Sam Langrock

Security Reporting Built Around Your Program
We've all been there: it's 3:00 PM on a Friday, and you get that "quick" request for a specific security status report. Suddenly, your afternoon is gone as you juggle filters, export CSVs, and try to explain to someone outside the security team why these numbers actually matter. Reporting shouldn't feel like a fire drill…

Vulnerability Management Requires Real-Time Intelligence
Security teams aren't short on data. But they’re often short on context and time. The average vulnerability management program is buried in alerts, running on scan results that are hours or days old, and facing both savvy and unskilled attackers that can leverage AI to develop sophisticated exploits in minutes. That combination is why backlogs…

Validate the Real-World Exposure of Your APIs with Upwind Attack Surface Management
Your APIs are probably the least-monitored component of your attack surface. They multiply faster than any team can document, and most scanners only ever pick up the ones you already know about. But that gap just got smaller. Upwind’s Attack Surface Management capabilities now provide a unified view of cloud and API exposure, helping security…

Upwind Integrates with PagerDuty for Instant Incident Response
Upwind now integrates with PagerDuty, enabling security teams to create workflows that automatically route Upwind findings and detections to the appropriate on-call team based on existing incident management workflows. This integration expands Upwind's growing library of native workflow integrations, giving security and platform teams even more ways to turn real-time detections into immediate action. What's…

Focus Mode for AI Security: A Dedicated Workspace for Identifying and Securing Your AI Stack
When we launched Focus Mode, we built it around the way security teams actually work: Vulnerability Management, Cloud Security Posture, Attack Surface Management, Threat Detection & Response, Administration. Each one strips away everything unrelated to the job at hand. AI Security is the next domain in the Focus Mode lineup, and it's built for a…

Complete KSPM: From Pull Request to Production Runtime
Kubernetes environments move fast. Workloads appear and disappear, container images change continuously, services are exposed, permissions evolve, and development teams deploy updates throughout the day. But most cloud security platforms force practitioners to investigate Kubernetes risk through interfaces designed for the broader cloud, leaving teams to manually filter the noise before they can begin investigating…

AWS Well-Architected Framework Available in Upwind
Continuous Compliance for Cloud Security Teams The AWS Well-Architected Framework is now available in Upwind. The framework helps organizations evaluate architectural decisions and align workloads with AWS best practices across 6 pillars: Operational Excellence, Security, Reliability, Performance Efficiency, Cost Optimization, and Sustainability. The Well-Architected Framework was designed by AWS as a consistent way for teams…

Upwind Brings Realtime Intelligence to Cisco Cloud Control
We are thrilled to announce that Upwind has been selected as a launch partner for Cloud Control Studio, part of Cisco Cloud Control, bringing realtime intelligence on cloud and AI security into the platform. Unveiled at Cisco Live Las Vegas on June 2, 2026, Cisco Cloud Control is the unified platform for agentic IT operations. …

Upwind Expands Runtime Protection to Windows Server VMs
Windows workloads remain a critical part of modern cloud environments. From business applications and identity services to databases and internal systems, Windows Server VMs often support some of the most important parts of the enterprise stack. Today, we’re excited to introduce runtime protection and visibility for Windows Server VMs, expanding Upwind’s runtime coverage to Windows…

Stop Chasing Ghosts: Why You Need Layer-Level Visibility in Your Container Images
The industry has a "shift left" problem. We’ve become excellent at scanning images and generating massive spreadsheets of vulnerabilities. But for most security teams, a scan result is just the start of a forensic investigation. You find a critical CVE, but then the real work begins: Is this in the base image? Did a developer…