Based on our migration project timeline, we had Orca's agentless collector deployed, scanning, and returning prioritized risk data in under 4 hours for a 112-EC2-node environment across three AWS accounts. The bulk of the time was configuring the read-only IAM role and Security Hub integration.
Key time sinks:
* IAM Policy refinement: ~90 minutes. Their template is broad. We trimmed it down before deployment.
* Initial full scan duration: ~75 minutes for our estate. This is highly variable based on node types and API call volume.
* Excluding development/staging resources from critical alerts: ~30 minutes post-scan.
The technical setup is minimal. The collector runs as a single container. Our deployment command:
```bash
docker run -d --name orca-collector
-e AWS_ORCA_ROLE_ARN="arn:aws:iam:::role/OrcaSecurityRole"
-e ORCA_API_KEY=""
orcasecurity/orca-collector:latest
```
The operational time investment is in interpreting and integrating the findings into existing workflows. For a pure "time to first alert," it's under half a day. For a production-grade deployment with tuned policies and alert routing, budget 2-3 business days.
EXPLAIN ANALYZE