Cloud Native Application Protection Platforms (CNAPP) are evolving beyond cloud infrastructure security to become the security control plane for AI-native enterprises. As organizations deploy AI services, large language models, AI agents, and autonomous workflows, cloud security must protect far more than infrastructure alone.
In this session, Mike Small, Senior Analyst at KuppingerCole Analysts, shares key findings from our latest Leadership Compass research on CNAPP. Discover how emerging capabilities such as AI-SPM, runtime intelligence, attack path analysis, cloud detection and response, and agentic AI are changing the cloud security landscape and helping organizations make more informed platform decisions.
Who Should Attend
This webinar is intended for CISOs, security leaders, cloud security and enterprise architects, DevSecOps leaders, SOC managers, and risk and compliance professionals seeking to understand the latest advancements in CNAPP and modern cloud security platforms.
Good afternoon, everyone. Good afternoon from Manchester for me, and welcome to the presentation this afternoon, which is called Beyond CNAPP, Securing the AI-Native Enterprise. My name is Mike Small, and I'm a senior analyst with KuppingerCole, and over the past six to nine years, I've been working with a number of different companies to develop and develop AI-native application protection platforms.
So, let's have a look at this. So, first of all, in terms of housekeeping, you're all muted centrally, and we control these features. There will be some polls during the webinar, and we'll be prepared to discuss the results during Q&A. There will be a Q&A session at the end of the webinar, and you can enter your questions using the Livestorm control panel. And don't worry, if you miss anything, we're recording the webinar, and the recording and the presentation slide decks will be made available for download in the coming few days.
So, here is the first poll, and perhaps you would all like to complete the poll and say which of these is the biggest challenge in your hybrid multi-cloud environment. Is it understanding the real risks? Is it the complexity of your environment? Is it managing the shared responsibilities for security? Is it the fact that there are inconsistent tools and capabilities, or do you lack transparent controls?
So, the poll will be up for about 20 seconds, and then we will move on. So, please, will you complete the polls?
So, the message that I get from the research that I have been doing is that securing AI means securing the cloud, and this has made CNAP as the control plane for AI. And we will talk about why that is true and look at some examples as we go through the remaining slides.
So, first of all, let's look at how cloud security is changing. Well, first of all, the cloud has become the foundation for AI-native agents and autonomous workflows.
So, going back to where we were, the cloud is the foundation for the AI-native applications, and building AI-powered applications is critical to use of the cloud. The key problem about cloud is that most cloud security incidents stem from risks that you are responsible for. And to give some examples of that, one is that Snowflake, and many of you will, I'm sure, know Snowflake as a cloud database service. And what was happening was that customers were not using multi-factor authentication to control their use of this.
And so, people could their authentication and therefore could in fact get into their cloud. Another problem, again, to do with identity and access management is that since the cloud is inherently exposed to the internet, then if you have data in the cloud, you have to take action to make sure that it isn't exposed.
And so, if you have S3 buckets that have internet access, then they are implicitly a problem. The next thing is that, in fact, there are complicated, complex paths to risks. And it is possible since most of the cloud entities, most of the cloud virtual resources have permissions that can be used to read or write to data.
And so, unless you carefully understand and control those paths to risks, then you won't be able to protect things. So, cloud services are different for a number of The first thing is that cloud services, cloud resources are ephemeral. The physical resources exist. The days when you had a server that sat beside your desk or that you could point to in a data center no longer exist. The physical resources are owned by the cloud service provider, but your resources are created on demand.
So, you don't really have time to have a conventional approach to things. And this means that all of the different resources know that they are yours because they have an identity and they have access rights, which means you can access them, but nobody else can do. And that has led to this explosion of non-human identities. Every cloud entity, every agent has some kind of identity and some kind of entitlements.
And so, in order to access these, you have a very complicated multi-resourced service. And so, it's very difficult to understand what is connected to what, so that you can fully work out how to secure things and where the risks really exist. And this is made worse by the fact that although each of the services that you might be using provides some kind of controls to help you manage it, each one of them has its own APIs and its different security tools.
