Great for first pass compliance reviews. Still very Beta for containers and registry integration.
What do you like best?
It basically is like me hiring 6 DevSecOps team members and allows me to save so much time by instantly giving me visibility into the state of my security posture across all my AWS organizations. Even across my container workloads. I could not manage my accounts from a security standpoint without Lacework, not without hiring an entire team of senior AWS security experts.
What do you dislike?
Consistent errors with the UI, container agent integration in wildly unstable, the documentation needs help and to date, we still can't fully integrate our DTR or Artifactory registries. The UI could be more intuitive. It takes some getting used to but it's worth it once you get over that hurdle.
Documentation on the website needs to be improved but luckily Lacework has made up for this by being super responsive to support tickets.
Recommendations to others considering the product:
Run a PoC and you won't be disappointed.
What problems are you solving with the product? What benefits have you realized?
I am better prepared for PCI audits, I can vet recent teams cloud migrations, I can ensure that security related items are visualised then actually prioritised because Lacework makes it evident WHERE the problems are and how critical they are. It's really helped our org shift security left.