Shift Security’s cover photo
Shift Security

Shift Security

Computer and Network Security

Coming soon...

About us

We're hiring. Email us at Careers@shift.security.

Website
https://www.shift.security
Industry
Computer and Network Security
Company size
11-50 employees
Headquarters
New York
Type
Privately Held

Locations

Employees at Shift Security

Updates

  • We’re now part of Anthropic's Cyber Verification Program, with unrestricted access to Claude's most capable models for defensive security work. Third-party involvement in confirmed breaches reached 48% last year, up 60% year over year. At that scale, every improvement in how fast and accurately exposure gets calculated matters.

    • No alternative text description for this image
  • Big news: Shift and Cyera are now integrated. A vendor's security score tells you how their controls looked at assessment time, but it doesn't tell you whether they hold your customer PII, your regulated financial data, or nothing sensitive at all, and this distinction is what actually determines exposure when something goes wrong. Cyera classifies where your sensitive data lives. Shift maps which vendors can actually reach it. Now, security teams can see vendor posture, third-party access, and sensitive data exposure in a single workflow. Know which vendors are worth worrying about before an incident makes that decision for you.

    • No alternative text description for this image
  • Shift Security reposted this

    For 71% of companies, the main trigger to reassess a vendor's security is that vendor getting breached. This year Gartner named the category built to fix it: Cybersecurity Third-Party Intelligence (CTPI). The idea is overdue… stop treating vendor risk as a form you collect once and start treating it as a live signal - correlating what's happening inside your environment with what's happening outside it, continuously. Because a questionnaire can't answer the questions that matter when a vendor goes down: - Which vendors have access to your systems right now - What can they actually see and do - One just got breached - what did they touch in YOUR environment The teams that handled Salesloft, Gainsight, Mixpanel, Vercel, and more, cleanly already had the inside-out view: access, identities, API keys, data. So when the news broke, they scoped the blast radius in minutes and acted - cut the connection, kill the credentials, contain it. The whole point is that you won't prevent every vendor breach, but you can know exactly what it means for you the moment it happens, and move before the attacker does. Gartner named six vendors in the new category, and Shift Security is one of them. When a vendor gets breached, does your team measure the response in minutes or days?

  • Shift Security reposted this

    Five years ago, when I was still at Microsoft, the first Microsoft Christmas Ugly Sweater came out. It instantly became the ultimate piece of company swag. I tried everything to get one - pulled every string (looking at you, Amir Barkol 👀), bought far too many charity raffle tickets - but no luck. That sweater became a legend. Not because it looked great (it was, in fact, very ugly), but because it represented something bigger: belonging. Fast forward to today — I finally have a new favorite piece of swag and it’s Shift Security’s very own. While I don’t expect our Lululemon backpack to generate as much buzz as that legendary sweater, I’ll say this - if you want one, there’s only one way: come work with us!

    • No alternative text description for this image
  • Shift Security reposted this

    Now that the dust has settled from the Salesloft Drift breach, let's talk about the real problem. Most breaches don't come through YOUR systems now. They come through your vendors. You're checking if you use Salesloft. Wrong place to look. The breach will come through: - Your marketing agency's Drift account - Your sales partner's integration - Your contractor's tool you never knew existed Hundreds of companies were compromised. Most didn't even know Drift was in their supply chain. The true impact? Still being discovered. The stolen credentials? Already being weaponized. Your vendor's breach IS your breach. And you might already be affected. Who got hit: Cloudflare. Palo Alto Networks. Zscaler. Proofpoint. If security companies couldn't detect this, what chance do you have? Post-Salesloft, these are now mandatory Monday morning questions for security teams: Question 1: Which vendors have access to your systems? If you're checking a spreadsheet, you're already wrong. Question 2: What can those vendors actually see and do? If you're reading contracts instead of logs, you're blind. Question 3: Your vendor just got breached. Can you name what they had access to? If you're thinking "which vendor?" - exactly. These questions used to be theoretical. After Salesloft, they're survival checks. Google confirmed attackers harvested credentials to "compromise victim environments." YOUR customers. YOUR data. Through vendors you might not even know exist. Stop wondering. Start knowing. → DM me. Shift Security

Similar pages