- Job title
- Software developer
- Sector
- Freight
- Organization type
- 300-person organization
- Joined
- Nov 2022
- Message
- 42
We are a 10-person B2B software company based in Berlin. For the past two years, we've been running about 15 virtual servers, a few relational databases, and object storage in the cloud. At a tech event I attended last week, everyone was raving about Cloud Security Posture Management. Right after that, we took a demo with a security vendor; they quoted us 6,000 euros for an annual license.
Right now, our infrastructure is managed part-time by two of our senior engineers. We enforce key-based access, regularly audit firewall rules, and run automated backups. Still, there's always that lingering anxiety about facing fines or suffering a data leak because of an exposed storage bucket or a misconfigured port.
For a small team of our size, are these enterprise tools an absolute must, or can we get by with our cloud provider's native free checks and open-source tools?