As organizations accelerate digital transformation and adopt generative AI, cloud environments have become indispensable—and increasingly targeted by cyber threats. Despite the inherent resilience of cloud platforms, security failures often result from customer-side misconfigurations, not provider flaws. The rising sophistication of threat actors, combined with the scale and complexity of hybrid and multi-cloud deployments, demands a new approach to cloud security.
This webinar will explore how Cloud-Native Application Protection Platforms (CNAPPs) deliver a cohesive security architecture across the four critical pillars of cloud security.
Senior Analyst Mike Small of KuppingerCole will share expert insights on how to leverage CNAPP capabilities—aligned with the MITRE ATT&CK framework—to reduce cloud risk, enforce policy, and respond to advanced threats in real time.
Who should attend:
CISOs, cloud security architects, threat intelligence leaders, and senior decision-makers responsible for securing modern cloud environments.
Hello, good afternoon and welcome to everyone for this webinar on Cloud Security in the Age of Generative AI. My name is Mike Small and I'm a Senior Analyst in KuppingerCole and I've just joined this webinar as the presenter. I don't understand if there is an echo, but I can't hear one.
So, okay, good. So, I've recently written a leadership compass on cloud native application security and this presentation has really followed from the work that I did on that presentation. There is in fact no doubt that cloud security is one of the major concerns of all businesses because the cloud has become a fundamental enabler for businesses.
And so, when we look at cloud and its use, then we start to see that security is a big problem. So, now in terms of the overall view of this presentation, we have control over the audio. There are going to be some polls and there will be an opportunity at the end to have some questions and answers. And the slides and the recording of this will be made available for download at the end.
So, in terms of what I'm going to talk about today is in first of all the challenges that are being presented by cloud security, then how cloud native application protection platforms have evolved to meet these challenges, and finally we'll give you a summary of the Copenger Coal Leadership Compass Report, which you can find on our website. And then we will have an opportunity for some questions and answers.
So, to begin with, what I'd like to do is to ask you to respond to this poll. And the moderator will in fact start the poll in a minute. But basically, what is the biggest security challenge in your hybrid multi-cloud environment? Is it understanding the real risks as opposed to the supposed risks? Is it to do with complexity of your cloud environment? Is it about understanding how to manage the shared responsibilities for security? Is it to do with there being inconsistent tools and capabilities? Or is it a lack of transparency for controls?
So, please can you start the poll, and we'll then be able to get an answer. Okay, so at the moment, top is understanding the real risks.
So, that's a very interesting result to the first poll. Okay, so I think people have now stopped answering the poll.
So, perhaps we can move on to the next slide. So, basically, I'm now going to talk about some of the security challenges that come from the cloud. And it's very interesting because I've been researching cloud for many years. And to begin with, the concern was actually devolving your security controls to the cloud service provider. Then it became a question of compliance and would the cloud provider be compliant? And now it's become clear that the problem is neither of those. It is actually that people who use the cloud aren't actually very well equipped to manage their own security.
And the internet and the news is full of stories about problems that basically arose from customer misconfigurations and mistakes. Many of these related to a cloud database called Snowflake, where the actual cloud users, the cloud customer was able to not enable multi-factor authentication.
And thus, any cyber criminal who was able to get hold of a suitable identity was able to get in and to alter things. Then in Australia, there was a problem with a news network where an open S3 bucket, that is to say an S3 bucket in the cloud with public access and no controls contained the data belonging to thousands of Australian customers. And finally, in these examples, we have an example where attackers were able to use a compromised AWS account with permissions to read and write S3 objects. And so they were able to actually encrypt something.
Now, all of those stemmed not from a failure of the cloud service. They stemmed from a failure from the customer to implement appropriate controls. And indeed, when you look at cloud services, they all say that they have various levels of accreditation. And one of the interesting things is that part of that accreditation is to do with the provision of appropriate controls for the customer to use. And these are known as customer entity user controls. So if we then look at why cloud security is different, because people say, well, cloud is just another form of IT.
Well, cloud is dynamic. In the old days, you could say, well, we bought a server, we've installed that server, and you would make changes to it. And when you'd made a change to it, you would be able to scan it. But in the cloud, in a virtual environment, assets are created as they are needed, and only exist for as long as they are needed. And this can be very, very short periods of time. It is no good trying to scan one of those things when it has been created. You need to prevent the problems from occurring.
