Alright, let's set the stage. We're a 500-engineer AWS shop, multi-account, landing zone-ish structure, heavy on ECS/EKS, Lambda, and the usual managed services (RDS, S3, etc.). Our security team is small but mighty, and we've been using a mix of open-source tooling, AWS-native services (Security Hub, GuardDuty, Config), and some custom scripts for cloud security posture management (CSPM) and vulnerability management.
Palo Alto Networks is pushing their Cloud CDR (Cloud Delivered Security Services) model hard with Prisma Cloud. The narrative is that it's a unified, streamlined approach for CSPM, CNAPP, and CWPP, all delivered from their cloud. The sales pitch makes it sound like it could replace our patchwork.
My core question for this community is: **For an organization of our size and complexity, is Cloud CDR truly sufficient as the *primary* control plane for cloud security, or does it inevitably become just one piece of a larger, more fragmented puzzle?**
I'm particularly curious about a few operational dimensions:
* **Data Residency & Latency:** With everything processed in their cloud, are there tangible latency issues for real-time workload protection or alerting? For teams in regulated industries, how have you handled data sovereignty requirements when all findings funnel through their SaaS?
* **Cost Predictability:** Their consumption-based model for Cloud CDR. Does it lead to "bill shock" in dynamic environments? With 500 engineers constantly deploying, have you found it hard to forecast or control costs compared to a more traditional seat-based or resource-based license?
* **Depth vs. Breadth:** While it covers a lot, does the Cloud CDR model provide the same depth of control and customization in specific areas (like container image scanning granularity, or serverless function inspection) as you might get from a best-of-breed point solution? Or do you find yourself making compromises?
* **Integration & Automation Burden:** How seamless is the integration back into our existing developer workflows (Slack, Jira, CI/CD pipelines) and SIEM? Is the API robust enough to allow us to build our own automation and overrides, or do we feel locked into their portal's way of doing things?
I'm trying to move beyond the feature checklist and understand the operational reality. We're not just buying a scanner; we're buying a process and a potential bottleneck. The promise of consolidation is incredibly appealing, but I'm wary of trading a known, messy toolkit for a sleek, monolithic one that might have its own unique constraints.
Any war stories, architectural insights, or even gotchas from those who've gone down this path would be invaluable. Especially interested in comparisons to a hybrid model or running Prisma Cloud self-hosted (which I know is an option, but they're clearly steering everyone toward CDR).
~jason
~jason