P

Gal Nakash

Co-Founder & Chief Product Officer at Reco

Overview

Gal Nakash is Co-Founder & Chief Product Officer at Reco[1][3]. Nakash has held multiple roles at Reco since its founding, including Co-Founder & CTO from October 2020 to December 2022[5] and Co-Founder & VP of Product from December 2022 to December 2023[4]. Prior to Reco, Nakash worked at the Office of the Prime Minister of Israel in various capacities spanning a decade, beginning as a Software Engineer in February 2011[10] and advancing to Head of Research by November 2017[7]. Nakash holds a Bachelor's degree in Economics from The College of Management Academic Studies[11]. Nakash is also listed as a Crew Member at Jibe Ventures as of March 2021[6].

Profile introduction
Source excerptLinkedIn [2]

Active and motivated professional with a proven record of generating and building innovative research groups, managing research and projects from idea to completion, designing educational training, and coaching individuals to success. Responsible for technical strategy, risk management, and critical decision making. Experienced in all aspects of business development, including operations, finance, technology, and co-operations with partners.

Career history

  1. Co-Founder & Chief Product OfficerSep 2023 to presentReco
  2. Co-Founder & VP of ProductDec 2022 to Dec 2023Reco
  3. Co-Founder & CTOOct 2020 to Dec 2022Reco
  4. Crew MemberMar 2021 to presentJibe Ventures
  5. Head of ResearchNov 2017 to Jan 2020Office of the Prime Minister of Israel
  6. R&D Team LeaderJul 2015 to Nov 2017Office of the Prime Minister of Israel
  7. Security ResearcherFeb 2013 to Aug 2015Office of the Prime Minister of Israel
  8. Software EngineerFeb 2011 to Feb 2013Office of the Prime Minister of Israel

Education

  1. Bachelor's degree, Economics2016 - 2019The College of Management Academic Studies
  2. maccabim-reut high school2007 - 2010

Insights & ideas

The through-line

Gal Nakash has been making the same argument since 2020, and each wave of technology has only made it more literal: the perimeter that security was built around no longer contains the business. The problem he and his co-founder set out to solve was that "in a SAS ecosystem there is no parameter and you don't have a network like in the on Prem and Cloud environment" [2], and that this gap was going to be "the next attack surface for large Enterprises in the cloud" [2]. Five years later the framing is unchanged but the urgency has multiplied. Where the pre-AI world was one in which "everything inside was trusted. Everything outside was threat" [1], he now describes a world where "the enterprise has moved outside" [1]: service teams running Salesforce with Agentforce, developers running Claude Code, finance running autonomous agents in NetSuite, marketing using AI tools nobody in IT has heard of, all of it beyond any control point a firewall can enforce [1].

The shift over time is one of tempo rather than thesis. The early pitch was about visibility and configuration hygiene across SaaS applications [2]; the current one is about speed. "Post AI revolution change is the only constant" [1], and the answer is not a better snapshot but a system that keeps moving: "We are building security that moves at speed of AI" [1].

On why SaaS broke the security model

The founding insight was structural. SaaS has no network layer to instrument and no boundary to defend, so the traditional toolkit has nothing to grip [2]. Nakash's answer was to build the missing context rather than the missing wall: "connect the dots between different applications and generate like a contextual graph" that yields insight across access management, configuration management and event monitoring, so anomalies and violations in the SaaS ecosystem can be detected [2]. Reco's product line follows directly from that, combining SaaS security posture management with Shadow IT discovery [2]. The problem was identified from direct exposure rather than market research: he and his co-founder Tal served together in the field of cybersecurity with the Prime Minister's office, and saw the pattern emerging first at large enterprises [2].

On AI agents as the new thing to secure

The agentic shift is, in his telling, the same architectural problem accelerated past the point where humans can track it. "AI agents are now running inside your SAS application autonomously, constantly outside your control" [1]: agents making decisions, copilots writing code, autonomous agents processing invoices [1]. What makes them different is not their intelligence but their multiplication rate. "They run in cloud platforms you don't control. They multiply faster than any security team can track. They create connections between applications that change constantly and bypass every parameter control you have" [1]. He puts numbers on the cadence: new AI capabilities launch weekly, new agents spin up daily, new connections form hourly [1], and "This happens daily, not quarterly" [1]. The conclusion he draws is that snapshot-based assurance is obsolete, and that the companies that win will be the ones that "can secure this dynamic reality, not static snapshots" with "continuous realtime visibility and control as their environment evolves" [1]. He describes Reco's own positioning in those terms: dynamic security for the agentic era, seeing and securing in real time [1].