The second major problem is that each of the virtual services, each of the virtual elements, needs to have some kind of identity and access control so that the ones that belong to you can only be seen by you and not by anybody else. And their entitlements needs to be managed by you. So since you have thousands, if not hundreds of thousands of virtual assets in your under your control, all of those have identities. And all of those have access entitlements that you need to manage and people fail to manage these.
This also leads, this complexity leads to many, many different potential paths to risks, that it can become so complex that the average customer does not understand how someone from the internet could navigate through the various components to get to the data. Because there are multiple elements between you and the internet. And it is finding those combinations of risks that is in fact going to make the difference between whether you are secure or not. And each of these elements is also different. And this has led to a multiple number of different tools.
So finally, you have the third problem, the fourth problem, which is that each of the major cloud services provides what you need, but they provide it in a different way. So each one has its own APIs, each one has its own security tools, and they are all doing the same thing, but in a slightly different way. So it adds another layer of complexity on trying to manage things. And not only that, but it's also going to get worse, because generative AI is going to create new opportunities, because there are new technologies with new risks. And part of the problem is that we're going to use it.
And not only are we going to use it to help us to understand our customers needs and be more efficient, we're going to use it to create apps. And so the more apps that we create, the more complexity that we add into our system, and the more difficulties we have in managing all of these things. According to IBM, they reckon that there will be 1 billion new apps developed in the next five years, based on the use of AI supported development tools. And all of these are going to be based on this multi cloud with multiple technologies, and the inconsistent tools.
And so from a business point of view, you have these three major challenges. How can I comply with all the regulations that I have? How can I prevent data breaches? And how can I ensure business continuity? And that is, if you will, made even worse when you look at the technology challenges that come from AI. And this is in addition to the other things that everyone talks about, like bias, accountability, misinformation, and so forth, just simply the additional services, you're going to be using data to train these systems. And so that data may be coming from places that you don't understand.
It's how do you keep that training data confidential? How do you make sure that it doesn't leak out through the answers? And how can you make sure that it doesn't contain the answers don't contain your intellectual property? Are you actually managing the AI services? Do you have a catalog of what those services are? Are you sure that you have configured them correctly? How do you protect the DevOps pipeline? And how do you know what AI you're using? Because nearly every organization is now put their toe in the water, and probably has some shadow AI that they didn't know about.
Then you lead on to the technical risks to do with models. So unless you have some control, there's going to be a supply chain risk where developers pick out LLMs without having checked out whether they are poisoned, whether they are going to be good to give the right answers. And there are also other kinds of risks that we know about such as prompt injection.
And so you need to include in all of this, in all of your cloud management, something that I'm calling AI posture, which means you know what AI you're using, you are able to measure how well you are using it from a security point of view, that you can have good reports of those risks and compliance reports of how you are complying with the evolving structure of regulations around this. So cloud security is complex. And what has happened is over time, there has become, there is evolved a sort of notion of cloud to code and code to cloud.
And this has come about because what actually happens is that you have four major phases. First of all, a lot of cloud native applications are being developed. And when they are being developed, they contain errors, they contain misconfigurations, they contain weaknesses. And remember that in the cloud, the actual structure is in fact also code, infrastructure is code, it's data. So you then deploy that by using it to build the resources. And so you need at that point to be able to manage the risks and to try and prevent the deployment of risky resources and containers during the build phase.
Then when you actually deploy it into the cloud, you need to be sure that what you've deployed is what you actually deployed, and it's not being changed, it's not drifting, and it's not being attacked. Because one of the ways would be for the threat actors to get in and start to change things while it's actually running. And then finally, when you do run it, you need to be able to relate back any problems that you find, any threats that are there, any risks to the actual code, which you can recover and change. So it's no longer just a question of going and tweaking some piece of hardware.
Now, all of this has led to what I'm describing as cloud alphabet soup. You have all of these different kinds of tools and technologies that have been evolved, each of which has a specific purpose to help with one or more of those different areas.
Now, complexity and all of these tools represents a risk in itself. And that there was an interesting study from the IBM Institute for Business Value, which discovered that on the organizations that they actually surveyed, these organizations had 83 different security tools on the average from 29 different vendors. And that is clearly a very difficult thing to manage. And in a sense, it brings a problem from the security perspective that probably there are some cracks between these, there are some security management holes that you're not aware of. And it's also costing too much.