So, that has led to this problem to do with understanding what the vulnerabilities are, because when you do a static sweep of your cloud, you find probably hundreds, if not thousands, of vulnerabilities. But which ones of those are actually reachable and how can you manage to control them?
And so, the question is not how many vulnerabilities do you have, but first of all, which of those vulnerabilities is in fact reachable and which of them is in fact active? And that leads you to understanding what you really need to deal with out of all of these hundreds and thousands.
And so, the other challenge is that the conventional SOC tends to be disconnected from the cloud. And so, often the SOC will detect something that is happening in the cloud, but it doesn't have the context with which to manage it. And it also is, therefore, you need to have deeper integration with the SOC in order to understand what the vulnerabilities are. And AI is expanding this attack surface, because you now have the AI services which you're using to implement, develop, train, and deploy AI. You've got all the enterprise data that may be exposed to AI.
And you have the AI development processes, which may be ingesting dubious models, third-party components, which may include changes that you didn't expect that are being made at runtime. And the AI runtime is indeed a specific problem, because there is a big race towards agentic AI.
And so, you have agents that have access rights. And the challenge is always that when you develop these things, in order to make sure they work, the temptation is to give excessive permissions. But the result of that is that, in fact, they then become a risk in their own right.
So, let's move on. So, let's look at how CNAP has evolved over time.
So, the first thing is that CNAP really evolved because of what I would call the acronym soup of cloud security. That there were all of these point products that had grown up, each of which was intended to solve a specific but real cloud security problem. And they all had different interfaces. They had configurations and all this kind of thing.
So, that actually made things worse, rather than made things better. But the objective of it all is to enable the customer of the cloud to secure their use. Because if you go back to the beginning of this, the problem with the cloud is that most of the problems are that, in fact, your customer has not properly secured things.
And so, the customer controls for an infrastructure as a service is that you need to control all the identity and access. You need to control all the applications, the agents, and all the other kinds of things. The databases, code containers, and IAC security, as well as the security of the various elements that are in this. And the actual cloud service provider is only responsible for delivering a secure service.
So, that's what CNAP is trying to do. Now, so when you look at what has happened, CNAP has provided a platform to bring together all of these different acronyms.
So, a good CNAP will contain a way of controlling the infrastructure entitlements and management. That is to say, all the non-human identities. It will provide capabilities for you to control the security of your data, which is to detect and manage data and storage risks. It will also be able to detect and manage app vulnerabilities in code and IAC, as well as third-party component risks.
So, this is part of the new things that have been invoked are what we call AI security posture management. And that is, in fact, now looking at all of the risks and the management of the risks to do with AI and deployment.
So, that should hopefully prioritize active threats and exploitable vulnerabilities. So, the support that is probably the most important one is the support for identity-centric security. It is looking for controls that are critical. If you look at the MITRE and ATT&CK controls, you will find that identity and access management is critical to defend against these. And this has become even more important with the growth of AI, with all of the extra non-human identities.
And so, you need to be able to, for administrators of the cloud, make sure that you enforce strong authentication, that you implement the principles of least privilege, and you detect things like privilege escalation coming from rogue accounts.
And for data security, we're looking in specific terms at denying public access, making sure that where you store your data is not publicly exposed, that it is appropriately encrypted, that you use techniques like confidential computing to provide an extra layer of security, either to share the data or to make sure that the data cannot be detected or cannot be stolen whilst it is being processed. And most of the tools now include some form of prevention. And one of the things that everybody forgets is that the cloud is data. Not only does it contain your data, but it is defined as data.
And that makes it doubly important to make sure that your data backup is running and that your data backup covers not just your business data, but also contains all the data that defines the cloud itself. And again, the challenge here is that artificial intelligence, gen AI, now is able to access that data.
In fact, you give it rights to access that data. And that can, in itself, pose problems in that it can either deliberately or inadvertently disclose the data that you did not want to be disclosed. Threat resilience is becoming an important issue. And this is where we move beyond simply being able to say, what are the static vulnerabilities, through to being able to understand what risks are reachable, what risks are actually active, and how you can detect and respond to those risks.
