Select a theme from the list.
Insights

From our experts

Latest
Slim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesUnpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemPasskey Reset Scams Turn Strong Authentication Into Cloud PersistenceFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformSlim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesUnpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemPasskey Reset Scams Turn Strong Authentication Into Cloud PersistenceFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development Platform
Security Insight

Microsoft's CNAPP Recognition Highlights the Shift Toward Unified Cloud and AI Security

Microsoft's CNAPP Recognition Highlights the Shift Toward Unified Cloud and AI Security
Photo by Ryutaro Tsukata on Pexels

Microsoft says KuppingerCole has named it a leader across all four categories in its latest Cloud Native Application Protection Platform assessment. The announcement reflects a broader change in cloud security, with enterprises seeking unified visibility across infrastructure, workloads, identities, data, applications and AI systems.

News Date: 2026-08-05

Microsoft has been named a leader in KuppingerCole's latest assessment of Cloud Native Application Protection Platforms, receiving recognition in the Overall, Product, Innovation and Market categories. Although vendor rankings should always be considered alongside independent testing and customer requirements, the announcement illustrates how quickly the CNAPP market is expanding beyond conventional cloud posture management.

Cloud Security Meets the AI Workload

Modern enterprise applications are assembled from containers, serverless functions, Kubernetes clusters, application programming interfaces, identities, databases and software pipelines. AI introduces another layer containing models, agents, machine identities, data connectors and automated actions. A security weakness in one component may appear minor until it is combined with excessive permissions or exposed information elsewhere.

Microsoft's position is that organizations need a shared control plane capable of correlating these signals. Defender for Cloud brings together posture assessment, workload protection, attack-path analysis, runtime intelligence and cloud detection and response. The platform is also being extended to examine the configuration and exposure of AI systems.

This reflects an important change in security operations. Teams no longer need another console producing thousands of isolated findings. They need evidence explaining which weaknesses are reachable, whether they are being exploited and what remediation will break the most dangerous attack path.

Questions Enterprises Should Ask

  • Does the platform provide consistent coverage across every cloud provider in use?
  • Can it connect identity permissions with workload and data exposure?
  • Does runtime evidence improve prioritization or merely generate more alerts?
  • Can findings be assigned directly to application owners and development teams?
  • Are AI agents, models and machine identities included in the same governance framework?

In my view, CNAPP consolidation can reduce operational friction, but it also introduces platform concentration. Organizations should avoid assuming that one vendor will provide equal depth across every cloud, workload and development environment. A structured pilot using real applications, red-team scenarios and measurable remediation workflows is more valuable than relying exclusively on an analyst ranking.

I believe the strongest CNAPP strategy will combine broad platform visibility with specialist controls where the business faces unusual risks. The objective is not to eliminate every security product. It is to build a coherent risk model that follows an application from source code to cloud deployment and, increasingly, through the decisions made by its AI agents.

Talk to our team →

Latest

Slim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesSep 10, 2026Unpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemSep 10, 2026Passkey Reset Scams Turn Strong Authentication Into Cloud PersistenceSep 10, 2026Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026

Most read

1Microsoft Redraws the Security Boundary for Edge AI2Ted Implant Turns Compromised HAProxy Servers Into Invisible Interception Points3IDScan Lawsuits Put Mass Identity Collection Under the Microscope4French Hospital Fine Turns Weak Identity Controls Into a GDPR Warning5Microsoft Prepares Windows Customers for a Faster Era of AI-Driven Patching6Scattered Spider's Cyberattack on Marks & Spencer Exposes Retail Vulnerabilities