Cloud Security
Cloud security is the highest-multiple, fastest-consolidating domain in cybersecurity. Google acquired Wiz for $32B, the largest cybersecurity acquisition to date, a deal that re-anchored valuation expectations across the sector. This page expands on the cloud-security domain within Vendors.
What cloud security is
Cloud security secures workloads, data, and configurations running in public cloud (AWS, Azure, GCP) and increasingly in the build pipeline that ships them. It fragmented into acronyms because each cloud-adoption wave created a new gap; the platform thesis is that they collapse back into one console — the CNAPP (Cloud-Native Application Protection Platform):
- CSPM (posture): continuously checks cloud configuration against best practice and compliance — the misconfigured-S3-bucket problem. Cheap to start, agentless, land-motion.
- CWPP (workload): protects the running workload — VMs, containers, Kubernetes, serverless — at runtime. Agent or eBPF-based; deeper, stickier.
- CIEM (entitlements): cloud-permission governance — who/what can do what across thousands of IAM roles (overlaps with identity).
- DSPM (data posture): discovers and classifies sensitive data across cloud stores — the fastest-rising sub-segment, because data is what actually gets breached.
- Code-to-cloud / ASPM: shifts all of the above left into the pipeline, tying a runtime alert back to the line of code and the developer who shipped it.
The CNAPP thesis, validated by Wiz, is that buyers want one agentless graph spanning config, workload, identity, and data, not five tools. The vendor that owns that graph tends to capture the cloud-security budget.
How each actor makes money and how they differ
| Sub-segment | Leaders | Challengers | Economics & moat | M&A posture |
|---|---|---|---|---|
| CNAPP (the platform) | Wiz (Google), Palo Alto Prisma Cloud, CrowdStrike | Orca, Sysdig, Aqua, Uptycs | Agentless graph + fast time-to-value; moat = breadth of coverage and the unified risk graph | Wiz absorbed; the rest racing to platform or be tucked in |
| CSPM | Wiz, Prisma, Microsoft Defender for Cloud | Orca, Lacework (Fortinet) | Low-friction land motion; commoditizing as a standalone | Feature, not a company — absorbed |
| CWPP / runtime | CrowdStrike, Sysdig, Aqua | Upwind, Uptycs, ARMO/Kubescape | Runtime agent = stickier, higher ACV | Sysdig/Aqua independent scaled targets; Upwind the best-capitalised challenger |
| DSPM | Cyera, Wiz, Varonis | BigID, Sentra, Concentric, Flow | Hottest greenfield; data classification is the wedge | Prime sell-side — Cyera at ~$12B valuation |
| Code-to-cloud / ASPM | Wiz, Palo Alto, Snyk | Endor Labs, Apiiro, Ox | Ties dev pipeline to runtime; overlaps AppSec | Strategic tuck-in fuel |
The competitive picture: CSPM is now a feature, not a standalone business (it commoditized fast and got absorbed into CNAPP); DSPM is where the next standalone value sits, because data-layer visibility remains the unsolved problem; and the CNAPP platform itself is a two-to-three-vendor contest (Wiz/Google, Palo Alto, CrowdStrike), with the remaining players either scaling toward platform status or positioning to sell into one.
The independent runtime lane
The runtime row is the one place in the table where a new independent has been capitalised toward platform scale rather than toward a tuck-in. Upwind (founded 2022; San Francisco, with engineering in Israel) sells a runtime-first CNAPP built on eBPF kernel telemetry, refreshing its asset map on a roughly 30-second cycle and prioritising findings by what actually executes rather than by static posture. It raised a $250M Series B on January 26, 2026 led by Bessemer Venture Partners, bringing total funding to $430M, and a $300M Series C announced September 3, 2026 anchored by Bessemer and TCV with Salesforce Ventures, Greylock, Craft Ventures, Cyberstarts, Leaders Fund and Alta Park participating — taking total funding to $730M at a $3.8B post-money valuation. At the Series B the company reported 900% year-on-year revenue growth (a tenfold increase) and headcount growth from 150 to more than 300; it does not disclose ARR, so no revenue multiple is derivable. The Series B valuation was not disclosed by the company and press accounts of it range from roughly $1.5B to an implied ~$1.8B, which places the step-up between about 2.1x and 2.5x over just over seven months — a range rather than a figure, because the denominator is not firm.
Two things make the round structurally interesting rather than merely large. The first is positioning against the hyperscaler bear case below: a runtime-evidence approach is the part of CNAPP least easily replicated by bundled native posture tooling, which is where the free-with-the-cloud-bill threat is most acute. The second is that Upwind's expansion is aimed at AI workloads — automatic generation of AI bills of materials, and detection of malicious model prompts developed with NVIDIA — which places a cloud-security independent on the same ground as the dedicated Security-for-AI cohort (20g, 03l) rather than in a separate category.
DSPM is also the domain's sharpest boundary-blur: the same "discover and classify the sensitive data" capability is claimed at once by cloud (CNAPP), data security (03g), and identity (CIEM) platforms. For a product leader the live decision is therefore less "build DSPM" than "which console owns the data graph" — and whether to build it, buy it (as Palo Alto did with Dig), or partner for it, since the graph is the substrate DLP, entitlements, and agentic-security policy all read from.
Why cloud carries the highest multiples in cyber
The premium reflects three reinforcing facts: cloud-security budgets are still growing 25%+ as workloads migrate; the CNAPP graph is difficult to displace once it spans an estate; and only a handful of assets can credibly anchor a platform, so strategic scarcity bids up the few that can.
Signature deals
- Google → Wiz, $32B (2025) — largest cyber acquisition ever; validated CNAPP as the platform and reset the ceiling on cloud-security valuations.
- Palo Alto Prisma Cloud — built by acquisition (RedLock, Twistlock, Bridgecrew, Dig Security, Cider) into the incumbent CNAPP; the canonical roll-up.
- Fortinet → Lacework — a once-$8.3B-valued CSPM/CWPP unicorn absorbed at a steep discount, an example of the 2022→2024 reset.
- Cyera (DSPM) — scaled to a ~$12B valuation on a $600M round in June 2026, from $6B in June 2025 and $9B in January 2026: a doubling in twelve months. The leading independent DSPM asset and a closely-watched sell-side candidate (11, 12).
- Tenable → Ermetic (CIEM) — pulled cloud-entitlement management into an exposure-management platform.
The bear case
The cloud-security premium assumes the hyperscalers do not absorb the category from below. Microsoft Defender for Cloud, AWS Security Hub, and Google's own native tooling are improving and bundled. If "good-enough native CNAPP" ships free with the cloud bill, the independent premium compresses to the multi-cloud and data-layer use cases only. A test of the thesis is whether Wiz's growth holds inside Google and whether DSPM startups reach durable ACVs before hyperscalers ship native data-posture. If native offerings win, today's 20x+ multiples represent a peak rather than a floor.
→ Cross-references: Vendors, Identity, Deals & Comps, Valuation, Bear Case.
Updated 2026-10-04 19:34 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.