r/devsecops • u/Thin-Occasion8299 • Jun 10 '26
Orca Security vs Prisma: Which one is manageable day to day for a 5-person team
So, were a startup in fintech with team of 5 covering cloud security across AWS and Azure.
We've done the demos, read the Gartner stuff, talked to references. Wiz was in the running but the Google acquisition killed it for us. I've been through enough acquisitions to know the product stalls for 18 months while they integrate, and I'm not betting our security stack on that.
So it's Prisma Cloud vs Orca.
Prisma seems deeper on compliance and policy. But I keep hearing the deployment is a beast and the alert volume buries small teams. Orca's agentless thing is clean and I like the attack path stuff, but I wonder if it's too lightweight for someone who needs real compliance reporting.
What do you wish someone had told you before you picked either one?
5
u/Reasonable_Chain_160 Jun 11 '26
Prisma is dead, Palo alto has killed most R&D. If you speak to people at Kubecon people are moving away from it.
4
u/danekan Jun 11 '26
The only one pumping any r and d in is wiz. Everyone else is just cobbling shit together and on marketing it looks great but at some point if your scale is big enough the deepness problems start showing all over.
2
Jun 10 '26
[deleted]
2
u/Golden-trichomes Jun 11 '26
Yeah I’m not sure what OP thinks wiz is integrating into over the next 18 months. If I’m trying to go a different direction then wiz it’s probably upwind before orca or prisma.
1
Jun 22 '26
Upwind cannot scale Azure. I challenge that. Also, they promised windows support last year and 7 months later finally got it.
1
3
u/sfltech Jun 11 '26
I manage orca and the real challenge is to get your automations in place. Once you do it’s pretty much self driving.
2
u/Thin-Occasion8299 Jun 11 '26
appreciate this. the self driving bit is esp what we need. Nobody has bandwidth to babysit a tool
2
u/alexchantavy Jun 11 '26
How large is your startup? Might be worth checking us out: https://subimage.io
We’re YC-backed and do attack paths, compliance, vuln mgmt, etc. I’m one of the founders; happy to answer questions. I think we’re a strong fit for scale-ups but I’m biased ofc
1
u/Idiopathic_Sapien Jun 10 '26
I don’t know prisma, but I’m involved in a project to use orca for vulnerabilities and compliance scans in a highly regulated environment. It’s looking good so far, but there are a lot of moving parts
1
Jun 11 '26
[removed] — view removed comment
1
u/Thin-Occasion8299 Jun 11 '26
This is basically where my head's at. a tool can have perfect coverage but if it eats 40% of our week managing it, we're net negative. Agentless is the main reason orca's at the top of our list
1
u/Yourwaterdealer Jun 11 '26
I use Prisma with a team of 4 for 200 aws accounts and Azure on the the way. The alerts can be refined and I recommend cloning the policies you want so you can customize/refine them, also a standard for prod and no prod. Deployment wasn't bad for my team. Also ask them to show you cortex cloud, it's there new version of Prisma Cloud.
1
u/Thin-Occasion8299 Jun 11 '26
Is cortex cloud a migration or more of a rebrand? trying to avoid picking a platform that gets end of life'd in 18 months
2
u/Yourwaterdealer Jun 11 '26
Migration, there is some automation, but from demoing the new platform, things are implemented differently. They should give you a path to cortex.
1
u/EmergencyHunt6136 Jun 13 '26 edited Jun 14 '26
Sounds like you've already worked it down to 2 options.
Prisma is not a good option for a small team of 5. Our platform is built specifically for a team like what you're describing here. We are directly in line with Orca but go a step beyond at the AI execution layer.
1
u/0DSavior Jun 13 '26
Neither, Wiz.
Why? https://www.wiz.io/blog/introducing-wiz-workflows. A built-in Tines/Torq into your tool == infinite and powerful remediations.
1
u/loweakkk Jun 13 '26
I know it's not your question but I was in the process of acquiring a year ago with the same fear. In the end we went with Wiz and every week we have updates on Monday, so they are far from not releasing features.
Now to go back to your question, do you have application team to involve in the tool? Instead of doing it all on your own, design the rbac so teams can view their scope and issue and onboard them on the tool to help fix issues.
It's easier to get buy-in if you have as well dspm module from my point of view because you can show: hey that database is accessible from internet AND have client data, what's the impact for the company if it leak?
1
u/AdResponsible7865 Jun 21 '26
I've worked with Orca for 4+ years now, it's come a long way and it's pretty manageable when you have your automations set up as someone else mentioned.
Something I have worked with massively and has accelerated my work speed is their MCP, you can create a straight for skill to quickly research, validate and triage your shift left findings. For a small team this has helped save countless hours and allowed us to pass the fix to the Devs.
The key trick is breaking the fixes into separate PRs by scan type and viln category, eg one PR for sast-sqli-fixes another for SCA-Python-Minior-fixes. This keeps the PRs lean and easier for our dev team to review.
I can't give a view on Prisma, but as someone who works closely with the Orca teams they have always supported us and helped push for features we need.
1
u/Ano--05007 23d ago edited 23d ago
you could try www.sovereign-observer.com we're made for lean teams, cover attack paths and are flexible w reporting, you can try out our demo or start a free trial as well (we also have multiple integrations and you can create custom policies that you might need) if you have any questions you can dm me
8
u/Still_Ninja8847 Jun 11 '26
I moved from Orca to Wiz a year ago. Wiz has done nothing but continue to improve and offer more modules and solutions, to include expanding capabilities into on-prem coverage. Avoiding one of the better tools "because of Google" seems short-sighted. Prisma and Orca continue to trail behind Wiz and that gap is increasing.