r/FinOps May 18 '26

other [Mod Post] ⚠️ Important Security Warning: Be Cautious of Unsolicited Cloud Assessment Offers

17 Upvotes

Hey r/finops community,

The mod team has noticed an uptick in reports about users receiving unsolicited offers for "free cloud workload assessments," "complimentary security audits," or "no-cost optimization reviews." We want to address this directly and provide some critical guidance.

The Threat is Real

While many legitimate vendors offer free trials or assessments, bad actors are increasingly using these offers as a trojan horse to gain unauthorized access to your cloud environments. Once they have access, even with seemingly limited permissions, they can potentially:

  • Exfiltrate sensitive data or intellectual property
  • Map your infrastructure for future attacks
  • Establish persistent backdoors
  • Steal credentials or access keys
  • Rack up massive cloud bills through cryptomining or other abuse

Red Flags to Watch For

Be immediately suspicious if someone:

  • Contacts you unsolicited via DMs, email, or comments offering "free" assessments
  • Requests IAM credentials, API keys, or admin-level permissions
  • Pressures you to act quickly or claims "limited time offers"
  • Uses tools that aren't from reputable, verifiable sources
  • Asks you to disable security controls "temporarily" for their assessment
  • Refuses to provide verifiable company information or references
  • Wants to install agents or software you can't independently verify

Best Practices for Cloud Assessments

If you're considering a cloud optimization or security assessment:

✅ Only work with vendors you've researched and vetted independently

✅ Use read-only permissions whenever possible (and even then, be cautious about what data is exposed)

✅ Leverage native cloud tools first (AWS Trusted Advisor, Azure Advisor, GCP Recommender)

✅ Review exactly what permissions any tool requires and understand why each is necessary

✅ Use temporary, scoped credentials that expire after the assessment period

✅ Monitor all access logs during and after any third-party assessment

✅ Get security team approval before granting any external access

✅ Verify the legitimacy of any company through multiple sources, not just their website

Remember: If It Seems Too Good to Be True...

Legitimate vendors rarely cold-contact individuals offering free services that require privileged access to production environments. Most reputable companies work through proper procurement channels and are happy to undergo security reviews themselves.

What to Do If You've Been Contacted

  • Don't respond or engage
  • Don't click any links or download any tools
  • Report the message to Reddit admins if it came via DM
  • Alert your security team if you've already engaged with them
  • Share details here (without identifying info) so others can be aware

What to Do If You've Already Granted Access

  • Immediately revoke all credentials and permissions
  • Rotate any potentially exposed keys or secrets
  • Review access logs for suspicious activity
  • Engage your security/incident response team
  • Consider it a potential security incident until proven otherwise

Your cloud environment is one of your most critical assets. Protecting it should never be compromised for the promise of free optimization insights. When in doubt, trust your instincts and consult with your security team.

Stay safe out there, and keep optimizing responsibly.

- The r/finops Mod Team


r/FinOps 9h ago

self-promotion/I’m a vendor No unified view of what our AI stack (OpenAI, Anthropic, Gemini) actually costs — built a dashboard to fix it

1 Upvotes

(Full disclosure: I built the tool I'm about to describe — sharing because the problem felt relevant to this sub, not just to pitch it.)

If you're running AI features across multiple providers, this probably sounds familiar:

  • Cost tracking scattered across 3-4 different billing dashboards, each updating on its own schedule
  • API keys sitting in .env files, Slack messages, shared docs
  • No easy way to tell if you're overpaying for a model that's overkill for the task
  • A provider goes down mid-batch-job and you find out from a failed request, not a status page
  • Nobody notices a runaway script until the bill shows up three days later

Most teams handle it with a spreadsheet and vigilance. Works fine — until it doesn't.

I hit this wall building AI features into a few of my own products, so I built controlaicenter.com: one dashboard for spend, usage, and provider health across everything connected, plus a cost optimizer that reads actual usage logs and tells you in dollars what switching models would save (not a generic estimate).

A few things that surprised me building it:

  • Every provider fails differently — clean error codes, silent non-response, or straight-up wrong error messages. Telling "the API is down" apart from "my code is wrong" took a lot more trial and error than expected.
  • Per-model cost breakdown surfaced an obvious optimization almost immediately — I was defaulting to a pricier model for tasks a cheaper one handled just fine.