On shadow IT and shadow AI

Discovery matters to him because organisations consistently do not know what they are running. Reco discovers and secures 15,000 applications [2], and much of the value he describes lies in telling customers about tools they never registered as being in use: "with most of our customers if they don't know about it we discover that they are using snowflake" [2]. He has extended the same argument to AI, discussing the gap between the small set of applications companies believe they have approved and the far larger set actually running, employees reaching for ChatGPT instead of the Copilot licence the company already paid for, and sensitive data going into free tools that were never reviewed [3]. AI sprawl, in his framing, is the current form of a familiar failure: "AI sprawl is exploding" [1] as adoption becomes mandatory at almost every enterprise [1].

On what breaches actually look like

His worked example is deliberately unglamorous. In the Snowflake breach, Reco customers with Snowflake integrations turned out to have former employees who retained access, with accounts configured without MFA [2]. The remedy he describes is access governance done continuously rather than at audit time: who has access, are they configured with MFA, are they configured via SSO, is there unauthorised access or malicious behaviour, checked not just in one application but across the whole SaaS ecosystem [2]. The lesson is that the breach surface is made of leftover accounts and unenforced settings inside applications the security team may not have inventoried.

On owning your SaaS risk

He is blunt that responsibility does not transfer to the vendor. His advice to enterprises is to accept that "you are responsible for the security of your uh SAS Solutions" and to "don't be an ostrich" about it, ensuring visibility, control and protection across the SaaS estate so that data survives the next breach [2]. That accountability framing underpins the product argument: the alternative to knowing is not safety, it is being the last to find out.

On the market and the ambition

Nakash treats SaaS security as a category still in its opening phase. Asked where the company would be in a year, when it had 14 employees and had raised two rounds, his answer was that Reco would be the SaaS security leader, that "this ecosystem just started", and that the company would secure the entire SaaS lifecycle for large organisations worldwide [2]. The later milestones are presented as evidence for that timing rather than as ends in themselves: a $30 million Series B less than ten months after the previous round, taking total funding to $85 million, alongside 400% business growth in 2025 and Fortune 100 customers [1]. He ties the raise directly to the agent thesis, saying it funds expanded AI agent capabilities on the view that "autonomous AI operating in SAS will drive the next decade" [1].

Takeaways

  • The founding thesis is architectural: SaaS has no perimeter and no network to instrument, which is why it became the next enterprise attack surface [2].
  • Reco's approach is to connect data across applications into a contextual graph covering access management, configuration management and event monitoring, then detect anomalies from it [2].
  • AI agents change the security problem through velocity, not intelligence: new capabilities weekly, new agents daily, new connections hourly, faster than any security team can track [1].
  • Static, point-in-time assurance is the wrong instrument for a dynamic estate; the requirement is continuous real-time visibility and control as the environment evolves [1].
  • Real incidents come from mundane gaps: in the Snowflake case, former employees retaining access on accounts configured without MFA [2].
  • Enterprises consistently underestimate their own footprint, believing they have approved a few dozen applications while hundreds are actually in use, including AI tools bought by nobody [3].
  • Accountability sits with the customer, not the SaaS vendor: get visibility, control and protection, and "don't be an ostrich" [2].

Media & appearances

  • Machine DreamsApple Podcasts
    Your Employees Are Using AI You Don’t Know About—And It’s A Security NightmareMost companies believe they’ve approved 30 apps. The truth? Over 500 are running right now. Your employees aren’t waiting for IT approval. They’re using ChatGPT instead of the Copilot you paid for. They’re uploading sensitive data to free design
  • YouTube
    Building Security for the AI Era: Reco's CPO on Product ...Gal Nakash announces Reco's $30 million Series B funding round, bringing total funding to $85 million. He discusses how AI adoption has created new security challenges as AI agents operate autonomously in SaaS applications outside traditional perimeters, requiring real-time visibility and dynamic security controls that move at the speed of AI rather than static security approaches.
  • YouTube
    AWS Startups on the Red Carpet - Reco SaaS Security - YouTubeGal discusses Reco, a SaaS security company he co-founded in 2020 that provides SaaS security posture management and Shadow IT discovery. He explains the company grew from recognizing that SaaS environments lack traditional network perimeters, a problem he identified with his co-founder from their shared background in cybersecurity with the Prime Minister's office. He gives an example involving Snowflake integration security gaps, such as former employees retaining unmonitored access without MFA, and states goals of becoming the leading SaaS security company securing organizations worldwide.

This page shows public professional information only, each fact cited. Is this you? send a correction, or ask for removal within 24 hours, no questions asked.