
About Priya
Priya covers identity, Kubernetes, and the politics of cloud risk. She believes the best security story is one a CFO can read without falling asleep.
Priya builds the datasets behind the publication's research pieces and is the person most likely to tell an editor that a number is not defensible yet.
Background in quantitative risk analysis and vendor due diligence, with a habit of reading pricing pages and product docs more carefully than the vendors expect.
Latest by Priya Shah

Your cloud misconfigurations stay open for 150 days. Here is the proof
Average remediation for critical cloud vulnerabilities now hits 60 days, while medium-severity misconfigurations often exceed five months. Data shows the bottleneck is not detection, but the manual labor of safe closure.

Two tools, two severities, one finding nobody closes
Discrepancies in severity ratings across security platforms and a lack of application context are preventing teams from using native auto-remediation tools in production.

We ran the numbers: managed remediation vs two new engineers over 12 months
Comparing the total output, time-to-value, and operational friction of internal hiring versus Managed Remediation as a Service.

Stop counting alerts. These 4 metrics show whether anything got fixed
Stop tracking total alert counts and start measuring the 30 day reversion rate and developer friction to fix cloud vulnerabilities.

53% of critical detections go unaddressed, and the clock runs 150 days
Critical cloud alerts now sit unresolved for 150 days as enterprise security teams lose ground to a 900% increase in high-severity telemetry.

Build vs buy: the real 12-month cost of your own remediation team
An internal cloud security team costs upwards of $700,000 annually. Here is how that compares to the operational outcomes of remediation as a service.

What good MTTR looks like when your security team is 4 people
For teams under ten people, the gap between cloud detection and closure is widening. We analyze the metrics that define a functional remediation process.

Who owns the fix? Mapping every finding to the person who can change it
Cloud security backlogs grow because the teams that detect risks lack the authority to fix them. Mapping ownership is the first step toward actual remediation.

Wiz vs Orca vs Prisma Cloud: what each one leaves on your plate
CNAPP vendors excel at detection, but the manual labor required to close findings remains the primary bottleneck for security teams.