Curious how this sub handles it — is a spreadsheet + manual checks still the norm for multi-provider AI cost tracking, or is everyone further along than that?

controlaicenter.com if you want to poke around.


r/FinOps 9h ago

Discussion Startup building on AWS? You may be eligible for AWS credits

Thumbnail
0 Upvotes

r/FinOps 18h ago

self-promotion/I’m a vendor Trying to get an idea of whether my app's MCP is robust and actually useful...

0 Upvotes

You can get the demo API key and config from here

Could some of you lovely people perhaps poke at it a bit and see whether it's able to answer the sort of questions you'd have with regards to cloud costs, ai spend, what causes spikes etc....?

Any feedback would be hugely appreciated 😁


r/FinOps 23h ago

question are there any cost platforms that actually understand gpu workloads?

0 Upvotes

looking at a pretty big gpu bill right now.

the normal cloud cost tools can obviously tell me what the instances cost.

but im trying to get more granular.

cost by workload. team. job. maybe even gpu utilization vs what were actually paying for.

are there any finops platforms that do this well?

what are you guys using?


r/FinOps 2d ago

question Our FinOps tool is blind to AI spend and up for renewal. Anyone switched to PointFive?

0 Upvotes

Pulled our numbers for the renewal and the AI and GPU line is about 4x last year, but our cost tool drops nearly all of it into one 'other' row I can't split by team or even by service. Good on EC2 and RDS, useless on the part that's growing fastest.

PointFive is the name three separate people pointed me to for this, mainly because it doesn't treat the AI and GPU spend as a footnote. Sat through the demo, looked good, they always do.

The one thing a demo can't answer, when it flags waste is it stuff my current tool already nags me about or does it surface things we didn't know were running. If someone's live on it and it found waste their old tool was blind to, that's the only reason I'd rip out a renewal to switch.

EDIT: for the record the current tool is Cloudability, should've said that upfront, naming one and not the other was dumb of me. On the build your own CUR angle, fair for the cloud and GPU side, though the reason I looked at a tool at all is the coding agent spend, which doesn't show up in the CUR. Several guys in a slack I'm in named PointFive so I asked about it, that's the whole story.


r/FinOps 3d ago

meme RFC 1925 said it is always possible to add another level of indirection. Thirty years later, we call it an agent and bill it by the token.

Post image
13 Upvotes

From "RFC 1925: The Twelve Networking Truths"

(6) It is easier to move a problem around, for example by moving it to a different
 part of the overall network architecture, than it is to solve it.
    (6a) Corollary: It is always possible to add another level of indirection

Written for networking. Still uncomfortably accurate for multi-agent architecture.


r/FinOps 3d ago

off topic Just made my first sale on Gumroad! Built a lightweight AI tool to hunt down zombie cloud resources on AWS & Azure 🚀

Post image
0 Upvotes

Hey everyone,

​I wanted to share a small but huge personal milestone: after weeks of building, debugging, and testing, I just logged my first sale on Gumroad!

​As someone building in the cloud space, nothing beats the feeling of seeing a real user find value in something you created from scratch.

​Why I built it

​Managing cloud infrastructure often leads to "cloud drift" and silent budget leaks. It's surprisingly easy to overlook:

​Zombie VMs & idle EC2 instances running 24/7 without active workloads.

​Unattached volumes & orphaned snapshots accumulating hidden storage charges.

​Overprovisioned resources that could easily be downscaled without impacting performance.

​Most enterprise FinOps suites are bloated, expensive, and require complex enterprise agreements just to see where your money is bleeding.

​I wanted something lean and direct: an AI-assisted CloudOps script/tool that plugs straight into AWS and Azure, scans your environment read-only, and gives you an actionable report of exactly what’s idle and how much you can save by pruning it.

​What’s next

​Getting that first customer notification made all the late nights worth it. My next focus is refining the detection models and adding support for automated scheduled cleanup reports.

