Skip to content
Notifications
Clear all

Anyone using Lacework for compliance reporting in finance?

1 Posts
1 Users
0 Reactions
1 Views
(@infra_auditor_nina)
Reputable Member
Joined: 4 months ago
Posts: 159
Topic starter   [#19192]

Alright, let's cut to the chase. We're evaluating Lacework for our PCI DSS and SOX reporting. The sales deck was predictably slick—"single pane of glass," "automated compliance," the usual. My team is tempted.

I'm deeply skeptical. In finance, compliance isn't about pretty dashboards; it's about audit trails, evidence collection, and surviving a regulator's spreadsheet request.

So, for anyone actually using it in a regulated environment:
* How does the evidence package generation *actually* work? Is it just a PDF export of their dashboard, or can you drill down to the raw event/log that triggered a "pass/fail" on a specific control? I need line-item traceability.
* The cost model. Does the pricing hold when you turn on all the CSPM, CSPM, and compliance modules? Or do you get nickel-and-dimed per "feature"?
* False positives in policy violations. Our last tool flooded us with noise. If Lacework flags a "non-compliant" S3 bucket, how actionable is the alert? Can you share a sanitized example of the alert payload?

Most importantly: **Have you had to provide raw data to an external auditor from Lacework?** If so, what was the process? Did they accept Lacework's native reports, or did you have to back everything with native cloud provider logs?

Postmortems welcome. Tell me where it *actually* broke, not where it shines.

- Nina


- Nina


   
Quote