Planning: Vendor Choice, Stakeholders, and Licensing

▶ Watch (3:16)

Picking Defender for Cloud because it comes with the subscription is a trap. Paramanathan saw five or six customers buy it and never use it. The real problem: no deep thought about CSPM requirements. His fix is a focused pilot of one tool at a time, not multiple shallow evaluations. Weak stakeholder engagement creates a second trap. Showing management a working tool gives quick buy-in but risks failure without upfront alignment. The third trap is unclear licensing. Vendors charge per workload but define workloads vaguely. One VM equals one workload, but 100 buckets might also count as one. Ask vendors for precise definitions and compare costs with similar companies.

Implementation: Resources and Integration

▶ Watch (19:06)

Underestimating resource requirements blocks pilots. Paramanathan thought he could deploy alone, but IT operations, dev teams, and platform teams all said no. Each infrastructure is unique, and a small change can break something. Scope must be wide enough to synthesize across data sources, but not so wide that it becomes unmanageable. The second trap is technical integration overload. Quick wins lead teams to connect everything at once. Paramanathan recommends starting with high-value integrations: VMs, public-facing assets, and critical systems. CI/CD pipelines require extra care. Never put them in block mode by default. Always test workflows through a ticket system before going live. And do not let a proof of concept become production.

Operations: Ownership, Findings, and Post-Pilot

▶ Watch (25:55)

Ownership gaps appear when features from multiple tools overlap. A young engineer wants to enable every feature. The architect notes the capability already exists elsewhere. The CISO asks what they are paying for. Paramanathan advises mapping capabilities and resisting the urge to activate everything. The second trap is mishandling critical findings. Telling leadership about a severe vulnerability without informing the system owner first creates enemies. Instead, alert the owner, establish a triage process, and loop in the MDR vendor. The third trap comes after a successful pilot: momentum stalls. Use that energy to run workshops, get feedback, and build a security champions program. A tech radar — showing which tools are on hold, in trial, or adopted — spreads knowledge across teams.

Strategic Advice: Actionability and Context

▶ Watch (33:03)

Strategy is about what you say no to. Paramanathan draws on Gregor Hohpe’s enterprise architect model: maximize developer flow, reduce risk, and waste no time. The first strategic trap is a gap between cloud tool insights and actual monitoring. Ask your MDR vendor what they do in your cloud environment — often the answer is nothing. The second trap is prioritizing visibility over actionability. A noisy tool that dumps vulnerabilities with no guidance fails. Shorten the path from finding to fix. The third trap is focusing on graphs instead of context. Attackers have used graph methodology for years. Defenders must aggregate multiple data sources to see lateral movement paths, not just pretty visualizations.

Notable Quotes

“I repeat, please do not let your proof of concept become production.” Johan Paramanathan · ▶ Watch (25:28)

“Ask your MDR vendor or security operations vendor, what are you actually doing in my cloud environment” Johan Paramanathan · ▶ Watch (38:12)

“Actionability is key and not just visibility.” Johan Paramanathan · ▶ Watch (35:01)

Key Takeaways

  • Run one deep pilot at a time instead of multiple shallow ones.
  • Reverse-engineer vendor capabilities using open-source projects like BloodHound.
  • Map overlapping capabilities across tools before enabling new features.
  • Always inform system owners before escalating critical findings to management.

About the Speaker

Johan Paramanathan is a security professional with deep expertise spanning advisory, technology, and architecture. He is a passionate and visible member of the community, frequently sharing his insights on podcasts and through his blog. As a security architect, his background provides extensive experience in key areas such as DevSecOps, enterprise architecture, and cloud security. He brings a broad range of experience across technical, operational, and large organizational initiatives, offering a unique perspective on maintaining cyber security at the intersection of business and technology.