💡Did you know that more than 70% of America’s domestic codebreakers during WWII were women? Codebreakers. Cryptanalysts. Intelligence leaders. Detection pioneers. Women have been shaping cybersecurity from the beginning. Swipe through for some cyber history and happy International Women in Cyber Day from Obsidian Security! #WomenInCyberDay #CybersecurityHistory
Obsidian Security
Computer and Network Security
Palo Alto, California 80,492 followers
Comprehensive Security for your Enterprise Applications
About us
Every enterprise runs on software it doesn't own: third-party apps, AI copilots, and agents logging in with OAuth tokens nobody's reviewing. Obsidian Security secures all of it, discovering every third-party app and AI feature connected to your business, governing risky permissions, and detecting threats in real time. Trusted by the world's most regulated, highest-scale enterprises. If you're adopting AI, you're adopting third-party software faster than ever we make sure that doesn't mean adopting its risk. SPECIALTIES AI Security Posture Management, AI Security, SaaS Security Posture Management, Identity Threat Detection & Response, AI & Agentic Security, Continuous Governance, OAuth & API Risk, Supply Chain Integration Risk, App-to-App Security Subscribe to our newsletter: https://www.linkedin.com/newsletters/true-positives-7435782529825038336/ Get a demo: https://www.obsidiansecurity.com/get-a-demo Sign up for a trial: https://www.obsidiansecurity.com/trial
- Website
-
http://www.obsidiansecurity.com
External link for Obsidian Security
- Industry
- Computer and Network Security
- Company size
- 51-200 employees
- Headquarters
- Palo Alto, California
- Type
- Privately Held
- Founded
- 2017
- Specialties
- Advanced Threat Protection, Insider Threat Protection, Threat Detection, Threat Response, Automated Intelligence, Machine Learning, Information Security Software, SaaS Security , Incident Response, Visibility and Monitoring, and compliance
Employees at Obsidian Security
Locations
-
Primary
Get directions
Palo Alto, California, US
-
Get directions
Newport Beach, California, US
-
Get directions
Cheltenham, GB
Updates
-
Security Outcomes Are Business Outcomes — So Why Is There Still Distance Between Boards and CISOs? 31 years after the CISO role was created, most CISOs still don't have a real seat at the table. 60% don't report directly to the CEO or board. 25% get less than 15 minutes per quarter to brief their board. Only 29% of boards have a member with any cybersecurity expertise at all. Meanwhile, AI is compressing the timeline on everything: the attack surface, the speed of exploitation, the cost of a wrong deployment decision. Boards are setting aggressive AI goals that often outpace what's actually been secured, and CISOs are left owning the risk on decisions they weren't in the room for. Obsidian Security's Head of Threat Intelligence, Carl Shimel's piece makes the case plainly: security outcomes are business outcomes: reputation, continuity, revenue, regulatory exposure. Treating the CISO as a peripheral advisor instead of a strategic partner isn't just a governance gap, it's a business risk. Worth the read for anyone thinking about how boards need to evolve as AI reshapes what "security" actually protects. #ciso #ceo #cio #security #saassecurity #ai #aisecurity #obsidiansecurity 🔗 Full piece linked below. https://lnkd.in/gN7JAV4e
-
Your supply chain is bigger than your vendor list. Every OAuth grant, non-human identity, and third-party integration creates a path into the applications where your business runs. And those paths don’t stop changing when the vendor review is over. On Monday, Chris Fuller, Field CTO & Sadia Haque, PMM of Obsidian Security are diving into how surging AI adoption and increasingly capable frontier models are reshaping third-party supply chain risk: ➖ Why the vendor is no longer the unit of risk ➖ Where exposure concentrates across integrations, standing credentials, and non-human identities ➖ What to audit first without ripping out the workflows your business depends on 🗓️ The New Supply Chain: Third-Party Risk in the Age of Apps, Agents, and AI Monday, August 31 | 11am PT / 2pm ET Register for the webinar → https://lnkd.in/gfGhPkRf
-
-
Obsidian Security reposted this
Obsidian Security is proud to be a signatory on OpenAI's call for collective cyber defense — an open letter signed by 100+ organizations across industry, government, and AI, including Anthropic, Microsoft, CrowdStrike, Cloudflare, and Snowflake. The premise is one we've been living for a while now: AI is compressing the timeline on both sides of the fight. The letter is direct about it — status quo security won't hold. Longstanding bugs, excessive permissions, misconfigurations, and technical debt aren't new problems, but AI-enabled attacks exploit them faster and at greater scale than security teams were built to handle. The part that hits closest to home for us: frontier AI companies are being asked to "ensure agentic identities are traceable and accountable" as part of this collective response. That's the exact problem we exist to solve — visibility and control over every human and non-human identity touching your SaaS estate, agents included. No single company, tool, or defender closes this gap alone. That's the actual point of a letter like this — it's a commitment to share tools, threat intelligence, and hands-on support, especially with the under-resourced teams protecting the infrastructure we all rely on. Glad to stand alongside this group. Full letter and signatories here: https://lnkd.in/gFeKj4Q7 #frontierai #aisecurity #agenticai #openai #obsidiansecurity #saassecurity
