Although a relatively new class of technology, cloud security posture management (CSPM) brings a welcomed source of confidence in public cloud migrations by targeting two increasingly important business concerns: cloud security and data compliance.
CSPM companies provide security processes and tools to prevent and fix cloud misconfigurations. This is important because exposures and data breaches due to misconfigurations are the leading cause of breaches and compliance violations in cloud applications — the Capital One data breach is one recent example. In fact, the most recent Cloud Security Alliance’s threat reports ranks data breaches and cloud misconfigurations as the No. 1 and No. 2 cloud security threats, respectively.
Considering the vast majority of successful attacks on cloud services are the result of customer misconfiguration, Gartner recommends all cloud security vendors invest in CSPM, and forecasts “through 2024, organizations implementing a CSPM offering and extending this into development will reduce cloud-related security incidents due to misconfiguration by 80%.”
CSPM “is only becoming more important,” said Gartner analyst Neil MacDonald in an earlier interview with SDxCentral. “It allows organizations to identify where they have known or unacceptable risk in their cloud configurations, and there’s been multiple acquisitions in this space.”
Because humans are prone to making mistakes, errors are unfortunately inevitable. This in turn has made CSPMs a hot mergers and acquisitions target for larger security vendors. These are the top 5 CSPM deals that are changing the cloud security landscape.
Zscaler Buys CloudneetiIn April, San Jose-based Zscaler acquired Cloudneeti for an undisclosed amount in a deal that added CSPM to its platform.
Cloudneeti’s technology collects actual configurations from cloud service providers, compares them against cloud security best practices, and then analyzes risks and fixes misconfigurations. It works across software-as-a-service (SaaS), infrastructure-as-a-service (IaaS), and platform-as-a-service (PaaS) providers including Amazon Web Services (AWS), Microsoft Azure (Azure), Google Cloud Platform, and Microsoft’s Office 365.
Zscaler has been steadily building out its cloud security platform over the past few years. The vendor started as a secure web gateway provider before adding next-generation firewall and zero-trust network access. Last year, it added out-of-band cloud access security broker (CASB) capabilities to its platform to provide visibility and enable data protection for SaaS applications.
Orca Security LaunchesOrca Security, a startup founded last year by Check Point executives, in May scored a $20 million Series A funding round to expand the reach of its multicloud visibility software.
The security startup essentially combines CSPM and cloud workload protection platform (CWPP) capabilities into one platform. In building its platform, Orca set out to provide deep visibility and analysis across multicloud environments but without complexity and a lengthy time to deploy.
The company began selling its cloud security platform last August, and it supports AWS, Azure, and Google Cloud.
Aqua Acquires CloudSpolitAqua Security purchased CSPM company CloudSploit last November for an undisclosed amount. The CloudSploit acquisition marked Aqua’s second acquisition and pushed the container and serverless security vendor into the CSPM market.
CloudSploit’s SaaS based platform provides visibility across customers’ cloud resource estates. It automatically manages cloud security risk and benchmarks against industry standards. CloudSploit started as an open source project, and the deal continues Aqua’s investment in open source.
More recently, Aqua announced updates to its CSPM platform in April that included the assets it gained from the CloudSpolit acquisition that closed last year.
Aqua changed the name of the SaaS platform to Aqua CSPM, and it features preview versions of Aqua Dynamic Threat Analysis, which protects containerized applications from image-based malware by automatically running images in a secure sandboxed environment, and integrated container image vulnerability scanning using Aqua’s Trivy open source scanner.
Sophos Snags Avid SecureSophos, a network and endpoint security vendor, bought Avid Secure, an artificial intelligence (AI)-based CSPM platform provider, for an undisclosed amount in January 2019 as a move to boost its cloud security offerings.
Founded in 2017, Avid Secure provides analytics and automates governance, risk, and compliance across AWS, Azure, and GCP. Sophos gained Avid Secure customers include Shutterfly, IDT Corporation, Belong.co, and Aspiring Minds in the purchase.
“With the cloud workload protection and the cloud security posture management software from Avid Secure, Sophos will expand its current capabilities in cloud security and drive leadership in this growing space,” said Dan Schiappa, senior vice president and general manager of products at Sophos, in a statement.
Trend Micro Bags Cloud ConformityCloud workload protection vendor Trend Micro dropped $70 million on Cloud Conformity late last year to address misconfigurations and unprotected user accounts in the public cloud. The CSPM acquisition was Trend Micro’s first since November 2017 when it bought web application vendor Immunio.
Cloud Conformity is a 50-person CSPM startup that was founded in Australia in 2016 to provide businesses with a platform to maintain security, governance, and compliance in the public cloud. Its technology monitors activity in AWS and Azure Cloud, and alerts users of potential issues.
Doug Cahill, senior analyst and practice director, cybersecurity for ESG in a video called “the convergence of these two products natural” due to the “highly complementary nature of cloud security posture management products and cloud workload protection platforms … It makes perfect sense: one solution to secure both cloud services and cloud containers and workflows.”
Comments