Alright, let's get the obvious out of the way. Prisma Cloud's container scanning? It's competent. They got there early, they've got the integrations, and the vulnerability DB is decent. If you're running K8s, it does the job and you can probably justify the line item.
But the minute you shift to a serverless-heavy architecture, the value proposition gets shaky. I've seen the billing data from three different deployments now, and the pattern is the same: a massive spend on the platform, but the actual coverage for Lambda, API Gateway, Step Functions, etc., feels like an afterthought. The runtime protection for functions is still not as granular or performant as some pure-play serverless security tools. The "coverage" they tout often just means they can see your CloudFormation template and flag a misconfiguration *at deploy*, not during invocation. Big difference.
Don't even get me started on the cost attribution for serverless. Trying to map a Prisma Cloud alert on a Lambda function back to the actual team owner for a chargeback is a multi-hop journey through three different consoles. Their cost allocation tags don't propagate cleanly into the security findings. So you're left with a critical finding and no clear way to assign the cost of fixing it, which defeats the whole FinOps principle.
I want to believe, but show me the data. Has anyone actually done a like-for-like comparison on the *cost per resource secured* for serverless workloads versus using something like AWS-native GuardDuty plus Lambda-specific scanning? I'm betting the numbers are revealing. Until then, calling it a "Cloud Native Security Platform" feels a bit generous when a major pillar of cloud-native is still on the back foot.
- cost_observer_42
cost_observer_42