-
-
Obsidian Security is proud to be a signatory on OpenAI's call for collective cyber defense — an open letter signed by 100+ organizations across industry, government, and AI, including Anthropic, Microsoft, CrowdStrike, Cloudflare, and Snowflake. The premise is one we've been living for a while now: AI is compressing the timeline on both sides of the fight. The letter is direct about it — status quo security won't hold. Longstanding bugs, excessive permissions, misconfigurations, and technical debt aren't new problems, but AI-enabled attacks exploit them faster and at greater scale than security teams were built to handle. The part that hits closest to home for us: frontier AI companies are being asked to "ensure agentic identities are traceable and accountable" as part of this collective response. That's the exact problem we exist to solve — visibility and control over every human and non-human identity touching your SaaS estate, agents included. No single company, tool, or defender closes this gap alone. That's the actual point of a letter like this — it's a commitment to share tools, threat intelligence, and hands-on support, especially with the under-resourced teams protecting the infrastructure we all rely on. Glad to stand alongside this group. Full letter and signatories here: https://lnkd.in/gFeKj4Q7 #frontierai #aisecurity #agenticai #openai #obsidiansecurity #saassecurity
-
-
2 out of 5 AI agents running today carry a risk factor serious enough to leak data or wipe a table. Without visibility or controls in place, a misunderstood prompt by a Claude agent could mean a production table gets wiped. Or your inbox gets deleted. But humans and their agents are handicapped without write access, so how can you let Claude run without letting it run wild? On August 26 at 11am PT, Scott Young & Viet Tran show you how to govern high-risk actions in Anthropic's Claude Code and Cowork: at the granular tool level, after Anthropic’s security controls end, and how to identify risky access and stop destructive actions. Register for our 20 minute webinar to hear insights from real observed environments. Because agents don’t ask twice but your security tools can. https://lnkd.in/g-v7MdYm
-
-
Obsidian Security reposted this
Tomorrow. 20 minutes. This briefing is for those who have to answer: do we revoke the token, suspend the integration, shut down the account, or let it keep running? Carl Shimel and Farah I. will walk through a decision framework for making that call before an incident puts you on the clock. The outcome: a clearer response plan, a smaller blast radius, and fewer decisions being made for the first time during an incident. RSVP today (we'll send you the recording if you can't make it!) 👇 https://lnkd.in/gSDbRbei
-
On the heels of Series-D, John Furrier sits down with our Head of Finance Chithra Rajagopalan in this NYSE Wired SiliconANGLE & theCUBE interview to talk AI Security from a CFO's lens. Every AI agent an organization deploys touches financial systems, customer data, or decision-making in some way. That means every AI agent is now a line item on the risk register, not just the tech roadmap. A few things related to AI governance through a finance lens: → The cost of an ungoverned agent isn't hypothetical. One bad action — a leaked dataset, an unauthorized transaction, a compliance miss — can wipe out years of margin in a single incident. → "Move fast" and "stay compliant" aren't opposites if governance is built in from day one. Retrofitting controls after adoption is always more expensive than building them in up front. → Boards are starting to ask about AI risk exposure the way they ask about cyber risk exposure. CFOs who can't answer that question clearly are going to feel it in due diligence, audits, and insurance conversations. The organizations getting this right aren't slowing down AI adoption to be safe. They're treating AI governance as an enabler, the thing that lets them scale AI faster because trust is already built into the system. #finance #security #data #ai #aisecurity #agenticai #obsidiansecurity #cfo Watch the full interview: https://lnkd.in/gpNQZuAR
-
-
Your Friday scroll has been interrupted by six people who know an alarming amount about how agents, attackers, and third-party apps are creating new paths to your data. That’s good news for you. In our mini-series "Agents, Attackers & Third-Party Apps: the New Path to Your Data," we get straight to it: what’s changing, where access and risk are expanding, and what security teams should be watching now. 📅 August 18, 26 & 31 11 AM PT | 2 PM ET 6 experts. 3 short sessions. 1 mini-series. The first session airs live Tuesday. RSVP here: https://lnkd.in/gVBdn8gW #ThirdPartyAccess #SaaSDataSecurity #NonHumanIdentity
-