And a major element of those risks are to do with the ones that are introduced by the development and development of applications, the so-called DevOps risks. And that has another layer added on it, because you've got the development of AI-related risks. And given that all of the cloud is defined in code, then all of the vulnerabilities to do with things like the identity and entitlement of the various components in your cloud will have been defined in that data. And they tend not to have been visible through normal identity governance.
So understanding this, which has become described as code to cloud and cloud to code, is a critical point in managing the risks to do with cloud. So what have we been doing, and what is the research that I've been working on?
Well, I've been creating a market, measuring and investigating the market for CNAP. And in the document that we just recently released that I wrote, this covered all of the vendors that you can see on this screen. And all of these vendors have some kind of CNAP offering. And we have looked at all of those vendors, looking to see how well they are performing. And so when we look at the things that we have found, all of those vendors, every single one without exception, has recognized the importance of AI in the context of cloud risk management and cloud risk assurance.
And that one of the things that is also clear is that all of them are now, or the vast majority of them, have started to include agentic AI agents to help you to manage that security. So they have created and introduced into their products agents that help you to understand what vulnerabilities exist, to understand what you should do to deal with those vulnerabilities, and also to tell you, give you hints about when there is a threat which is active and how you might be able to deal with it.
And the focus of CNAP platforms has moved away from saying, look, we can detect tens of thousands of vulnerabilities, to actually saying, we can show you which vulnerabilities are really at risk, those which are reachable and exploitable in production. And the next key thing that is happening is that all of them, to some degree or another, have found the need to help with detecting and securing the AI use of non-human identities.
And ultimately, although we look at the technical vulnerabilities which are important, I would simply say that every one of the breaches is ultimately due to the fact that something or someone was able to get hold of a genuine set of entitlements which they were able to be used. And so identity and entitlement and least privilege are critical. And what actually matters to most organizations is the impact of all of this on their data. So when we look at CNAP solutions, we evaluate them against eight functional capabilities, and what I would call five qualities.
So we're looking at looking in the solutions for how well they meet the criteria that we have set against all of those areas. And you will recognize those areas that map back to the things that we've been talking about, which is at the top is entitlement and identity management, especially to do with non-human identities and cloud administrators. They're then providing capabilities to do with data and storage security, how well they can secure your virtual networks, the elements that do computing, including things like GPUs, the DevOps process.
So it is all of the tools that are being used to do with DevOps, and in particular things like the Kubernetes world. And now increasingly the way in which they will gen AI security and how they integrate with threat detection and response, and finally give you some measure of how well you are doing. And so when we look at the vendors in this, we categorize those vendors and we plot them on this two-dimensional map. And so the vertical dimension on this is our understanding and our view of the innovation that those vendors are showing in this particular market segment.
And the horizontal access is in fact our evaluation of the completeness and the functionality of the product that is being offered. And the size of the bubbles gives you an idea of the market leadership of that particular vendor. So a bigger bubble is a bigger vendor with more market. And in this you can see that at the top right hand in a pink color are what we call the overall leaders, which are those that have both innovation and product leadership. In the vertical access, some of the ones that are towards the right, which have very strong products, but not yet have innovation leadership.
And towards the left are the challengers. And these are products which are very good in themselves, but often tend to be somewhat of a niche in that they may have focused on particular geographic areas or they may have focused on specific sets of capabilities. And so that is our overall assessment of the market. Now it's interesting to look at the variability in the solutions that we And so this graph shows the percentage of solutions that performed or had the capability that you can see on the left.
So we can see that nearly all of the solutions had some controls or some assessment and management of the controls for the access of AI services. But very few had in fact controls over AI rollout mechanisms. And so you have a range of capabilities. And so it's important when you are choosing a cloud, a native application protection platform, to understand where it fits in your set of capabilities that you need. And this slide shows you, if you will, again, the range of capabilities that we found in the solutions that we measured.
