Our co-founder Patrick Farwick recently sat down with Josh Zweig, co-founder and CEO of Zip Security, for a Partner Conversation on what an early-stage security program actually needs to hold up under pressure. The short version: most programs don't fail because a team skipped security work. They fail because the work got spread unevenly across six areas that all need to be covered, and one or two got left wide open.
The six starting blocks
Identity, endpoints, cloud, code and pipeline, observability, and resilience. Every early-stage security program touches all six. The problem is that most founding teams go deep on the one or two that feel most urgent, usually because a customer asked about it, and leave the rest as a checkbox. That's how a company can pass a SOC 2 audit and still get breached the same quarter.
Documented is not the same as enforced
One of the clearest points from the conversation: a control that's written down in a policy document is not the same as a control that's actually running. Half-rolled-out MFA and a SIEM nobody reads are the two classic examples. They show up fine on paper. They do nothing to stop an attacker who's already found the gap.
Where the split actually falls
This is also where the partnership between our two firms makes sense. Zip automates and enforces the fundamentals, identity, endpoints, and compliance work, so that the boring stuff that stops most real attacks (MFA, SSO, device trust, identity hygiene) is running continuously instead of living in a spreadsheet. Amomitto picks up the parts that need a person thinking about them: SIEM tuning, incident response, and cloud and application testing. Getting that split right early is what turns into fewer stalled deals the next time an enterprise prospect's security review lands on your desk.
Why the timing matters
The architecture decisions a team makes around identity, devices, and cloud at ten people compound. Standing them up correctly now is far cheaper than retrofitting them at fifty. The goal isn't to build everything on day one. It's building the 80% that matters now, in a way that scales at the right milestones without slowing the team down.
Watch the full conversation
Patrick and Josh go deeper on all of this, including where day-to-day management like patching, onboarding, and offboarding fits, and where set-it-and-forget-it programs quietly fall apart.
Watch the full Partner Conversation on zipsec.com →
Want a program that covers all six, sized to where you actually are?
We'll walk through your current setup against the six pillars, identity, endpoints, cloud, code and pipeline, observability, and resilience, and show you exactly where the gaps sit.
Schedule a security program review →