Spotlight

Report:

The Forrester Wave™: Infrastructure-As-A-Service Platform Native Security, Q2 2023

How does Forrester define the Infrastructure-As-A-Service Platform Native Security market in 2023?

IPNS (Infrastructure-as-a-Service Platform Native Security) is the foundational building block that cloud infrastructure providers utilize to secure cloud workloads, storage, and networks. The market is experiencing significant change as customers increasingly use multiple cloud infrastructure providers and seek to minimize administrative overhead and security threat surface by using a single set of IPNS services. Key differentiators include: agent-based and agentless guest OS security for cloud workload protection, multicloud security covering both native and third-party platforms (including CSPM and storage security), and comprehensive network security capacity across native next-gen firewalls, WAFs, and DDoS protection.

Key Facts for The Forrester Wave™: Infrastructure-As-A-Service Platform Native Security, Q2 2023 in 2023

How did the Infrastructure-As-A-Service Platform Native Security market evolve in 2023?

What product features are required to be included in this year's evaluation?

What are the common features of top products in the Infrastructure-As-A-Service Platform Native Security space?

No common features specified.

Scope Exclusions

Inclusion Criteria

Vendors must, among other requirements:

Offering Strengths — Relative Weighting

Strategy Strength — Relative Weighting

FAQs

Q: What does this research cover?

A: This research evaluates eight major infrastructure-as-a-service platform native security (IPNS) providers across 22 criteria grouped into three categories: current offering (50% weight), strategy (50% weight), and market presence. The evaluation covers compute, storage, and network security capabilities including administrative IAM, CSPM/CIEM, hypervisor security, guest OS security, container security, storage and data security, network security, multicloud support, and scale.

Q: Who should use this research?

A: Security and risk (S&R) professionals should use this research to select the right IPNS provider for their needs. The report helps organizations understand vendor positioning, strengths, and weaknesses across security capabilities. It provides guidance for organizations seeking multicloud security support, agentless workload protection, and comprehensive network security. The accompanying Excel tool allows buyers to customize criteria weightings based on their specific requirements.

Q: What are the mandatory features of vendors included in this market?

A: Vendors must have: 1) A complete IPNS offering and strategy covering compute, storage, and network security with regular updates and improvements, 2) Native, purpose-built security features confirmed by customer reports, 3) At least US$75 million in combined annual IPNS revenues, and 4) Significant market presence demonstrated by frequent mentions in Forrester end-user client inquiries, vendor selection RFPs, shortlists, consulting projects, and case studies.

Q: What are some reasons for not being included in this report?

A:

  • IPNS annual revenues below the US$75 million threshold
  • Incomplete IPNS offering lacking compute, storage, or network security components
  • Lack of demonstrated thought leadership and solution strategy execution
  • Insufficient product portfolio updates and improvements
  • Solutions lacking native, purpose-built security features
  • Limited mindshare with Forrester end-user organizations
  • Infrequent mentions in client inquiries, RFPs, and consulting projects
  • Not recognized as viable competitors by other vendors in the space

Q: What should buyers consider when evaluating products in this market?

A:

  • Agent-based and agentless guest OS security capabilities for cloud workload protection
  • Breadth and depth of operating systems covered by security features
  • Multicloud security support covering both native platform and other cloud providers
  • Coverage of guest OS, container runtimes, and orchestration
  • CSPM and storage security capabilities (encryption key management) for multiple cloud platforms
  • Network security capacity including native next-gen firewalls, WAFs, and DDoS protection
  • Understanding of virtual network constructs (VPCs, VLANs)
  • Policy configurability for DDoS protections
  • Ability to minimize administrative overhead across multiple cloud platforms

Q: How has the Infrastructure-As-A-Service Platform Native Security market evolved in 2023?

A:

  • Customers increasingly using multiple cloud infrastructure providers
  • Demand for minimizing administrative overhead and security threat surface through unified IPNS services
  • Growing importance of agentless workload protection methods (still nascent but evolving)
  • Expansion of multicloud security beyond native platforms to cover others' policies and workloads
  • Rising need for CSPM (cloud security posture management) across multiple cloud platforms
  • Increased focus on container runtime and orchestration security
  • Need for robust network security defenses (WAFs, next-gen firewalls, DDoS protection) as workloads are on public internet by default

Q: What differentiates Strength of Offering vs. Strength of Strategy?

A: Current Offering (vertical axis) evaluates the strength of a vendor's existing IPNS capabilities across technical areas including data centers, security certifications, IAM, CSPM/CIEM, hypervisor security, guest OS security, container security, storage/data security, network security, multicloud support, and scale. Strategy (horizontal axis) assesses the vendor's future direction and execution capability through vision, roadmap, market approach, planned enhancements, innovation, supporting products/services, partner ecosystem, delivery model, and commercial model. Offering focuses on 'what exists today' while Strategy focuses on 'where the vendor is heading and how they'll get there'.

Reference

View Leaders
View Vendor Movements