This report is an update of our 2025 report on this topic. If you would like to see a copy of this, please click here.
Key Capabilities
- Cloud Identity and Entitlements (20% of product rating)
a. Discover and continuously analyze all identities (human, service accounts, roles, workload identities, API keys, machine identities).
b. Detect excessive privileges, toxic combinations, privilege escalation paths, and unused permissions.
c. Identify orphaned identities, stale credentials, and weak authentication policies (e.g., lack of MFA).
d. Provide automated least-privilege right-sizing and remediation workflows.
e. Correlate identity risk with resource and exposure context (identity-centric attack path modeling). - Cloud Data and Storage Security (10% of Product Rating)
a. Discover and classify cloud data across object storage, databases, data lakes, file systems, and managed data services.
b. Identify public exposure, weak encryption, improper key management, and misconfigured access controls.
c. Detect sensitive data (PII, PHI, PCI, IP) and map it to identity and exposure risks.
d. Correlate data sensitivity with network and identity risk to prioritize remediation.
e. Monitor data access patterns for anomalous behavior. - Cloud Network Security (10% of product rating)
a. Discover and analyze network topology, ingress/egress controls, and segmentation.
b. Identify publicly exposed assets and internet-facing workloads.
c. Detect risky firewall rules, overly permissive security groups, open ports, weak TLS configuration.
d. Model lateral movement paths across cloud environments to identify paths to risk. - Cloud Compute Security (10% of product rating)
a. Assess configuration posture of VMs, containers, Kubernetes clusters, and serverless functions.
b. Detect vulnerabilities in OS, packages, and dependencies.
c. Provide runtime threat detection (behavioral analysis, anomaly detection).
d. Monitor container runtime activity (process, network, file integrity).
e. Support Kubernetes security posture management (KSPM). - Cloud DevOps Security (20% of product rating)
a. Scan Infrastructure-as-Code (IaC) templates (Terraform, CloudFormation, ARM).
b. Scan container images and registries for vulnerabilities and secrets.
c. Integrate with CI/CD pipelines (shift-left security).
d. Detect secrets in code repositories.
e. Support SAST/DAST/SCA (where integrated).
f. Provide risk correlation between code findings and deployed cloud risk. - Cloud Threat Detection and Response (10% of product rating)
a. Capabilities designed to monitor, detect, analyze, contain, and remediate security incidents in cloud environments.
b. Detection of anomalous activity and cloud-native attack techniques.
c. Identity-based and workload-based threat detection.
d. Forensic investigation support.
e. Automated response and remediation workflows.
f. Integration with SIEM, XDR, and SOAR platforms. - Cloud GenAI Security (10% of product rating)
a. Capabilities to analyze the technology related risks from the development of AI-based applications.
b. Discover and monitor use of AI/GenAI services across cloud environments.
c. Assess access control, data exposure, and model security risks.
d. Identify sensitive data used in AI training or inference pipelines.
e. Monitor AI infrastructure misconfiguration and model deployment risks.
f. Detect AI-specific risks such as prompt injection exposure or insecure API usage (where applicable). - Cloud Security Posture (10% of product rating)
a. Unified risk dashboard across identity, data, network, workload, and code.
b. Context-aware prioritization using attack path and blast radius modeling.
c. Compliance reporting against common security frameworks and best practices such as NIST CSF, ISO/IEC 2700x, CIS, as well as major regulatory obligations.
d. Custom policy creation and regulatory mapping.
e. Executive reporting and remediation tracking metrics.