The employee wanted to download software. A sponsored search result offered a familiar-looking route to it. The website was a counterfeit; the download was malware. In the incident described by Zip Security and its advisory partner Observa, the first thing to fail was an ordinary act of recognition. Something looked legitimate, so someone clicked.
- Zip sets up and operates security tools for businesses with lean teams.
- Its proposition is coordinated execution: devices, identities, threats, and audit evidence.
- Customers buy by custom quote; published savings are estimates.
The download that became a drill
The interesting part came after the click. According to the published account, endpoint detection killed the malicious process, managed detection and response isolated the device, and outbound connections were blocked. The machine was subsequently wiped as a precaution. The attack stayed on one device. The case study reports no data loss or customer impact.
Those are vendor-reported outcomes, rather than an independently reconstructed incident. Still, the sequence explains Zip’s business more clearly than a page of dashboard adjectives. Several systems had to perform complementary jobs. Owning them was only the beginning. Someone had to make the handoffs work.
- 01DetectStop the process
- 02IsolateContain the device
- 03ResetWipe as a precaution
The expensive space between tools
Josh Zweig and Gabbi Merz encountered this coordination problem while securing government systems at Palantir. They founded Zip to turn that expertise into software a smaller organization could operate. SecurityWeek dates the company’s founding to 2022. Zweig is CEO; Merz is CTO.
A Mac fleet might run through Jamf, Windows machines through Microsoft Intune, identities through Okta, and endpoint protection through CrowdStrike. Each product has its own view of the organization. Zip connects these systems, helps configure them, and keeps controls enforced through a common operating layer. It also supports Google Workspace and Microsoft’s identity services.
“We are the glue”Josh Zweig, speaking to SecurityWeek
The phrase is wonderfully unglamorous. Glue earns its keep where things meet. Zip’s proposition places it between established vendors and the people responsible for running them. The alternative is often a staff member juggling consoles, or an outside service doing the juggling. A prettier console would be a small improvement. Reliable execution is the larger wager.

A clinic discovers the missing layer
Pine Park Health’s clinicians provide primary care to elderly patients, including people in assisted living communities. Their devices travel with them. Zip’s case study describes a previous workforce platform that handled basic provisioning and remote locking but left gaps in continuous monitoring and policy enforcement. Devices sometimes lost their enrollment state, leaving IT unable to manage them.
Then an acquisition added a largely Windows-based medical practice to the mix. The operational question changed: could a small team keep different systems under consistent control? Pine Park considered buying Jamf and Intune directly, with additional monitoring. It chose Zip’s coordinated approach, which included CrowdStrike monitoring, device lifecycle workflows, and access to security expertise.
This is a useful account of what changed a customer’s mind. The burden was the continuing work after installation. In Zip’s telling, Pine Park retained a lean IT operation while policies applied automatically as devices enrolled. That is a practical benefit for a clinician whose appointment schedule has little room for a laptop emergency.

Ambience Healthcare supplies another version of the same problem. Zip reports that the healthcare AI company grew from 15 to more than 150 employees while adding one security team member. The co-managed arrangement covered corporate devices, access, monitoring, and compliance evidence. Internal staff could concentrate on core infrastructure while retaining visibility into the controls.
The invoice behind the dashboard
Zip sells a B2B software platform with managed operations and expert support. Its pricing page markets a flat annual rate and invites buyers to request a quote. That makes the right cost question broader than the subscription: which licenses, deployment tasks, monitoring responsibilities, and response services does the agreement cover?
The public calculator illustrates the sales argument using a $120 monthly per-user MSSP baseline. For 50 employees, that produces $72,000 annually. Zip advertises savings of up to 80%, but labels them estimates dependent on scope and contract terms. The calculation below reproduces that illustration. It is no substitute for comparing actual proposals.
Investors have funded the attempt to make those economics work: a $7.7 million seed round in November 2023, followed by a $13.5 million Series A in July 2025. Ballistic Ventures led the latter. The disclosed rounds total $21.2 million. Funding buys room to build; it does not establish a customer’s return.
A shared file joins the threat model
In June 2026, Zip introduced Google Workspace data loss prevention. It examines file metadata and up to 180 days of sharing history to identify publicly exposed Drive files, explain their risk, and let administrators revoke public access. The company says it neither reads nor stores file contents. An everyday collaboration setting becomes a manageable security task.
September brought participation in CrowdStrike’s Project QuiltWorks, focused on extending protection against frontier AI risk to smaller businesses. A separate Galvanick partnership addresses the boundary between corporate IT and industrial operational technology. Both moves show Zip relying on specialist capabilities while organizing their delivery.
The habit worth borrowing
Start with the handoffs. Who notices an unprotected device? Who acts on an alert? Who verifies that a policy still applies? Zip’s model makes most sense where supported cloud tools and repeatable controls account for much of the workload. Bespoke environments and unusual operational requirements still need explicit scoping. Compliance evidence also needs an organization behind it.
The lesson is portable: name the owner of the work between products. A shopping list can be completed once. A security program has to get up tomorrow.
Website · LinkedIn · Company blog · Interactive product tour · Customer stories · Funding coverage