. Reach continuously finds and fixes these weaknesses before AI attackers can exploit them.

Misconfigured Security Controls Open the Door for Storm-2949

The Microsoft Defender Security Research Team and Microsoft Threat Intelligence documented a campaign in which Storm-2949 abused Microsoft Entra ID accounts to exfiltrate data from Microsoft 365 and Azure environments. The attack path depended on a chain of security control gaps across identity, SharePoint access, endpoint protection, application control, and event visibility. Each misconfigured security control gave the attackers an opening and more room to move after the initial identity compromise. We took a closer look at the security controls mapped directly to the steps that Storm-2949 actually executed, and how proper configuration could have likely thwarted forward progress for Storm-2949.

Getting Started with Reach

To join the community of customers enjoying the benefits of Reach and learn more about how it can transform your security posture, visit:

Reach Recognized in Gartner® Emerging Tech Report on Domain-Specific Language Models for SecOps
Get the report
arrow rightarrow right