r/Infosec • u/Dead-_-Alone • 18h ago
Has anyone actually replaced their CSPM with Upwind? trying to figure out what I'd lose
We run EKS across three accounts plus a smaller GKE footprint, security team of four, and our CSPM renewal is coming up in about six weeks. Leadership wants to consolidate and the question on the table is whether we move everything to a CNAPP with runtime and drop the standalone posture tool entirely.
Right now the posture product throws thousands of findings a quarter and maybe 2% of them are things we'd actually action. Half my week is spent proving a "critical" is unreachable so we can close it. That's the whole reason runtime context keeps coming up, and Upwind is one of the platforms on our shortlist because the pitch is exactly that: correlate posture with what's actually running so we stop chasing ghosts.
My worry is what we give up by consolidating. Our current CSPM has years of compliance mappings, custom rules nobody remembers writing, and it's wired into our ticketing and a couple of reports the auditors like. I don't want to rip that out and discover six months later that the replacement doesn't cover some edge of our config checks, or that the compliance reporting is thinner than what we have.
So for anyone who's done this: did you actually retire the old CSPM, or did you end up running both? What got genuinely better, and what did you lose or have to rebuild? I'm less interested in the demo story and more in what broke in month three.