4 ms·
If you're in security and you haven't at least heard of Wiz, I have doubts about what you actually do. I'm not saying you have to be a CSPM expert, but not even
by ryanSrich 2y ago
If you're in security and you haven't at least heard of Wiz, I have doubts about what you actually do. I'm not saying you have to be a CSPM expert, but not even hearing about Wiz, when they are the largest CSPM, is somewhat concerning.
- aleph_minus_one 2y ago> If you're in security and you haven't at least heard of Wiz, I have doubts about what you actually do. IT security a very wide field. For example, a lot of positions in IT security are actually about compliance (i.e. lots of documentation), and ensuring the rollout of all necessary application patches in the whole company.
- marcus0x62 2y agoCompliance and patch/vulnerability management teams are a major constituency for CSPM tools.
- ramraj07 2y agoI know diabetologists in India who didn't hear about Ozempic till late 2024. Sometimes the simpler explanation is the correct one.
- assanineass 2y ago[dead]
- msm_ 2y agoI am in security for many years now, my main focus is reverse engineering (but I did many diverse things, including cryptography, some exploit development and the opposite, AV work, I did R&D in security automation and some development of security tools and engines). I never even looked at a CSPM, and from my point of view[1] CSPMs are a tool only relevant for a small part of security teams focused on enterprise cloud security. Today is the first time I heard of Wiz. edit Actually my partner works in policy/compliance/legal side of security, and I'm pretty sure she never heard of Wiz too. [1] I wrote this only to stress how different people in the same field can see things differently.
- tptacek 2y agoI've heard of Wiz, but would have had a hard time listing out their feature/benefit statement, because I don't work with CSPM tools. I don't think this "I have doubts about what you actually do" line is doing the work you want it to; it may be backfiring on you a bit.
- ryanSrich 2y agoCNAPPs and CSPMs are extremely common tools in cybersecurity. This is my concern. If you're in cyber and don't have knowledge of these things you're either in something insanely niche, in research of some sort, or lack critical knowledge that you should have. There's a big responsibility as a security practitioner to stay up to date on new tools and techniques. CNAPP and CSPM is not some new thing that was invented last year. It's been around for a decade.
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- arachnids 2y agoYou might want to google the person you’re arguing with
- brailsafe 2y agoOne of those beautiful HN moments where just clicking the profile link would have helped them shift from such an authoritative tone.
- csomar 2y agoCSPM solutions are what corporate buys when they don't want to invest in security. It is rubber-stamping and ass covering. From my experience most people involved with such platforms are rather technical sales people than actual security experts.
- 2y ago
- udev4096 2y agoBullshit. Infosec is not just about highly inflated startups or whatever the fuck CSPM means. I know people who do exploit dev, reverse engineering, blue teaming and they have never heard of wiz. Stop overexaggerating
- nickpsecurity 2y agoI've been securing my cloud instances the same way I would for dedicated hardware. I use the same tools. I periodically eyeball usage data from the service providers to make sure their end is OK. Takes 5-15 minutes. Occasionally run updates. It all mostly just keeps chugging along. What is a CSPM? Some cloud monitoring tool? What does it provide over open-source security and monitoring tools with years of field use that would make me invest time into it? Also, have these tools been thoroughly audited, scanned, fuzzed, and pentested by reputable people like some of the open source tools we've been using? Since tools are part of the attack surface, do these tools themselves increase or reduce it? Serious questions since you think I should be very knowledgeable about these tools. My tech stack just works with minimal maintenance. So, I'd have to lose time on more important or fun stuff to even study CSPM or Wiz. Not counting setting it up.
- deleted 2y ago[deleted]