Cloud Security Posture Management (CSPM) Tools
Compare the best CSPM tools for cloud security posture management. Detect misconfigurations, enforce compliance, and secure your cloud infrastructure.
Acquired by Google. Wiz is the leader in having an all-in-one cloud security platform by expanding into CTEM, ASPM, and Runtime capabilities all within a single dashboard. Their posture and vulnerability capabilities remain the strongest, but their Code and Defend offerings are competitive in their own right.
Aikido provides everything the average startup to mid-market company needs for security in a box - every code and cloud security scanner under the sun without much feature compromise, alongside a surprisingly robust runtime application solution for things like bot prevention. A no-nonsense replacement for a lot of more "specialized" solutions that tend to slow developers down.
Upwind has built CNAPP from the ground-up around runtime insights provided from a network focused endpoint agent. They provide unique features like API security, alongside vulnerability prioritization and scanning, and the more generic CNAPP feature sets.
Ox provides an all-in-one application security solution that provides their own scanners combined with the ability to import third party findings. They also have a robust API for managing the data in the tool.
Orca offers the standard suite of CNAPP features with a focus on agentless scanning. They're a good all around CNAPP offering mostly focused on the posture side.
Tenable offers a robust ecosystem of vulnerability scanning solutions, most recently consolidated with their Tenable One Exposure Management platform. Tenable offers scanning from cloud to DAST to network scanning, and is widely deployed across enterprises in order to consolidate different scanners. Their exposure management platform has done a great job bringing together their various data points, creating a more unified experience that the platform had been missing.
Intruder offers holistic network vulnerability scanner, DAST, and CSPM scanning solutions, a great option for mid size businesses looking for a flexible scanner
Cloudfence has focused on creating a more actionable CSPM for specifically managing network and identity security in the cloud. Their network visibility allows them to do some cool things like limiting security groups based on observed traffic.
Acquired by Cloudflare. Kivera is not strictly speaking a CSPM, but provides granular controls over what cloud API calls are permissible within your environment. This allows instant enforcement of custom rules and policies, giving the same outcomes as CSPMs without the alert explosion. The downside of using them as a sole CSPM would be missing out on more holistic CNAPP features and visibility, but they run well alongside other providers.
Lacework built on top of an alert based approach rather than more traditional scanning models. That has the benefit of reduced noise and a faster reactive approach, but at the cost of surfacing a lot of alerts to security that they don't have the ability to fix.
Security Hub does a decent job aggregating AWS' security tooling reports into a single dashboard. They also offer a lot of integrations into other tools. That being said, they're not a great CSPM solution on their own and their dashboards have limited usefulness.
Codeshield has created an attack simulation platform for viewing the blast radius of a permission takeover.
CheckRed has created a CSPM with vulnerability scanning for containers. They are focused on an offering for MSSPs as a value add, but have a differentiator with some smart SaaS configuration rules as part of the platform.
Firemon has assembled a unique collection of cloud security features - CSPM, JIT AWS access, and alerting off cloudtrail events. While they don't have the full feature set of larger CNAPPs, they provide smart features at an aggressive price. They offer CSPM scanning for free.