Multi-Cloud Complexity Driving Use of Cloud Native Application Protection Platforms
August 28, 2023

The Cloud Native Application Protection Platform (CNAPP) has emerged as a critical category of security tooling in recent years. According to the CNAPP Survey Report, commissioned by Microsoft, CNAPP's popularity has been driven by the complexity of comprehensively securing multi-cloud environments and their ability to consolidate the capabilities of the numerous security tools organizations current deploy, namely Cloud Security Posture Management (CSPM), Cloud Workload Protection (CWP), and Cloud Infrastructure Entitlement Management (CIEM), network security, and secure DevOps.

"When considering the challenges facing today's businesses, people and technology take center stage. On one hand, companies need to bolster the workforce with well-trained security professionals who understand their roles and responsibilities. On the other hand, there's a pressing need for effective technology and tooling that both addresses the rapidly evolving landscape of cybersecurity threats while effectively supporting security teams," said Hillary Baron, lead author and Senior Technical Director for Research, Cloud Security Alliance. "It's clear that today's multi-cloud environments are increasingly complex, and enterprises must find ways to comprehensively address their security posture."

"Many traditional security solutions still in use today just aren't capable of adequately protecting increasingly dynamic and distributed multi-cloud strategies. As organizations navigate their path in the cloud, it's imperative that they leverage solutions that offer an integrated approach to security. In doing so, they can better prepare themselves to handle the complex cybersecurity challenges of today and the future," said Adwait Joshi, Director of Cloud Security product marketing at Microsoft.

Among the survey's key findings:

Cloud Native Application Protection Platform

Three out of four organizations are opting to use CNAPP to protect their multi-cloud environment. A majority of organizations (75%) have either implemented or plan to implement CNAPPs in their cloud environments. One of the driving factors behind this move is the prevalence of multi-cloud strategies — 84% of organizations reported that they utilize two or more cloud environments.

Cloud Security Posture Management

Security teams are demanding clear-cut information for proper prioritization. A flood of security alerts has made it difficult for security teams to manage and prioritize security enhancements. 32% of respondents disclosed that they're struggling with prioritizing security improvements due to the overwhelming—and often incorrect—information they receive. Moreover, 34% find themselves buried under security recommendations, while an equivalent percentage lacks contextual or actionable insights to make informed decisions.

DevOps Security

Despite growing recognition the importance of DevOps security, expertise and talent shortages are hindering progress. Despite the trend toward shift-left security and DevSecOps, the incorporation of robust security measures within DevOps is still in its early stages, with significant obstacles hindering full integration. Currently, 51% of organizations are in the process of integrating security into their DevOps practices, with only 35% reporting complete integration. The primary challenges include lack of security expertise (46%), insufficient automation (43%), an excessive number of false positives (42%), and lack of actionable feedback (42%).

Cloud Workload Protection

Challenges around incident response come back to people, process, and technology. The lack of manpower was identified as a significant challenge by 25% of respondents; an absence of formal response plans was reported by 29% of organizations; and 39% reported the lack of automation as a key challenge.

Network Security

The most mature implementation, yet threat detection remains a challenge. Network security, out of all the categories, was the most mature. 43% of respondents reported full integration in a multi-cloud environment for network security, compared to just 28% CSPM. While the growing popularity of zero-trust strategies may be a key driver behind this level, organizations are still facing key challenges in network security, particularly concerning threat detection and the management of a large volume of security alerts.

Cloud Infrastructure Entitlement Management

Just under half (43%) of organizations identified misconfigurations of permissions as their top concern. This prevalent issue can have serious repercussions, potentially leading to unauthorized access and even catastrophic data loss. Misconfigurations can inadvertently expose sensitive data or grant unnecessary privileges, creating openings that could be exploited by malicious actors

Methodology: The survey, conducted in April 2023, gathered more than 1,200 responses from IT and security professionals from various organization sizes, industries, locations, and roles. Sponsors are CSA Corporate Members who support the research project's findings but have no added influence on the content development or editing rights of CSA research.

Share this

Industry News

November 18, 2024

MacStadium announced the launch of Orka Engine, the latest addition to its Orka product line.

November 18, 2024

Elastic announced its AI ecosystem to help enterprise developers accelerate building and deploying their Retrieval Augmented Generation (RAG) applications.

Read the full news on APMdigest

November 18, 2024

Red Hat introduced new capabilities and enhancements for Red Hat OpenShift, a hybrid cloud application platform powered by Kubernetes, as well as the technology preview of Red Hat OpenShift Lightspeed.

November 18, 2024

Traefik Labs announced API Sandbox as a Service to streamline and accelerate mock API development, and Traefik Proxy v3.2.

November 18, 2024

Kubiya announced Captain Kubernetes, an AI-powered teammate designed to simplify Kubernetes management with natural language interaction and autonomous, self-healing capabilities.

November 14, 2024

Solo.io is donating its open source API Gateway, Gloo Gateway, to the Cloud Native Computing Foundation (CNCF) to further its mission of building a complete omni-gateway connectivity solution.

November 14, 2024

LaunchDarkly announced a new approach to software delivery—Guarded Releases—that empowers organizations to ship with confidence and manage risk proactively.

November 14, 2024

Diagrid announced details of the upcoming release of Dapr 1.15, a Cloud Native Computing Foundation project maintained by Diagrid, Microsoft, Intel, Alibaba, and others.

November 14, 2024

Fermyon™ Technologies announced the release of Spin 3.0, enabling enterprises to quickly move toward more sophisticated production applications based on WebAssembly (Wasm).

November 13, 2024

Mirantis announced Mirantis Kubernetes Engine (MKE) 4, the latest evolution in its long-established product line that sets the standard for secure enterprise Kubernetes.

November 13, 2024

Cequence Security announced the launch of its new API Security Assessment Services.

November 13, 2024

Pulumi announced improvements including major updates to the EKS provider supporting Amazon Linux 2023 and Security Groups for pods, the release of Pulumi Kubernetes Operator 2.0 with dedicated workspace pods, Pulumi ESC integration with External Secrets Operator, and a new Kubernetes-native deployment agent for enhanced security and scalability.

November 13, 2024

Loft Labs announced the public beta of vCluster Cloud, a managed solution that simplifies and reduces the costs of Kubernetes clusters.

November 13, 2024

DevZero announced DXI (Developer Experience Index), an initiative aimed at transforming developer productivity by unifying engineering throughput and operational metrics.

November 13, 2024

Horizon3.ai announced the release of NodeZero™ Kubernetes Pentesting, a new capability available to all NodeZero users.