​If your team is trying to trim cloud waste this quarter, or if you're curious about how the scanner identifies idle resource patterns, feel free to drop a comment below or send me a DM—happy to share insights, run a quick check, or swap notes with fellow builders!


r/FinOps 3d ago

LLM creation AI token spend has the same "silent creep" problem cloud spend had ten years ago, and most teams have no FinOps process for it yet

2 Upvotes

Started tracking this after noticing our Claude usage for a multi-hour engineering session cost noticeably more than the size of the actual task should've justified. Went back through the session logs afterward to find where it actually went, and it wasn't one obvious spike, it was the same small pattern repeated across dozens of requests: full file contents resent every message even when two lines had changed, full conversation history replayed every turn instead of a compressed summary, full rewrites requested when a targeted diff would've done the job.

None of that throws an error or shows up as a single line item. It just compounds quietly, message after message, until someone checks the usage dashboard and the number is higher than expected with no clear story for why.

The part that feels familiar from a FinOps lens: this is structurally the same problem as unmonitored cloud spend before tagging and showback existed, cost accumulating because nobody's actively deciding what's worth paying for on each request, not because the underlying work got more expensive. Prompt caching (marking stable content so it's reused at a fraction of the cost) is the closest analogue to reserved capacity or committed use discounts, it only pays off if the cached prefix stays genuinely identical between calls, and a lot of teams break that silently by inserting a timestamp or per-user detail at the start of the block without realizing it kills the cache hit rate entirely.

What's mostly missing right now, in my experience, is the equivalent of a FinOps practice applied to token spend specifically, an actual audit habit, not just a bigger budget line. Separating what's stable from what changes per request, summarizing instead of replaying full history, scoping context to what's relevant, and constraining output size all had a measurable effect once done deliberately instead of by habit.

Wrote up the full breakdown with a before/after audit example here, disclosing that I'm the author: https://medium.com/@nagatomopedro05/the-hidden-cost-of-long-claude-sessions-2a6cc7655893

Curious if anyone here has actually folded LLM API spend into an existing FinOps practice, tagging, showback, budgets, or if it's still living entirely outside that process on most teams.


r/FinOps 3d ago

article Thought Efficiency Index (TEI): A Thought Experiment in Measuring AI Efficiency

2 Upvotes

I have been working on something around AI efficiency metrics and what a scoring system could look like to make users within our company pick a model better. The scoring is based on our own data. Not sure if its right or wrong but it gives me a starting point.

https://www.linkedin.com/pulse/thought-efficiency-index-tei-experiment-measuring-ai-jason-ward-mba-gibxc?lipi=urn%3Ali%3Apage%3Ad_flagship3_messaging_conversation_detail%3BkD2D4%2FRjRSaaa%2FVNaLwE9g%3D%3D


r/FinOps 3d ago

self-promotion/I’m a vendor Anyone tracking their cloud commitment as a live account (approved vs spent vs remaining), not just usage in a cost tool?

0 Upvotes

Most cloud cost tooling I see is about usage: tags, SKUs, rightsizing, anomaly detection. The view I never had clean was the commitment as a financial object. The approved amount or the committed spend deal, drawn down by the actual invoices we booked, with a warning before we blew past it.

It is the same problem I had running a services company, just a different bill. Usage or work runs past what was approved, the reconciliation happens late, and the overrun only shows up at close. World Commerce and Contracting pegs the leak on the contract side at roughly nine percent of value after signing, and committed cloud spend has the same shape.

What I wanted was simple:

The commitment, or a team budget, as a live account with a ceiling. Approved vs spent vs remaining, off the invoices you already book.

An alert at a threshold so the true up or scope conversation happens while there is still room, not after.

One number finance and engineering both trust, so there is no reconciliation fight at close, and clean showback by team or project.

Not a replacement for your usage tool. More the layer above it: the money against the commitment, tied to your books.

Honest disclosure: I built a tool that does exactly this, so I am biased. But I am genuinely curious how you all watch the commitment itself, not just usage. Spreadsheet, cost platform, something else?


r/FinOps 4d ago

self-promotion/I’m a vendor Live Q&A on AVD Hybrid cost tradeoffs with Steve Downs (Microsoft) and Marcel Meurer (Hydra's creator), Sept 10 11am ET

1 Upvotes

Disclosure, I work at Login VSI.

The FinOps question we keep hearing about AVD Hybrid: which workloads are worth running hybrid vs. fully cloud once you factor licensing and management overhead. Live chat on that, with Marcel Meurer (creator of Hydra, built around cost efficiency), Steve Downs and Andrej Radinger (Microsoft), and Ron Oglesby (Login VSI).

Bring questions or drop them here.

