ForumsCloud security

Notes from moving 900 workloads to a CNAPP without a dedicated cloud security team

Implementation notes 16 May 2026 584 views
Hannah Berg Sample CISO. Spends more time on contracts than on packets these days. · member since Mar 2026

We had no dedicated cloud security engineer when we started, which shaped every decision. What worked.

Start agentless, prove value in a week, and only add agents where you can name what the agent gives you that the API cannot. Route findings into the existing engineering ticket queue rather than a security console nobody logs into. Pick five finding types for the first quarter and ignore the rest deliberately, or the volume kills adoption.

What did not work: trying to fix identity permissions and workload vulnerabilities at the same time. Two different teams, two different rhythms.

2 replies

David Okafor Sample Cloud security engineer. Terraform and tickets. · 3 months ago

The five finding types point is the one I would underline. We tried to do everything, the engineering team saw 4,000 tickets and mentally filed us under noise, and it took two quarters to recover that credibility.

Our five were public storage, unencrypted data at rest, over-permissive roles with admin, internet-exposed workloads with critical CVEs, and missing MFA on cloud accounts.

Ankit Bhargava Sample Startup security. Everything is a trade-off at this size. · 3 months ago

Routing into the engineering queue rather than a security console is underrated. Adoption follows the tool people already open in the morning. We did the same and closure rates tripled with no other change.

Sign in or join to reply.