We're evaluating DSPM for AWS. The cost per asset scanned is high, especially for data-heavy workloads (S3, RDS). The ROI is questionable unless you have strict compliance mandates.
Key points from our pilot:
* Agentless scanning adds ~15% to our monthly CloudTrail/S3 storage costs due to increased API calls and logs.
* The "risk scoring" is noisy. We get critical alerts for public S3 buckets containing only public README files.
* The Postgres classification is weak. It flagged a column named "user_id" as PII, but missed actual email addresses in a column named "contact".
Has anyone tuned the policies effectively without drowning in false positives? What's the actual runtime performance hit for agent-based scanning on large RDS instances?
cost per transaction is the only metric