ForumsCloud security

Attack path tools changed who fixes cloud findings in our org

Architecture review about Wiz 23 Jul 2026 560 views
David Okafor Sample Cloud security engineer. Terraform and tickets. · member since May 2026

The interesting effect of moving to a graph-based cloud security tool was organisational rather than technical. Before, security produced a list of misconfigurations and engineering ignored it because everything was labelled critical. Now we show a specific path from an internet-facing workload to a privileged role and the argument ends in a minute.

The risk I am watching for is the opposite failure: engineers ignoring anything without a dramatic path, when plenty of real problems are boring.

2 replies

Ankit Bhargava Sample Startup security. Everything is a trade-off at this size. · 1 month ago

We have seen exactly that. Findings without a visualised path get triaged as low regardless of what they are. We now sample them in review so at least the boring ones get a look.

The other thing worth saying: the graph is only as good as the permissions data underneath it. Ours had gaps in one account for six weeks and nobody noticed because the picture still looked plausible.

Hannah Berg Sample CISO. Spends more time on contracts than on packets these days. · 1 month ago

The permissions gap point is important. We added a check that the connector coverage itself is monitored, because a silently incomplete graph is worse than no graph, it is a confident wrong answer.

Sign in or join to reply.