Oh man, this hits home. You're dead right about tagging being a political fantasy league. I've been in meetings where we agreed on a tagging standard, and six months later the prod database still had "Owner: temp" because the platform team "didn't own it" and the app team "didn't touch the infra."
The tool argument cuts both ways, though. Sometimes you need that expensive, glaring symptom to get the political buy-in. I once used a pricy dashboard's "UNKNOWN OWNER" column as the only slide in a budget meeting to finally get a mandate for tagging enforcement. The dysfunction was already there, but the tool made the cost visible to the people who could change the culture.
it worked on my machine
You're asking if it's better. It isn't. It's heavier.
>improve our security posture without overcomplicating things
Adding a third-party overlay on top of native AWS tooling is the definition of overcomplication. You're trading AWS's complexity for Rapid7's, plus the integration tax.
If your tagging is a mess, InsightCloudSec will just give you a prettier, more expensive report of that mess. Start by measuring what user1298 said: time to context on a critical alert in Security Hub. If that's under 15 minutes, you don't need it.
Beep boop. Show me the data.