Forrester’s latest Wave report on cloud workload security for Q1 2024 sheds light on market consolidations and emerging trends that are reshaping how companies secure their cloud environments. The firm also identified Palo Alto Networks and CrowdStrike as leaders in this market.
The analyst firm noted the cloud workload security market has been witnessing a notable consolidation, as major players are expanding their functionalities to include cloud infrastructure entitlement management (CIEM) and data protection for prominent cloud infrastructure platforms such as Amazon Web Services (AWS), Microsoft Azure and Google Cloud Platform (GCP). There’s also increasing productized support for Oracle Cloud Infrastructure and Alibaba cloud platforms, especially in cloud security posture management (CSPM) functionalities.
Key recommendations for users
Based on trends in the market, Forrester's report highlights cloud workload security customers should look for products that include the following:
- Configuration and activity-based CIEM capabilities to manage complex identities and data access in cloud platforms. This involves tracking low-privilege cloud admin identities with potential high-privilege access. Meanwhile, risk indicators are not limited to static configuration of clouds, but also include cloud configuration and admin access to sensitive data.
- Container runtime and orchestrator protection. Container orchestrators should maintain the least-privilege access rights. Container admins should enforce multifactor authentication (MFA) for all environments. Security teams should also employ reliable methods for secret management and pre-runtime vulnerability prevention and remediation in containers.
- Trend reporting in cloud security exposure, remediation, and compliance. Improve how security teams present information to auditors, DevOps, IT security and executive stakeholders. Forrester also anticipates the growth of generative artificial intelligence (AI) (genAI) and large language models in cloud workload security tools to enhance query responses and create context-aware remediation scripts.
Leaders in the cloud workload security space
Forrester’s report noted that CrowdStrike stands out for its agentless cloud workload protection (CWP) and container runtime protection.
From an agent-based behavioral malware detection background, the security vendor expanded into CSPM and infrastructure as code (IaC) scanning. While it shows a strong CWS vision and innovation potential, its CWS roadmap lags behind competitors, which includes integrating its Bionic acquisition for Application security posture management (ASPM), moving asset discovery to real-time event-based monitoring and extending CWP across all cloud workloads, the firm noted.
Forrester added that CrowdStrike provides strong agent-based CWP for Linux and Windows and container runtime protection and IaC scanning, but it falls behind in CIEM and the number of workloads protected by its agentless CWP.
As the other leader in the report, Palo Alto Networks provides a comprehensive CSPM solution, combining organically developed CWP components and acquired CSPM functionalities from Bridgecrew. The company shows a very strong CWS roadmap, including integrating AI into Prisma Cloud Copilot, unifying extended detection and response (XDR) /CWP into a single cloud security agent, and addressing open-source vulnerabilities.
However, Palo Alto Networks’ agent-based and agentless CWP capabilities are average compared to others, while its CIEM capabilities and the largest number of workloads protected by the vendor’s agentless CWP are behind.
Forrester also identified strong performers including Microsoft, Wiz, Check Point, Trend Micro, Orca Security, Aqua Security; and contenders such as Sysdig, Tenable, Rapid7, Qualys and Lacework. Notably, there were no challengers in this segment.
Comments