{"id":7317,"date":"2025-08-14T09:00:00","date_gmt":"2025-08-14T09:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-3608\/"},"modified":"2026-05-10T19:04:54","modified_gmt":"2026-05-10T19:04:54","slug":"cnapp-and-cspm-2025-building-cloud-native-security-correctly","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2025\/08\/14\/cnapp-and-cspm-2025-building-cloud-native-security-correctly\/","title":{"rendered":"CNAPP and CSPM 2025: Building Cloud-Native Security Correctly"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">1 min Reading Time<\/p>\n<p><strong>Misconfigurations are the most common cause of cloud security incidents  &#8211;  not sophisticated attacks, but an incorrectly opened S3 bucket or an overly broad IAM role. Cloud Security Posture Management (CSPM) and the overarching CNAPP approach are the industry&#8217;s response to this structural problem.<\/strong><\/p>\n<h2>TL;DR<\/h2>\n<ul>\n<li><strong>CSPM automatically detects misconfigurations:<\/strong> Continuous compliance monitoring against CIS Benchmarks, AWS Well-Architected, ISO 27001.<\/li>\n<li><strong>CNAPP is the umbrella term:<\/strong> Combines CSPM, CWPP (Workload Protection) and CIEM (Entitlements) in one platform.<\/li>\n<li><strong>Shift Left Security:<\/strong> Integrate security checks into the CI\/CD pipeline  &#8211;  not just in production.<\/li>\n<li><strong>Gartner term since 2021:<\/strong> CNAPP has established itself as a standard category, all major security providers have CNAPP solutions.<\/li>\n<li><strong>Multi-cloud capable:<\/strong> Modern CNAPP platforms cover AWS, Azure, and GCP simultaneously.<\/li>\n<\/ul>\n<h2>CSPM: What It Does and Why It&#8217;s Necessary<\/h2>\n<p>A Cloud Security Posture Management tool connects to cloud APIs and continuously checks the configuration of all resources against defined security standards. Result: an overview of all misconfigurations, prioritized by severity, with remediation recommendations.<\/p>\n<p>Typical findings: Publicly accessible S3 buckets, security groups with 0.0.0.0\/0 access, missing encryption-at-rest, root account without MFA, overprivileged service accounts. In most cloud environments, there are hundreds of such findings  &#8211;  CSPM makes them visible and prioritizable.<\/p>\n<h2>CNAPP: The Holistic Approach<\/h2>\n<p>CNAPP (Cloud-Native Application Protection Platform) is Gartner&#8217;s term for an integrated platform that combines several cloud security disciplines:<\/p>\n<p><strong>CSPM:<\/strong> Infrastructure configuration monitoring.<\/p>\n<p><strong>CWPP (Cloud Workload Protection):<\/strong> Security of VMs, containers, and serverless functions at runtime.<\/p>\n<p><strong>CIEM (Cloud Infrastructure Entitlement Management):<\/strong> Who has which permissions in the cloud? Enforce least privilege.<\/p>\n<p><strong>SAST\/DAST in CI\/CD:<\/strong> Security checks in the code and deployment pipeline before anything goes into production.<\/p>\n<p>The advantage: One platform, one data model, one interface for the cloud security team  &#8211;  instead of integrating four different tools.<\/p>\n<h2>Market Overview and Getting Started<\/h2>\n<p><strong>Leading Providers 2025:<\/strong> Wiz, Palo Alto Prisma Cloud, Microsoft Defender for Cloud (for Azure-heavy environments), Crowdstrike Falcon Cloud Security, Sysdig, and Lacework. Wiz has gained particular traction with an agentless approach.<\/p>\n<p><strong>Getting Started Without a Large Budget:<\/strong> All three major cloud providers have native CSPM basic functions: AWS Security Hub, Azure Security Center, GCP Security Command Center. These are free (or included in the service) and a good starting point.<\/p>\n<p><strong>Prioritization:<\/strong> Don&#8217;t try to solve all 500 findings at once. Start with critical misconfigurations (public storage, missing encryption, root account security) and proceed systematically.<\/p>\n<h2>Key Facts at a Glance<\/h2>\n<p><strong>Cause of Cloud Security Incidents:<\/strong> 80% due to misconfigurations (Gartner)<\/p>\n<p><strong>CNAPP Market Size 2025:<\/strong> ~7.5 billion USD (IDC)<\/p>\n<p><strong>Growth Rate:<\/strong> 25%+ annually (fastest-growing cloud security segment)<\/p>\n<p><strong>Average Misconfigurations:<\/strong> Enterprise environments have an average of 200-400 active CSPM findings<\/p>\n<p><strong>Native CSPM at No Extra Cost:<\/strong> AWS Security Hub, Azure Security Center, GCP SCC  &#8211;  all freely available<\/p>\n<p><strong>Fact:<\/strong> Gartner predicts that by 2027, around 80% of companies will use a CNAPP platform to comprehensively secure cloud workloads  &#8211;  compared to 15% in 2023.<\/p>\n<p><strong>Fact:<\/strong> According to the CrowdStrike Cloud Threat Report 2025, misconfigurations are the most common cause of cloud security incidents, accounting for 36% of incidents.