Obsidian Security’s cover photo
Obsidian Security

Obsidian Security

Computer and Network Security

Newport Beach, California 32,062 followers

Comprehensive Security for Your SaaS Applications

About us

Protect your business-critical applications by mitigating threats and reducing risk with Obsidian, the first truly comprehensive security solution for SaaS. The company is backed by Greylock Partners, Wing, GV and Norwest Venture Partners.

Industry
Computer and Network Security
Company size
51-200 employees
Headquarters
Newport Beach, California
Type
Privately Held
Founded
2017
Specialties
Advanced Threat Protection, Insider Threat Protection, Threat Detection, Threat Response, Automated Intelligence, Machine Learning, Information Security Software, SaaS Security , Incident Response, Visibility and Monitoring, and compliance

Locations

Employees at Obsidian Security

Updates

  • Attackers are increasingly targeting SaaS applications and the identities that unlock them. Obsidian’s data reveals a 300% surge in SaaS breaches. But why are these applications the new frontline? Because that's where your data now resides. In an article featured in Cyber Defense Magazine, Obsidian Security Co-Founder Glenn Chisholm breaks down this new trend and offers insights on how organizations can defend themselves against the escalating threats to SaaS identities. Link to the article in the comments. #CyberSecurity #SaaSSecurity #SaaSIdentityProtection

    • No alternative text description for this image
  • 𝗔𝘃𝗼𝗶𝗱 𝗳𝗶𝗻𝗲𝘀 𝗺𝗲𝗲𝘁𝗶𝗻𝗴 𝗶𝗺𝗽𝗲𝗻𝗱𝗶𝗻𝗴 𝗡𝗬𝗗𝗙𝗦 𝗱𝗲𝗮𝗱𝗹𝗶𝗻𝗲𝘀 𝗳𝗼𝗿 𝗦𝗮𝗮𝗦. Several financial services firms have already incurred millions in fines for failing to meet NYDFS cybersecurity requirements, particularly around MFA enforcement. Part 500 of the NYDFS security regulation specifically highlights protecting information systems like SaaS with access to sensitive data. That means any application with nonpublic information like Salesforce and Snowflake are in scope. But SaaS compliance doesn’t have to be a burden. Obsidian Security maps 23 NYCRR Part 500 requirements directly to your SaaS security controls, so you can: • Identify and manage elevated privilege for SaaS to SaaS integrations • Identify federated and unfederated SaaS • Uncover and remediate security and compliance gaps in SaaS • Ensure MFA and access policies are enforced • Detect and mitigate threats before they become violations • Automate compliance tracking and reporting Don’t wait as regulators are stepping up enforcement. Read our latest blog to learn how to stay compliant and secure your SaaS applications. Link in comments. #SaaSSecurity #NYDFS #CyberSecurity #FinancialServices

    • No alternative text description for this image
  • Obsidian leads the way in SaaS security, and part of that is thanks to our leaders. Tune in next week for the first CFO Talks from Chithra Rajagopalan on changes in the SaaS security landscape and what finance leaders need to know. #saasidentitysecurity #womenincyber

    View profile for Chithra Rajagopalan

    Finance Leader | Philanthropist

    We’re officially one week until the very first CFO Talks! Since I announced this series, people have been asking me what finance has to do with security. It’s a good question, and there are two ways to answer it. First, the “stereotypical” security answer: The cost of a data breach is now in the millions, and that’s excluding potential lawsuits, regulatory fines, and loss of customer trust, brand reputation, and stakeholder confidence. As finance leaders, it’s our responsibility to think about these risks. Given that SaaS breaches jumped 300% last year, there’s never been a more critical time to act. While that answer is true, it’s also incomplete. Here’s my second answer. CFOs should care about SaaS security because it drives business value. What I’ve learned from so many customers at Obsidian is to not think of SaaS security as an obstacle. A good strategy leads to outcomes in real numbers. One of our customers saves hundreds of hours every single month with an agile threat response capability. Another speeds up M&A dramatically, by being able to easily scope out their target acquisition’s environment. This scale of efficiency and business growth, that's what finance is all about. Talk to your security team today, and learn more about how Obsidian Security can create value for you. #strategicfinance #cfo #womenincyber #saasidentitysecurity

  • 🚨 Are you ready to test your cybersecurity skills? 🚨 Obsidian Security is hosting the only CTF at BlackHat Asia this year! Join us to get behind the scenes of a real-world SaaS breach: https://lnkd.in/eGCTJH6R

    View profile for Andrew Latham CISSP

    Lead Principal Sales Engineer - APJ @ Obsidian Security

    Obsidian Security is the only Capture the Flag (CTF) running at BlackHat Asia this year. If you are attending make sure you don't miss out on a a hands-on CTF scenario based on a real-world SaaS breach. There will be 2 sessions on Friday April 4 - Session One - 9AM - Session Two - 1PM Don't miss out and book your seat here - https://lnkd.in/gq2GMb95 For more information reach out to Tom Tokic, Shabeel Shah, William Muschetto, Joseph Stubberfield or myself if you would like more information. #ctf #SaaS #SaaSSecurity #SSPM #ITDR

    • No alternative text description for this image
  • Obsidian and HackerOne Present: March Madness Exclusive Event 🏀 Calling all CISOs and security execs! Join us for an action packed day of networking, expert insights, and watching the Sweet Sixteen showdown! Just like on the court, defense wins the game 🏆 📅 When: Thursday, March 27th 📍 Where: Cosm LA, Inglewood, CA Seats are limited, so secure an invitation today at the link in the comments.

    • No alternative text description for this image
  • Despite claims that Okta's CORS policies and device matching can stop AiTM phishing attacks, our research proves otherwise. We demonstrate how attackers can easily modify Evilginx configurations to bypass these controls and steal session cookies—even with MFA enabled. Learn why traditional security measures fall short against sophisticated phishing and what actually works: phishing-resistant MFA like Okta FastPass, proactive domain monitoring, and robust ITDR solutions. Link in comments.

    • No alternative text description for this image
  • “Adversaries are spending 240 days embedded in our SaaS ecosystems before being detected.” Last month, Obsidian’s Alfredo Hickman and Renee Guttmann took the stage at CISO Forum Canada 2025. They shared their experiences as CISOs in the modern SaaS threat landscape, along with Obsidian findings straight from the front lines. A big thanks to siberX for this amazing partnership—we look forward to more! Interested in hearing firsthand how two CISOs are tackling the challenges of SaaS security? Listen to the session here: https://lnkd.in/eDwZRMi4 #cisoforumcanada #cybersecurity

    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image

Similar pages

Browse jobs

Funding