Zscaler revealed its cloud-native application protection platforms (CNAPP) platform, dubbed Posture Control, during its Zenith Live conference. It is designed to help DevOps and security teams collaborate more efficiently to prioritize and remediate risks in cloud-native applications earlier in the development lifecycle. 

Gartner recently coined CNAPP, and the whole cloud security sector has quickly rallied around this name and product category. Zscaler is the latest security vendor to dive into this market.

CNAPP products secure cloud-native, microservices-based architectures including containers, Kubernetes, and serverless. It also helps organizations adopt a DevSecOps approach to security by helping them identify vulnerabilities and misconfigurations early in the development process.

Gartner defines CNAPPs to consolidate a large number of previously siloed capabilities including runtime cloud workload protection platform (CWPP), cloud security posture management (CSPM), cloud infrastructure entitlements management (CIEM), development artifact scanning, and infrastructure-as-code (IaC) scanning.

Zscaler delivers all those CNAPP capabilities natively based on technologies from its recent acquisitions and organic developments over the last couple of years, Rich Campagna, SVP of cloud protection at Zscaler, told SDxCentral.

The vendor acquired Cloudneeti in 2020 to add cloud security posture management (CSPM) to its platform, which provides security processes and tools to prevent and fix cloud misconfigurations. 

Then it gained CIEM capabilities through the Trustdome deal last April, which provides governance over who and what has access to data, applications, and services in public cloud environments.

For CWPP, Zscaler expanded its Private Access and Internet Access protection capabilities to the public cloud workloads. And it natively developed the cloud asset scanning and IaC scanning, according to Campagna.

The Posture Control also includes a risk correlation and prioritization engine, which Campagna argues is “what Gartner doesn't really explicitly mention in their definition of CNAPP … [but] one of the most powerful capabilities of the platform.”

The engine pieces together the context across the user's environment to identify relationships across weaknesses and drive risk prioritization, which can improve the InfoSec team's efficiency to secure their public clouds, he explained. 

Zscaler’s Later Entrant Advantages 

CNAPP is still a nascent market, and Gartner named 17 vendors as representative providers, including Aqua Security, Lacework, Palo Alto Networks, Snyk, and Trend Micro.

Palo Alto Networks introduced its CNAPP products and added some of its missing capabilities with Prisma Cloud 3.0 during last year’s Ignite conference.

As a relatively later entrant, Zscaler has several advantages over the first movers, Campagna said. “The needs in the market are much more well defined” and the vendor learned more about how users wish to operationalize CNAPP products based on the conversations with both its own and competitors' customers to inform their product directions.

And Zscaler’s distinctions are among the risk correlation and prioritization engine, platform integration internally, and also with its other existing cloud security capabilities and the Zero Trust Exchange platform, Campagna touted.

A CNAPP platform is not “a set of separate, siloed functionalities inside a platform under the same UI,” he added. That’s why Zscaler built it from scratch and integrated the data and policy model into it.

Plus, Posture Control leverages the Zscaler Zero Trust Exchange platform to build a zero-trust strategy to control communications and protect users’ hybrid cloud assets or workloads, Campagna stated.

“Our long-term differentiation in the CNAPP space is around tying into not only building a market-leading CNAPP platform but leveraging the capabilities over the cloud that thousands of organizations already trust to strengthen that platform further,” he said.