So this is what has led to cloud native application protection platforms. And these things are going to support the major problems. And the first of these problems is understanding this concept of shared responsibility, that you have to be absolutely clear about what is the CSP's responsibility, and what you are responsible for. And basically, you are always responsible for security of access to your service, for the security of your applications that you have and so forth, and the security of your network and storage.
And in order to ensure this, you have to implement what are described as complementary user entity controls. And that's what these things have to support. So we've divided our view of this into three major areas, which is support for identity centric security, where, if you look at this, you can see that not only for people, but also for the non human identities, you need to enforce the principle of least privilege. And that is a fundamental problem, because with the cloud, you get more and more administrative access needed.
Different departments, different, different applications, different services will have different privileged access management people. And you need to minimize this and always look for the principle of least privilege, then you should, by default, be implementing strong authentication. In order to prevent the kinds of problems that were described earlier on, you know, you need to be using more than username and password. And then to detect where in fact, there is some kind of abnormal ingress, you should be looking for abnormal behavior, as one of the ways of detecting that there are problems.
And these would almost certainly be the same kind of activity, which is leading to escalations of privilege, which is rogue accounts. So basically, identity and access management is fundamental, and provides many of the signals you need to detect that there are bad things happening. And AI can support you in that, as well as being part of the problem. The next area is to do with data. And this is what we call data centric security. You need to know what data you are holding in the cloud, and by default, denying public access.
If you look again, where most of the problems occur with the cloud, it is because by default, somebody has left a public access to a database, to a data bucket, to a file. Then the next thing is to make sure that to prevent access to unauthorized exfiltration of data, encrypt it, and make sure that you keep control of the keys. Encryption helps with data in transit and with data in storage. But you need to take a little bit more concern if you want to protect data that is being processed. And not only that, but you want to be able to share data in a confidential manner.
And there is an emerging field called confidential computing, which includes things like trusted execution environments and rather interesting forms of encryption, which can help you with that. Don't forget about data leakage prevention to help with the unnecessary and thoughtless transmission of data using things like email or copying it to risky environments. And finally, remember that in order to be able to recover this, if your cloud service goes, or if you are hit with a ransomware attack, make sure you have a secure data backup.
Now, CNAP also needs to support what we call cyber threat resilience. And this is the ability to recover from and robustly respond to attacks when they occur. And this involves not only training all your users to be extremely careful in what they do, but also making sure that you implement good network security. And there are lots of ways of implementing this and zero trust access is a very popular approach. And you could do that not only at your physical network, but also at the virtual network within your cloud.
You also need to make sure that the compute elements that you have are properly protected in terms of their access controls, because remember, they have access controls. And also the OS model and all of the software that is installed on them under your control needs to properly be configured to remove vulnerabilities and to protect.
And so this then leads you on to when you are developing software, your DevSecOps pipeline needs to be protected, you need to know what services you're running, and have built in controls at each of the stages that stop you from deploying code with vulnerabilities and risks. And that also applies to Gen AI. And to make sure that when you are running, you know when things are happening, you need some kind of detection and response. So those are the main things that you need in a cloud native application protection platform. So we have written a leadership compass on this.
And when we wrote it, we actually looked for the capabilities of products in the market to actually provide a consistent and single platform, which covered all of these things. And this interesting table here is a mapping of these various elements of security that I've been describing against the attack tactics. And one of the interesting things is that the two columns that contain the most of the crosses are cloud identity and entitlements, and cloud detection and response. So those are things that you may must make sure that you've got.
And otherwise, you need to look at a matrix, something like this, which you can find in our report, to understand how best to optimize what you're doing. When we write a leadership compass, we come up with five, four categories of leadership, a product leadership, a market leadership, an innovation leadership, and an overall leadership. And here are some of the vendors that we have profiled in this leadership compass.
And these range from very large companies like Microsoft to quite small companies with rather specialized and focused products like cloud defense, some new and focused ones like size scale, as well as the network vendors like Palo Alto and Acqua, which is focusing on development tools, IBM, which has a focus on compliance, and a very strong set of capabilities for different kinds of compliance, as well as Wiz, which is quite remarkable, having just been acquired by Google for a very large amount of money.
So, this is our view of the overall leadership, where we see we divide the vendors into leaders and challengers. And you can see that all the leaders have a good market share, they have a very good product, and a very high level of innovation. The challengers tend to be more focused on particular market areas, on particular capabilities, and also have good products within those areas. In order to help you to match products to your need, we also produce these spider charts, these radar charts.
