Spotlight

Report:

The Forrester Wave™: Cloud Workload Security, Q1 2024

How does Forrester define the Cloud Workload Security market in 2024?

The CWS market has rapidly consolidated with large suite providers augmenting functionality with CIEM and data protection capabilities for cloud platforms (AWS, Azure, GCP). Vendors are increasingly adding support for Oracle Cloud Infrastructure and Alibaba cloud platforms, particularly for CSPM functionality. Infrastructure as code (IaC) scanning is gaining adoption to ensure foundational security of cloud and container environment build scripts. CSPM capabilities for mapping configuration rules to compliance templates are becoming less differentiated. Organizations should prioritize providers offering configuration and activity-based CIEM capabilities, container runtime and orchestrator protections, and comprehensive reporting on cloud security exposure, remediation, and compliance trends.

Key Facts for The Forrester Wave™: Cloud Workload Security, Q1 2024 in 2024

How did the Cloud Workload Security market evolve in 2024?

What product features are required to be included in this year's evaluation?

What are the common features of top products in the Cloud Workload Security space?

No common features specified.

Scope Exclusions

Inclusion Criteria

Vendors must, among other requirements:

Offering Strengths — Relative Weighting

Strategy Strength — Relative Weighting

FAQs

Q: What does this research cover?

A: This research covers the cloud workload security (CWS) market, evaluating 13 major providers across 21 criteria. It assesses vendors' current offerings including CSPM, CIEM, cloud workload protection (agent-based and agentless), container security, IaC scanning, detection and response capabilities, as well as their strategies, market presence, and innovation potential. The evaluation focuses on how vendors address the consolidating CWS market with emphasis on configuration and identity-based security, container runtime protection, and compliance reporting.

Q: Who should use this research?

A: This research should be used by security and risk (S&R) professionals who need to select the right cloud workload security provider for their organization's needs. It helps buyers evaluate CWS vendors based on their specific requirements, understand vendor strengths and weaknesses across different capabilities, and make informed purchasing decisions. The downloadable Excel-based vendor comparison tool allows users to customize criteria weightings to match their unique priorities and environment characteristics.

Q: What are the mandatory features of vendors included in this market?

A: Vendors included in this evaluation must have: 1) A thought-leading, productized CWS portfolio with regular updates covering cloud security posture management (CSPM), cloud workload protection for both OS and containers, and infrastructure as code (IaC) scanning; 2) At least $15 million in annual CWS revenues; 3) Strong mindshare with Forrester's end-user customers evidenced by frequent mentions in client inquiries, RFPs, shortlists, and consulting projects; and 4) Recognition from other CWS vendors as viable and formidable competitors in the market.

Q: What are some reasons for not being included in this report?

A:

  • Annual CWS revenues below the $15 million threshold
  • Incomplete CWS product portfolio lacking CSPM, CWP (OS and container), or IaC scanning components
  • Insufficient productization with offerings still in beta or lacking integrated functionality
  • Limited mindshare with Forrester's end-user customer base
  • Lack of recognition from competitor vendors as a significant market player
  • Point solutions focusing only on one aspect of CWS rather than a comprehensive platform
  • Vendor declined to participate in the evaluation process
  • Vendor provided only partial information during the evaluation period

Q: What should buyers consider when evaluating products in this market?

A:

  • Evaluate providers offering both configuration and activity-based CIEM capabilities to detect transitive access and manage identity risks across cloud environments
  • Assess container runtime and orchestrator protection capabilities, including secrets management, vulnerability remediation, and IaC scanning integration
  • Examine reporting capabilities for trends in cloud security exposure, remediation progress, and compliance status with presentation-ready outputs for different stakeholder audiences
  • Consider deployment flexibility with both agent-based and agentless CWP options to accommodate different workload types and organizational constraints
  • Review support for multiple cloud platforms including AWS, Azure, GCP, and increasingly Oracle Cloud Infrastructure and Alibaba Cloud
  • Assess the vendor's roadmap for AI/ML integration, particularly for query formulation and automated remediation capabilities
  • Evaluate integration with CI/CD pipelines and developer workflows for shift-left security
  • Consider the maturity of compliance template mapping and the breadth of regulatory framework coverage

Q: How has the Cloud Workload Security market evolved in 2024?

A:

  • Rapid market consolidation with large CWS suite providers augmenting functionality with CIEM and data protection capabilities
  • Increasing productized support for Oracle Cloud Infrastructure and Alibaba cloud platforms, especially for CSPM functionality
  • Growing adoption of Infrastructure as Code (IaC) scanning to ensure foundational security of cloud and container environment build scripts
  • CSPM capabilities for mapping configuration rules to compliance templates becoming less differentiated
  • Need for configuration and activity-based CIEM capabilities to track transitive access and identity risks
  • Container technology creating 'cloud on top of cloud' complexity requiring specialized runtime and orchestrator protections
  • Improved reporting trends for compliance, remediation, and security exposure with presentation-ready outputs for executives
  • Proliferation of generative AI and large language models for query formulation and dynamic remediation script generation

Q: What differentiates Strength of Offering vs. Strength of Strategy?

A: Current Offering evaluates the strength of a vendor's existing product capabilities across technical features like admin IAM, CSPM, CIEM, agent-based/agentless CWP, container protection, IaC scanning, detection/response, reporting, and scale. Strategy evaluates the vendor's future direction and business positioning through vision, roadmap, community engagement, innovation potential, partner ecosystem, customer adoption acceleration, and pricing approach. Offering focuses on 'what the product does today' while Strategy focuses on 'where the vendor is heading and how they execute.'

Reference

View Leaders
View Vendor Movements