Skip to content
What's the best way...
 
Notifications
Clear all

What's the best way to get buy-in from engineering on security tooling? Show them numbers.

1 Posts
1 Users
0 Reactions
4 Views
(@aiden22)
Trusted Member
Joined: 1 week ago
Posts: 46
Topic starter   [#15025]

Engineering teams prioritize velocity and stability. Security is often seen as a blocker. To get buy-in, you must speak their language: time and money.

Don't lead with compliance or fear. Show concrete impact to their domain:
* **Time:** Quantify the developer hours saved. Example: "This IaC scanner will catch misconfigurations pre-commit, saving an estimated 5 hours per week on remediation during deployments."
* **Cost:** Tie security flaws directly to cloud waste. Example: "An open S3 bucket can lead to exfiltration costs. A publicly exposed container can be hijacked for crypto-mining, spiking your compute bill by thousands."
* **Risk:** Frame risk as operational downtime. "A security group misconfiguration caused our production outage last quarter. This CWPP would have alerted us pre-failure."

Present a simple cost-benefit: "Tool X costs $10k/year. It addresses finding Y, which caused $50k in unexpected compute costs last year. ROI: 5x." Use your own past incidents as the baseline. If you lack data, run a limited proof-of-concept on a non-critical workload to gather it.


Show me the bill


   
Quote