And that radar chart has on its dimensions, the actual dimensions that I showed you in that table of mapping against the MITRE ATT&CK, so that you can look at our assessment of each of the vendors products against that to match it more carefully to your needs. And in addition, there are another set of vendors who, which either we were not able to rate, or did not have time to rate, or they did not want to be rated.
And so, there are many other vendors that have some kinds often of specialized products in this. So, something like Oracle has solutions, but it's mainly solutions for the Oracle stack, and we were looking for products that covered all of the different clouds.
So, now we're coming to the end. So, there is another poll, and it would be good if you could answer your polls for this. How would you describe your organization's current stage of access of a CNAP adoption? Have you fully adopted it, where all and most of your NAP apps are protected using CNAP? Is it partially adopted, where you've just started using it, but you've not yet covered everything? Are you still evaluating it?
You're looking into the solutions but haven't implemented all one yet, and you're not even considering it because you think that there is something better that or something else that you can do instead. So, please let me know what your poll is.
So, that's interesting. At the moment, most people are still evaluating, and some people are in partial adoption, and something like 15% are fully adopted, which is very interesting. Okay.
So, I believe that if we give you some time to all respond to that, then we can move on to the questions and answers. Okay. Thank you.
So, questions and answers. So, are there any questions? And if there are, please raise your hand. Yes. Okay.
So, the first question is, how is the CNAP market evolving? Well, our evidence is that it is growing very strongly. It is already in many billions of dollars worth of the current market, and it's growing at something like 20%. And it's growing towards unified platforms to help organizations to avoid the need for multiple point tools.
And it is also going to have, it is also evolving to take account of the changing nature of the way in which people are using the cloud, both from the point of view of new technologies, like AI adoption, and the move of the use of the cloud into more, for more regulated industries, which demand to have high levels of compliance and high levels of security. Then, how is AI changing the landscape?
Well, so that's an interesting question, because as I said at the beginning, AI technologies are mainly being delivered through cloud. And like all new and evolving technologies, organizations don't know that they are using them.
And so, we're starting to see concern about the deployment of shadow AI. So, what you can see is we're getting the tools that we already have for other uses of the cloud, are each evolving towards inclusion of the AI services, of recognizing the ways in which data are being used by AI, and recognizing the technology and infrastructure risks that come from the use of AI. And that is, if you will, distinct from the kinds of tools that are there to help you to comply in the way that you are ethically using it, but that will be coming.
And then, how mature are the AI capabilities for CNAP already? Well, the answer to that is it depends. And if you read the report, you will see that some of the vendor solutions have nothing special.
Now, that's not to say that they don't contain it, but they don't have, if you will, the pre-canned recipes. You can say, well, if I can control who can access a service, then that could apply to AI services. But if we take it a stage further, where you can actually say we've got a pre-canned recipe, which says we know who has access to, shall we say, upload data and all this kind of thing, that is what we're looking for.
So, some vendors, some of the bigger vendors have already gone down that path, and they are looking at how data is being used for AI, how that data is being protected against use, how the services, access to the services are controlled, how the development cycle for AI is being controlled. So, the answer is that it depends on the different vendors, and in the report, you can see our opinion of each vendor with respect to that.
So, with that, I don't see any further questions. Ah, right. How do I see CTEM or anything else as a strong complement to CNAP?
Well, to some extent, if you look at the cloud security posture management, which is somehow or other mixed up with CTEM, which is sometime with XDR, and is mixed up with the other forms, the XDR, that the cloud has a threat surface, and it is an extended threat surface, and being able to understand all of that threat surface is important.
The other interesting thing is to do with the connection between all of that and cloud risk quantification tools, because what is happening is that all of these risks, and there are many, are becoming so arcane and so many that it is becoming very difficult for organizations to where to apply their limited budgets.
And so, one of the things that I think we're seeing is the demand from boards of directors for having some kind of understandable way of recognizing how much risk they have in terms that they understand, which is usually money, and where best to invest their limited budgets in order to arrive at a solution which meets the appetite for threats that they're willing to accept. So, that's an excellent question, Geoffrey. Thank you very much for it.
Okay, well, if there's no further questions, what I would like to do is to say thank you very much to everyone for joining this presentation this afternoon. And as I said earlier on, you will be able to get a recording and download the slides and please go on to the Copenhagen Coal website, have a look at the report, and I would be very interested in any feedback that you have. You can connect to me via LinkedIn and via the Copenhagen Coal website. Thank you very much, everyone. Thank you.
See All Locations
See All Locations