Portrait of Priya Shah
Research Director

Priya Shah

Original analysis, benchmarks and market landscapes

London, UK · 9 stories

About Priya

Priya covers identity, Kubernetes, and the politics of cloud risk. She believes the best security story is one a CFO can read without falling asleep.

Priya builds the datasets behind the publication's research pieces and is the person most likely to tell an editor that a number is not defensible yet.

Background in quantitative risk analysis and vendor due diligence, with a habit of reading pricing pages and product docs more carefully than the vendors expect.

Coversmarket researchbenchmarksvendor due diligence

Latest by Priya Shah

Research

Your cloud misconfigurations stay open for 150 days. Here is the proof

Average remediation for critical cloud vulnerabilities now hits 60 days, while medium-severity misconfigurations often exceed five months. Data shows the bottleneck is not detection, but the manual labor of safe closure.

Priya Shah  -  August 17, 2026 · 6 min
Comparisons

Two tools, two severities, one finding nobody closes

Discrepancies in severity ratings across security platforms and a lack of application context are preventing teams from using native auto-remediation tools in production.

Priya Shah  -  August 10, 2026 · 7 min
Comparisons

We ran the numbers: managed remediation vs two new engineers over 12 months

Comparing the total output, time-to-value, and operational friction of internal hiring versus Managed Remediation as a Service.

Priya Shah  -  August 7, 2026 · 6 min
Research

Stop counting alerts. These 4 metrics show whether anything got fixed

Stop tracking total alert counts and start measuring the 30 day reversion rate and developer friction to fix cloud vulnerabilities.

Priya Shah  -  July 12, 2026 · 6 min
Research

53% of critical detections go unaddressed, and the clock runs 150 days

Critical cloud alerts now sit unresolved for 150 days as enterprise security teams lose ground to a 900% increase in high-severity telemetry.

Priya Shah  -  July 8, 2026 · 7 min
Comparisons

Build vs buy: the real 12-month cost of your own remediation team

An internal cloud security team costs upwards of $700,000 annually. Here is how that compares to the operational outcomes of remediation as a service.

Priya Shah  -  June 26, 2026 · 7 min
Research

What good MTTR looks like when your security team is 4 people

For teams under ten people, the gap between cloud detection and closure is widening. We analyze the metrics that define a functional remediation process.

Priya Shah  -  June 21, 2026 · 6 min
Research

Who owns the fix? Mapping every finding to the person who can change it

Cloud security backlogs grow because the teams that detect risks lack the authority to fix them. Mapping ownership is the first step toward actual remediation.

Priya Shah  -  June 11, 2026 · 6 min
Comparisons

Wiz vs Orca vs Prisma Cloud: what each one leaves on your plate

CNAPP vendors excel at detection, but the manual labor required to close findings remains the primary bottleneck for security teams.

Priya Shah  -  June 4, 2026 · 6 min