
About Arjun
Arjun has spent his career automating security workflows for fast-growing SaaS companies. He writes about practical remediation, not vendor fairy tales.
Arjun covers what CNAPP deployments look like on day 400: which findings actually get closed, which ownership models hold up, and where the platform stops and the human work begins.
Former cloud security lead at a multi-account AWS shop, where he ran a CNAPP rollout across roughly 300 accounts and learned exactly how far native remediation goes.
Latest by Arjun Raval

You did not buy a CNAPP. You bought a very expensive to-do list
CNAPP tools are excellent at surfacing thousands of risks, but they lack the mechanism to close them. Here is why the detection-remediation gap persists and how to fix it.

Your cloud tools disagree on 2% of findings, and those are the ones that stall
Conflicting risk assessments across major cloud security platforms force engineers to manually verify findings and stall remediation efforts.

Month four of your CNAPP rollout: coverage is up, closures are flat
Detection velocity in month four of a CNAPP rollout often hits a wall as security teams realize that surfacing a critical finding is not the same as closing it.

One scan, 2,000 hours of engineering work, no extra headcount
Security platforms identify thousands of vulnerabilities faster than engineers can fix them, creating a structural deficit that turns expensive dashboards into shelfware.

Tune your CNAPP so the top 50 findings are the ones an attacker would use
Default CNAPP severity scores often ignore environment context. Effective cloud security operations require tuning alerts for reachability and establishing a dedicated mechanism for closure.
