Cloud Security
Cloud security is the highest-multiple, fastest-consolidating domain in cybersecurity. Google acquired Wiz for $32B, the largest cybersecurity acquisition to date, a deal that re-anchored valuation expectations across the sector. This page expands on the cloud-security domain within Vendors.
What cloud security is
Cloud security secures workloads, data, and configurations running in public cloud (AWS, Azure, GCP) and increasingly in the build pipeline that ships them. It fragmented into acronyms because each cloud-adoption wave created a new gap; the platform thesis is that they collapse back into one console — the CNAPP (Cloud-Native Application Protection Platform):
- CSPM (posture): continuously checks cloud configuration against best practice and compliance — the misconfigured-S3-bucket problem. Cheap to start, agentless, land-motion.
- CWPP (workload): protects the running workload — VMs, containers, Kubernetes, serverless — at runtime. Agent or eBPF-based; deeper, stickier.
- CIEM (entitlements): cloud-permission governance — who/what can do what across thousands of IAM roles (overlaps with identity).
- DSPM (data posture): discovers and classifies sensitive data across cloud stores — the fastest-rising sub-segment, because data is what actually gets breached.
- Code-to-cloud / ASPM: shifts all of the above left into the pipeline, tying a runtime alert back to the line of code and the developer who shipped it.
The CNAPP thesis, validated by Wiz, is that buyers want one agentless graph spanning config, workload, identity, and data, not five tools. The vendor that owns that graph tends to capture the cloud-security budget.
How each actor makes money and how they differ
| Sub-segment | Leaders | Challengers | Economics & moat | M&A posture |
|---|---|---|---|---|
| CNAPP (the platform) | Wiz (Google), Palo Alto Prisma Cloud, CrowdStrike | Orca, Sysdig, Aqua, Uptycs | Agentless graph + fast time-to-value; moat = breadth of coverage and the unified risk graph | Wiz absorbed; the rest racing to platform or be tucked in |
| CSPM | Wiz, Prisma, Microsoft Defender for Cloud | Orca, Lacework (Fortinet) | Low-friction land motion; commoditizing as a standalone | Feature, not a company — absorbed |
| CWPP / runtime | CrowdStrike, Sysdig, Aqua | Uptycs, ARMO/Kubescape | Runtime agent = stickier, higher ACV | Sysdig/Aqua independent scaled targets |
| DSPM | Cyera, Wiz, Varonis | BigID, Sentra, Concentric, Flow | Hottest greenfield; data classification is the wedge | Prime sell-side — Cyera at ~$3B+ valuation |
| Code-to-cloud / ASPM | Wiz, Palo Alto, Snyk | Endor Labs, Apiiro, Ox | Ties dev pipeline to runtime; overlaps AppSec | Strategic tuck-in fuel |
The competitive picture: CSPM is now a feature, not a standalone business (it commoditized fast and got absorbed into CNAPP); DSPM is where the next standalone value sits, because data-layer visibility remains the unsolved problem; and the CNAPP platform itself is a two-to-three-vendor contest (Wiz/Google, Palo Alto, CrowdStrike), with the remaining players either scaling toward platform status or positioning to sell into one.
DSPM is also the domain's sharpest boundary-blur: the same "discover and classify the sensitive data" capability is claimed at once by cloud (CNAPP), data security (03g), and identity (CIEM) platforms. For a product leader the live decision is therefore less "build DSPM" than "which console owns the data graph" — and whether to build it, buy it (as Palo Alto did with Dig), or partner for it, since the graph is the substrate DLP, entitlements, and agentic-security policy all read from.
Why cloud carries the highest multiples in cyber
The premium reflects three reinforcing facts: cloud-security budgets are still growing 25%+ as workloads migrate; the CNAPP graph is difficult to displace once it spans an estate; and only a handful of assets can credibly anchor a platform, so strategic scarcity bids up the few that can.
Signature deals
- Google → Wiz, $32B (2025) — largest cyber acquisition ever; validated CNAPP as the platform and reset the ceiling on cloud-security valuations.
- Palo Alto Prisma Cloud — built by acquisition (RedLock, Twistlock, Bridgecrew, Dig Security, Cider) into the incumbent CNAPP; the canonical roll-up.
- Fortinet → Lacework — a once-$8.3B-valued CSPM/CWPP unicorn absorbed at a steep discount, an example of the 2022→2024 reset.
- Cyera (DSPM) — scaled to a reported ~$3B+ valuation, a leading independent DSPM asset and a closely-watched sell-side candidate.
- Tenable → Ermetic (CIEM) — pulled cloud-entitlement management into an exposure-management platform.
The bear case
The cloud-security premium assumes the hyperscalers do not absorb the category from below. Microsoft Defender for Cloud, AWS Security Hub, and Google's own native tooling are improving and bundled. If "good-enough native CNAPP" ships free with the cloud bill, the independent premium compresses to the multi-cloud and data-layer use cases only. A test of the thesis is whether Wiz's growth holds inside Google and whether DSPM startups reach durable ACVs before hyperscalers ship native data-posture. If native offerings win, today's 20x+ multiples represent a peak rather than a floor.
→ Cross-references: Vendors, Identity, Deals & Comps, Valuation, Bear Case.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.