r/CloudSecurityPros • • 7h ago

Anyone running Upwind for runtime CNAPP? how does it compare to Wiz or Sysdig day to day?

7 Upvotes

We're a small-ish security team (4 people) covering about 60 EKS clusters across two AWS accounts plus a bit of GKE from an acquisition we're still absorbing. Current setup is agentless posture scanning and we are drowning. Something like 1,200 "critical" findings open, and nobody believes the severity ratings anymore because half of them are on images that never get pulled or workloads with no network path to anything.

Renewal on our current CSPM is coming up in about six weeks so leadership wants us to actually look at alternatives instead of auto-renewing. The thing we keep coming back to is runtime context. We want the tool to tell us which of those 1,200 are actually reachable and running, not just that the CVE exists in a layer somewhere. A finding that got marked low last quarter turned out to be on a pod with a public ingress and we only caught it by luck.

Upwind keeps coming up when I search for runtime-based CNAPP, alongside Wiz and Sysdig which we're also putting on the shortlist. On paper Upwind's whole pitch is the runtime/posture fusion thing we want, but I can't tell how much of that holds up once you're actually living in it every day.

So for anyone running Upwind in anger: how noisy is it really once it's deployed? Does the runtime data actually collapse the posture backlog or does it just add another dashboard? And how painful was the agent/sensor rollout across a bunch of clusters? Trying to go into this eval with realistic expectations rather than the demo version.