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<h3>What is the difference between CSPM and CNAPP?<\/h3>\n<p>CSPM is a subcategory: it monitors the configuration of cloud infrastructure. CNAPP is the overarching term for an integrated platform that combines CSPM with workload protection, entitlement management, and CI\/CD security.<\/p>\n<h3>Do I need an agent for CNAPP?<\/h3>\n<p>Not necessarily. Agentless approaches (e.g., Wiz) use only cloud APIs  &#8211;  without installation on VMs or containers. Agent-based approaches provide more runtime information but are more complex to operate. For getting started, agentless solutions are often more practical.<\/p>\n<h3>What is CIEM and why is it important?<\/h3>\n<p>Cloud Infrastructure Entitlement Management analyzes who has which permissions in the cloud  &#8211;  and compares this with what is actually used. The result: a least-privilege report with hundreds of overprivileged accounts. Attackers specifically look for these.<\/p>\n<h3>Can CNAPP be integrated into DevOps processes?<\/h3>\n<p>This is the core of &#8220;Shift Left Security.&#8221; Modern CNAPP platforms have plugins for GitHub Actions, GitLab CI, Jenkins, and other CI\/CD tools. Infrastructure-as-Code is checked for misconfigurations before deployment.<\/p>\n<h3>Which tool is recommended for getting started?<\/h3>\n<p>For getting started: activate native cloud tools (AWS Security Hub \/ Azure Security Center)  &#8211;  free and quick. For more professional use: evaluate Wiz or Palo Alto Prisma Cloud. Both offer free trials and POC programs.<\/p>\n<h2>Further Articles on the Topic<\/h2>\n<p>\u2192 Multi-Cloud Security 2026: The 5 Biggest Risks<\/p>\n<p>\u2192 <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/02\/22\/post_id-3527\/\">Zero Trust for SMEs<\/a><\/p>\n<h2>Further Reading in the Network<\/h2>\n<p>Current Cloud Security: <a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/02\/28\/cloud-trends-2026-was-it-entscheider-jetzt-auf-dem-radar-haben-muessen\/\" target=\"_blank\" rel=\"noopener\">cloudmagazin.com<\/a><\/p>\n<p>DevSecOps in Practice: <a href=\"https:\/\/mybusinessfuture.com\/en\/ki-made-in-germany-935-startups-oekosystem\/\" target=\"_blank\" rel=\"noopener\">mybusinessfuture.com<\/a><\/p>\n<h2>Related Articles<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/02\/24\/post_id-3529\/\">Multi-Cloud Security 2026: The 5 Biggest Risks and How to Solve Them<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2025\/02\/25\/case-study-financial-services-cloud-migration-security\/\">Case Study: Cloud Migration of a Financial Service Provider  &#8211;  Security from the Start<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/02\/22\/post_id-3527\/\">Zero Trust for SMEs: Getting Started in 5 Steps<\/a><\/li>\n<\/ul>\n<h2>More from the MBF Media Network<\/h2>\n<p><a href=\"https:\/\/www.cloudmagazin.com\" target=\"_blank\">cloudmagazin<\/a> | <a href=\"https:\/\/mybusinessfuture.com\" target=\"_blank\">MyBusinessFuture<\/a> | <a href=\"https:\/\/www.digital-chiefs.de\" target=\"_blank\">Digital Chiefs<\/a><\/p>\n<p style=\"text-align: right;\"><em>Header Image Source: Pexels \/ Brett Sayles<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"Misconfigurations are the most common cause of cloud security incidents &#8211; not sophisticated attacks, but an incorrectly opened S3 bucket or an overly broad IAM role. Cloud Security Posture Management (CSPM) and the overarching CNAPP approach are the industry&#8217;s response to this structural problem. TL;DR CSPM automatically detects misconfigurations: Continuous compliance [&hellip;]","protected":false},"author":8,"featured_media":3607,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"cnapp","_yoast_wpseo_title":"CNAPP and CSPM 2025: Building Cloud-Native Security Correctly","_yoast_wpseo_metadesc":"CNAPP and CSPM 2025: Prevent cloud misconfigurations with integrated security. Secure your cloud-native environment today\u2014start building right.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["post_id-3608"],"footnotes":""},"categories":[217],"tags":[],"class_list":["post-7317","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-innovation"],"evm_reading_time_minutes":5,"wpml_language":"en","wpml_translation_of":3608,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7317","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=7317"}],"version-history":[{"count":3,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7317\/revisions"}],"predecessor-version":[{"id":10043,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7317\/revisions\/10043"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/3607"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=7317"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=7317"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=7317"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}