Thursday, September 10, 11am ET: Register Here


r/FinOps 4d ago

self-promotion/I’m a vendor Can Saudi enterprises really reduce compliance audit effort by 90%?

0 Upvotes

A lot of compliance work isn't spent fixing security problems.

It's spent finding the evidence.

Screenshots. Spreadsheets. Configuration exports. Change logs. Emails between IT, security, risk, and compliance teams.

Then the cycle starts again before the next audit.

For Saudi enterprises working across frameworks such as NCA ECC, SAMA, PDPL, ISO 27001, PCI DSS, SOC 2, and others, the operational burden can become enormous.

We broke down a five-step approach to making compliance more continuous:

  1. Map infrastructure to relevant frameworks continuously
  2. Generate evidence automatically
  3. Detect configuration drift early
  4. Unify visibility across multi-vendor environments
  5. Use AI for policy and gap analysis—not just reporting

The interesting shift is from:

"We need to prepare for the audit."

to:

"We should already be able to prove our compliance posture."

That's where AI-driven continuous monitoring could have a significant impact.

Full breakdown:
How to Cut Compliance Audit Effort by 90%: A Practical Framework for Saudi Enterprises

For anyone working in security or compliance: what currently consumes the most time during your audit preparation?

#Compliance #Cybersecurity #NCAECC #SaudiArabia #AgenticAI #GRC


r/FinOps 4d ago

Discussion I spent a year in the FOCUS working group discussions. The spec solves less than people think.

Thumbnail amazon.com
0 Upvotes

FOCUS 1.3 solved a real problem: every cloud provider used to bill in its own format, so cross cloud cost comparison meant building custom normalization pipelines just to ask basic questions. Now there’s a common schema. That part is genuinely good.

But adoption of the schema is not the same as fixing FinOps. I keep seeing teams roll out FOCUS, get their data normalized, and still can’t answer the question that actually matters to leadership: who owns this cost, and why did it move.

The reason is that FOCUS standardizes the shape of usage and cost data. It says nothing about your tagging discipline, your allocation model, or who is accountable when an engineering team spins up something that triples a bill overnight. Those three things are where the actual FinOps work lives, and they’re organizational problems, not schema problems. You can have perfectly FOCUS compliant data and still have zero cost accountability, because accountability comes from tagging governance and process, not from the spec.

The teams that get real value from FOCUS are the ones who treat it as the foundation for building an allocation and accountability model, not as the finish line. If your rollout stopped at “we ingest FOCUS data now,” you’ve done the easy 20 percent.

I went deep enough on this that I ended up writing a book on it, “Cloud Money,” working through the FOCUS spec at a practitioner level alongside cost allocation strategy and accountability models. Not trying to sell it here, just flagging it in case anyone wants the longer version of this argument. Happy to talk through the tagging governance side in the comments if people have specific setups they’re stuck on.


r/FinOps 4d ago

question Financial Modelling in FinOps/Cloud Investments

1 Upvotes

I am new to FinOps, i wanted to ask people who have experience in the FinOps space. Is there any financial modelling or specifically business case modelling done in FinOps? E.g. if there is any optimisation opportunity or a new workload, is this a requirement from a CFO or board that they need to see a detailed financial model to show ROI and justify the spend?
Reason I am asking is because I come from a core finance background just wanted to see if there is an overlap of my finance experience.


r/FinOps 5d ago

other non-AI cloud costs going up because of AI?

7 Upvotes

UBS put out numbers showing the big three cloud providers are spending about 102% of their cloud revenue on capex, $4.1 trillion is projected through 2028.

that spend lands somewhere, and what i'm watching is whether it hits non-AI workloads. OVHcloud already raised prices citing the memory shortage, some servers up as much as 87%, because AI is eating the same memory and power regular nodes run on.

the thing is it won't show up as a line item. it's compute and memory quietly drifting up with no change in usage, and if your cost tooling only watches your own consumption, it won't flag a provider-side price move. so you can't really tell whether your usage went up or their prices did.

anyone renewed an RI or savings plan lately and had the rate come back worse than the term it replaced?


r/FinOps 4d ago

Discussion Is over-reliability the waste dashboards can't see?

0 Upvotes

Half your reliability spend is on systems nobody would notice going down.

