Leadership Compass

This report is an update of our 2025 report on this topic. If you would like to see a copy of this, please click here.

Key Capabilities

  1. Cloud Identity and Entitlements (20% of product rating)
    a. Discover and continuously analyze all identities (human, service accounts, roles, workload identities, API keys, machine identities).
    b. Detect excessive privileges, toxic combinations, privilege escalation paths, and unused permissions.
    c. Identify orphaned identities, stale credentials, and weak authentication policies (e.g., lack of MFA).
    d. Provide automated least-privilege right-sizing and remediation workflows.
    e. Correlate identity risk with resource and exposure context (identity-centric attack path modeling).
  2. Cloud Data and Storage Security (10% of Product Rating)
    a. Discover and classify cloud data across object storage, databases, data lakes, file systems, and managed data services.
    b. Identify public exposure, weak encryption, improper key management, and misconfigured access controls.
    c. Detect sensitive data (PII, PHI, PCI, IP) and map it to identity and exposure risks.
    d. Correlate data sensitivity with network and identity risk to prioritize remediation.
    e. Monitor data access patterns for anomalous behavior.
  3. Cloud Network Security (10% of product rating)
    a. Discover and analyze network topology, ingress/egress controls, and segmentation.
    b. Identify publicly exposed assets and internet-facing workloads.
    c. Detect risky firewall rules, overly permissive security groups, open ports, weak TLS configuration.
    d. Model lateral movement paths across cloud environments to identify paths to risk.
  4. Cloud Compute Security (10% of product rating)
    a. Assess configuration posture of VMs, containers, Kubernetes clusters, and serverless functions.
    b. Detect vulnerabilities in OS, packages, and dependencies.
    c. Provide runtime threat detection (behavioral analysis, anomaly detection).
    d. Monitor container runtime activity (process, network, file integrity).
    e. Support Kubernetes security posture management (KSPM).
  5. Cloud DevOps Security (20% of product rating)
    a. Scan Infrastructure-as-Code (IaC) templates (Terraform, CloudFormation, ARM).
    b. Scan container images and registries for vulnerabilities and secrets.
    c. Integrate with CI/CD pipelines (shift-left security).
    d. Detect secrets in code repositories.
    e. Support SAST/DAST/SCA (where integrated).
    f. Provide risk correlation between code findings and deployed cloud risk.
  6. Cloud Threat Detection and Response (10% of product rating)
    a. Capabilities designed to monitor, detect, analyze, contain, and remediate security incidents in cloud environments.
    b. Detection of anomalous activity and cloud-native attack techniques.
    c. Identity-based and workload-based threat detection.
    d. Forensic investigation support.
    e. Automated response and remediation workflows.
    f. Integration with SIEM, XDR, and SOAR platforms.
  7. Cloud GenAI Security (10% of product rating)
    a. Capabilities to analyze the technology related risks from the development of AI-based applications.
    b. Discover and monitor use of AI/GenAI services across cloud environments.
    c. Assess access control, data exposure, and model security risks.
    d. Identify sensitive data used in AI training or inference pipelines.
    e. Monitor AI infrastructure misconfiguration and model deployment risks.
    f. Detect AI-specific risks such as prompt injection exposure or insecure API usage (where applicable).
  8. Cloud Security Posture (10% of product rating)
    a. Unified risk dashboard across identity, data, network, workload, and code.
    b. Context-aware prioritization using attack path and blast radius modeling.
    c. Compliance reporting against common security frameworks and best practices such as NIST CSF, ISO/IEC 2700x, CIS, as well as major regulatory obligations.
    d. Custom policy creation and regulatory mapping.
    e. Executive reporting and remediation tracking metrics.
How to Book a Briefing
  1. Go to the KuppingerCole Booking tool webpage.
  2. Under Select a Service, select Leadership Compass Briefing 55 mins.
  3. Under Select Staff, scroll down and select Mike Small
  4. Choose date and time between April 21 - May 28, 2026 that are convenient for your team. Please note: Times will be shown in your time zone.
  5. You will receive an MS Teams invite that you can forward along to others in your company. Alternatively, you can use this as a placeholder and send us an invite with another app.
  6. Please prepare a slide deck and provide it to the analyst

Key Topics to Cover

The briefing should present an overview of these key topic areas, as well as a demo of the product’s capabilities:

  • Discover and continuously analyze all identities (human, service accounts, roles, workload identities, API keys, machine identities) to detect and remediate risks such as excessive privileges, toxic combinations, privilege escalation paths, and unused permissions.
  • Discover and classify cloud data across object storage, databases, data lakes, file systems, and managed data services to detect and remediate risks such as public exposure, weak encryption, improper key management, and misconfigured access controls.
  • Discover and analyze network topology, ingress/egress controls, and segmentation to identify misconfiguration such as lateral movement paths and identify paths to risks.
  • Assess configuration posture of VMs, containers, Kubernetes clusters, and serverless functions to identify and remediate vulnerabilities and risks.
  • Scan Infrastructure-as-Code (IaC) templates (Terraform, CloudFormation, ARM) to identify and remediate security vulnerabilities.
  • Scan container images and registries for vulnerabilities and secrets.
  • Integrate with CI/CD pipelines to control the deployment of code / third party modules with security vulnerabilities.
  • To monitor, detect, analyze, contain, and remediate security incidents in cloud environments and integration with incident response tools and processes.
  • Analyze the technology related risks from the development of AI-based applications.
  • To display and manage cloud security posture and compliance against a range of frameworks and best practices such as NIST CSF, ISO/IEC 2700x, CIS as well as regulatory obligations.
  • Highlighting what is innovative and/or unique to the solution

The demo can be live, video, or canned, although the analyst would like to be walked through the demo, so he understands the products key capabilities including dashboards etc.

Your Benefits of Participation

Benefit from Third-Party Attestation

Receive an objective evaluation of your solution that you can easily integrate into your marketing strategy. Our vendor neutral approach ensures results are trustworthy and credible. Use this assessment as a powerful marketing asset to enhance customer trust.

Increase Brand Awareness

Share your cybersecurity expertise with the world. By participating in our analysis, you gain a platform to spotlight your company. Boost your visibility and establish yourself as a leading provider in the industry. If you take part in this Leadership Compass, your solution will be featured in our Research Library at no cost to you.

Get Insights Into Competing Solutions

Discover how your solution compares with others in the industry. Our analysis provides insights not only into your solution but also valuable information about competitors. Utilize this knowledge to strengthen your position in the market.

Gain Valuable Insights on Your Market Standing

Benefit from a thorough, complimentary evaluation of your solution. KuppingerCole Analysts will evaluate not only your product but also your positioning in the market. Seize this opportunity to receive valuable feedback and make your solution even more effective.

Switch to dark theme

Research Assistant

Hi, I'm Kuppi, your AI-powered research assistant. Ask me about KuppingerCole Analysts' research, events, or analysts.
As an AI assistant, I can make mistakes. Please verify important information.