And so like I said earlier on, we measured each of the solutions against these four major security, deployment, interoperability, and usability. And the functionality we looked at in terms of those eight lower capabilities. And so you can see that the area within this radar chart, the outer band is what the best vendor was for each of those areas. And if you look at the inner of the gray area, you can see what the worst capability was for the worst vendor in that particular capability.
So that's not saying that there was one vendor that was worst in all of those or one vendor that was best in all of those. But it's looking at the range of capabilities that the vendors offered. And that gives you, again, an idea of the importance of looking in depth when you are making a choice. So coming back to where we started, what I said at the beginning was that CNAP is becoming the security control plane for the AI native business. And that is because most of the AI deployments start in the cloud, although they may migrate outwards.
And controlling what is going on in the cloud is in fact critical. And the cloud is complex. Most organizations have multiple clouds. And CNAP gives you the ability to have a single way of visualizing and a single way of managing the multiple dimensions of security across the multiple clouds. So thank you very much for that. We now have a second poll. And I will give a few seconds for you to complete the control.
So if you can't see this, it's understanding where your organization's current stage is in the adoption of CNAP, from fully adopted through to partially adopted, or whether you're still evaluating it, or you found some other way and some other method of looking at the CNAP. So with that, I'm going to finish the poll and say, thank you very much indeed. And don't remember, please remember, we've got lots and lots of research. So please go and look at this. So there is a question which says, is security guardrail agentic AI part of CNAP?
Which is very interesting, because what I would say in answer to that is it's interesting because sort of the next story that I'm working on is in fact to do with securing AI. And the market to do with securing AI is almost exactly in the state that the CNAP market was in the beginning, in that there's a wild west of lots and lots of small vendors, each of which are producing specialized tools that address one or more of the problems which are specifically related to gen AI.
And so you have tools that are specifically related to the visibility of agents, the visibility of agentic AI for protection against agents. Now, what is happening with those is that many of them are being acquired by the current and existing CNAP vendors, and being integrated into their CNAP products, or integrated into larger governance platforms that provide a comprehensive view of the risks related to AI. You have a market that's evolving called AI security posture management, you have governance, and so forth.
So, there is a fragmentation in that market at the moment. And indeed, Copenhagen is producing a series of reports which are aimed on that.
Now, in my personal humble opinion, complexity is the enemy of security. So, complex, disconnected sets of tools don't help.
So, I would say that we should be seeing some kind of consolidation in that market, and a lot of it will get consolidated into the CNAP. Now, so Andrea has said, in the beginning, you said that CNAP struggled to protect just-in-time resources and short-lived real-time AI agents. Do you see any trend about how to overcome this?
Well, I would say that it is the customers, it is the classic security that struggled to deal with the ephemeral nature of the cloud. And what has happened is that CNAP has become a consolidation of the kinds of tools that are needed in order to provide a different perspective in that, in the sense that they have to deal with and they have to manage these resources. And the way you manage them is by making sure that when a resource is created, it is created without vulnerabilities or with vulnerabilities that are manageable or don't matter.
And since the resources that you use in the cloud are in fact defined as data, that means that the tools have to detect the vulnerabilities in the data that defines the services, so that when they are created, the data does not create things with vulnerabilities. And that is complex.
So, that is part of the code to cloud and cloud to code that people talk about. Now, in terms of CNAP and AI adoption, well, of course, organizations are racing towards AI, because it is the hot topic of the month. And the good news is that if you already have a CNAP from one of the major vendors, then that CNAP is also racing to provide you with the tools that you need.
And so, the intersection that I see between the conventional CNAP vendors and AI security is very large. Now, that's not to say that it's complete, because there is still this boiling cauldron of different tools, which are specifically focused on AI. And many of those are highly relevant and will eventually become into the mainstream. And whether or not there will be a separate stream of what you might call AI NAP remains to be seen.
So, I've answered all the questions now. So, unless there's any more questions, I think I'll say to everyone, well, thank you so much for taking the time to join me today. Thank you. Thank you so much for your participation. And I look forward to you reading my blogs and looking at the research on our website.
See All Locations
See All Locations