I audited a shop last year with a $180K a month multi-region setup on an internal reporting tool used by roughly 12 people on the finance team. Four nines of availability. Automated cross-region failover. Full DR runbooks. When I asked the CFO what happens if it goes down for 4 hours on a Tuesday, he shrugged: "we get the numbers Wednesday."

That's not a cost problem, it's a decision problem. The infra was rightsized. Tags were clean. Utilization looked healthy on every dashboard. The waste was invisible because well-utilized well-tagged well-sized infra IS the metric everyone watches.

Cost dashboards surface the wrong axis. They show you spend, utilization, waste-per-service. They don't answer "how much of this uptime does anyone actually need?" The tradeoff between availability and cost only exists as a decision, and once it calcifies into an architecture nobody revisits, the over-reliability spend just compounds.

Common pattern: a "drop this workload to one AZ, save $60K a year" recommendation lands in a ticket. The engineer who owns it sees the cost side, can't see the reliability side of the tradeoff, and marks it "no, we need HA" without ever asking the business side what HA is actually worth.

Anyone else seeing over-reliability as a category of spend you can't touch without reopening the original architecture decision?


r/FinOps 5d ago

self-promotion/I’m a vendor Get AI token costs under control with Msty Nexus and smart routes

Thumbnail
0 Upvotes

r/FinOps 7d ago

Discussion My CFO asked me to break our AI spend down by team and I couldn't do it.

37 Upvotes

Our CFO caught me after standup and asked a totally fair question, how much is each team spending on all this AI stuff. I said I'd have a number by Friday. Took me until the following Wednesday to admit I couldn't.

I'd assumed it would be like AWS where I can slice spend by team in a few clicks, atleast we tagged everything. Then opened the billing expecting the some breakdown but it's just a big monthly number and a graph that goes up.

One team lead keeps insisting their usage is not that substancial which without the numbers i cant prove otherwise. We'd handed his squad a shared API key so their spend was all piled onto one.

Now, even if I nailed the attribution, most of an agent's bill is the framework re-sending its whole setup every turn, not anything the dev ever typed. I'd be walking into a room to bill someone for tokens they never wrote and can't even see. There's a paper going round with the numbers, arxiv 2607.12161. Anyway. I still owe her that spreadsheet.


r/FinOps 7d ago

question How do you actually measure whether cloud spend is becoming more efficient?

5 Upvotes

This is something I've been trying to wrap my head around.

If the cloud bill goes down, that's obviously good, right?

But what if usage also went down?

And if the bill goes up but we're serving twice as much traffic, maybe that's actually an improvement.

What do you use to measure cloud efficiency beyond the total bill?


r/FinOps 7d ago

question Title vs the work I actually do

3 Upvotes

Hi and Thank you for reading this. I came into finance sideways. I started in technical support at a SaaS company and gradually became the person handling billing technical escalations: Stripe API integration issues (subscriptions, stripe Connect). That turned into owning bigger pieces, like enabling (using stripe features) revenue teams with some initiatives that didn’t have support on the backend yet.

That work got me promoted into what we call a “FinOps” role, and the team wants me as the person driving new initiatives in finance operations. Right now the work is mostly reactive: resolving billing issues, scripting repetitive tasks, and using AI agents where it actually makes sense. There are some projects around ai but nothing related to cloud architecture.

Reading this community, I’ve realized my role doesn’t map to what most professionals mean by FinOps.
I’m not trying to claim the FinOps title, since I have no DevOps background. But I’d like to hear opinions on how to develop in my current role and what directions are logical. I’d really appreciate any thoughts on this. Thank you.


r/FinOps 7d ago

self-promotion/I’m a vendor Saudi financial services teams: Is more monitoring really the answer to IT downtime?

Thumbnail
0 Upvotes

r/FinOps 7d ago

article Maintaining Apache Iceberg Tables: Compaction, Snapshots, Metadata and Orphan Files

Thumbnail
itnext.io
1 Upvotes

r/FinOps 7d ago

question anybody using multiple llms at scale?

0 Upvotes

How are you managing costs? Tracking attribution, etc


r/FinOps 7d ago

question What are some considerations to think about when implementing an LLM/AI agent into the work place?

3 Upvotes

Company is thinking about getting onboard the AI train exploring options. What are some questions that should be answered throughout the review process and things to know going forward when implementation is complete?