You're spot on about the FinOps angle. It's the hidden engineering hours that never make it into the initial TCO.
> I've seen teams spend more time making Drata *look* green
Yup, been there. We ended up building a whole separate Terraform module just to manage the exclusion lists for noisy controls. It felt like we were building and maintaining a parallel meta-system.
One thing I'd add: this also impacts your cloud bill directly. Those custom Lambda feeders and log subscriptions add up, not to mention the increased data transfer from shuffling logs around. It's a triple cost - license, engineering time, and infrastructure spend.
Has anyone tried pushing back by quantifying *all three* in a unified report for leadership?
Infrastructure as code is the only way
Quantifying the triple cost is exactly the move, but you're assuming leadership wants the real number. In my experience, they often don't.
That unified report becomes a political liability. You show them the infrastructure spend for the Lambda proxy pipeline, the engineering hours burned on Terraform modules for exclusions, plus the license fee, and the math looks terrible. So they kill the report, not the tool. The incentive is to keep the costs buried in "platform" and "security" budgets where they're less visible.
The real pushback isn't in a report. It's in forcing the tool's cost into the same P&L as the product features it's supposedly securing. When the feature team's margin drops because 30% of their sprint is feeding Drata, that's when priorities shift. But that requires a level of internal accounting honesty that's rarer than a straightforward AWS bill.
-- cost first
Been in the same meeting. The real kicker is when the "requirement for enterprise sales pipeline" evaporates after a few lost deals because prospects don't ask for it. But the tool and its maintenance tax don't get sunset. You just keep paying to make the green lights flash for an audience that stopped looking.
CRM is a necessary evil
That last point is the quiet part nobody says out loud. The compliance tooling gets justified as a "sales enablement" cost, but when that pipeline dries up, it never gets reclassified as pure overhead. The budget line just sticks around.
I've seen this with GRC platforms that were purchased for a specific RFP that later fell through. The engineering upkeep becomes permanent, like a phantom limb. The worst is when the sales team moves on to the next "must-have" checkbox, and you're left maintaining two of these meta-systems.
Latency is the enemy, but consistency is the goal.
That breakdown feels painfully accurate. I've already seen the time sink from false positive management when we set up our first security scanner.
It makes me wonder, for those 50-60% of hours spent on integrations and noise, do you ever push to just turn off the noisiest controls entirely? Or is that politically impossible once the dashboard is a KPI?