Aqua Security today said it bought cloud security posture management company CloudSploit for an undisclosed amount. It’s the second acquisition for the container and serverless security vendor, and moves Aqua into cloud security posture management.
“We wanted to get into this adjacent space,” said Rani Osnat, VP of strategy at Aqua Security. “We see a consolidation in the market, and we see customers wanting to get more out of the vendors they work with.” And, Osnat added, cloud security posture management looked like a smart move for Aqua, which started in 2015 as a container security vendor before expanding its platform to also support virtual machines and serverless. “We felt giving customers what they need around security and compliance with their cloud posture — basically how well their accounts are configured, and how can they improve compliance — was a good fit for us.”
CloudSploit and CSPMCloud security posture management (CSPM) is a newer Gartner term, and as the name implies it addresses the management of cloud security — processes and tools to avoid cloud misconfigurations that can lead to data leakage. Gartner recommends all cloud security vendors invest in CSPM. The most recent Cloud Security Alliance’s threats reports ranks data breaches and cloud misconfigurations as the No. 1 and No. 2 cloud security threats, respectively, and as such these tools are becoming increasingly top of mind for chief information security officers as well.
CloudSploit’s software-as-a-service- (SaaS) based platform provides visibility across customers’ cloud resource estates. It automatically manages cloud security risk and benchmarks against industry standards.
Aqua finalized the CloudSploit acquisition a couple months ago, “but we wanted time to integrate, and we plan to make this even more integrated next year,” Osnat said. “Right now it’s still a SaaS solution distinct from our container and serverless platform, but ultimately it will be one solution.”
CloudSploit started as an open source project, and the deal continues Aqua’s investment in open source, Osnat said. “We expanded our open source team even before the acquisition so that we now have seven people dedicated just to doing open source,” he said. Additionally, in August Aqua acquired Trivy Vulnerability Scanner and it remains open source.
Market ConsolidationAqua’s CloudSploit acquisition follows a $62 million in a Series C funding round that brought Aqua’s total raised to more than $100 million.
About a month after the funding round, Palo Alto Networks bought Aqua’s chief container security rival, Twistlock, for $410 million, along with a serverless security startup, PureSec. And last year Palo Alto Networks bought a couple of CSPM vendors: Evident.io and RedLock.
“We need to provide these solutions to our customers so that rather than go to a different vendor for that, we can provide this capability and we can do it well with CloudSploit,” Osnat said. But, he added, Aqua wants to do more than simply add CSPN to its portfolio.
“The other area we want to pursue is really exploring those security synergies between CSPN and workload protection,” Osnat said. "It would be really cool if you could understand not just when an attack actually happens in your container infrastructure, but also if you could trace that back to which cloud account it came from, which cloud service was used to get there, and vice versa. Having another layer of security is always useful but if you can create that tracking capabilities between them, that’s even better.”
Comments