CNAPP
A Cloud-Native Application Protection Platform (CNAPP) bundles multiple cloud security functions into one single platform.
A Cloud-Native Application Protection Platform (CNAPP) combines several cloud security functions on one platform. It typically unites CSPM, CIEM, CWPP and the scanning of code and images.
How it works
The platform collects information on configuration, permissions, workloads and vulnerabilities. It connects this data to create a comprehensive overview. From this, it identifies attack paths that arise from multiple individual weaknesses. It also scans Infrastructure as Code and container images before they reach production.
A practical example
Three findings are each rated medium on their own. A VM is publicly accessible. It has a known vulnerability and a role with access to the customer database. The CNAPP shows this combination as a critical attack path. The team closes this gap first and addresses the other findings later.
What to look out for
- The main benefit lies in prioritisation. Check how well the platform visualises attack paths.
- Clarify which clouds and services are supported, especially with multiple providers.
- Pay attention to integration into development processes, such as the CI/CD pipeline.
- A CNAPP does not detect all active attacks. Cloud logs in the SIEM remain necessary.
Classification
The term was coined by Gartner and describes a market development. The offerings differ greatly in scope and depth. Some providers originate from the CSPM space. Others come from the workload protection area.
Typical mistakes
A CNAPP is often introduced without involving the teams who run the cloud. The findings then go to the security team, who cannot fix them. Direct assignment to the responsible teams with clear deadlines per severity level is more effective.
Switzerland and regulation
For financial institutions, FINMA (Swiss Financial Market Supervisory Authority) requires effective control of outsourced cloud environments. A CNAPP can help to continuously document the security posture.
How we implement it
We integrate critical findings and Alerts from your CNAPP into the SOC. We correlate them with cloud logs to detect when a known attack path is exploited.