Field GuideLast reviewed October 2026
Cloud security (CNAPP): posture, workloads and permissions
How companies find and fix risk in their cloud accounts: posture, permissions and workloads, why fixing is the bottleneck, agentless scans versus agents, who pays for a cloud breach, and what's real about AI in the tools.
The industry on one page
Picture a company that sells inventory and ordering software to wholesale distributors. It runs on AWS: about 2,000 workloads (virtual machines, containers and serverless functions) across nine accounts, 200 engineers, and a small Azure tenant left over from an acquisition. On a Monday its security tool shows 40,000 open findings, and the team can fix a few dozen that week. Most of cloud security, day to day, is picking which few dozen, getting the right engineers to fix them, and making sure the fixes stay fixed.
The cloud provider secures the infrastructure underneath: buildings, hardware, the hypervisor and, for managed services, the platform software. You own what you put on it: configurations, identities and permissions, keys and data, and AWS's customer agreement makes that a contract term. Attackers probe what you own with exploits and stolen keys. A security platform reads your configurations through the cloud's APIs and snapshots disks to see what's installed on your workloads, builds a graph of what connects to what, finds risks and hands them to the security team, which triages, sets policy and opens tickets. The fix belongs to the engineers who own each service, ideally made in code, and that handoff is where risk tends to sit waiting.
Gartner's name for the bundle is CNAPP, a cloud-native application protection platform. Under it sit older product names: posture management (CSPM, checking configurations against policy), entitlement management (CIEM, who can do what) and workload protection (CWPP, watching what runs on each machine), plus data, code, detection and AI security. The table in How a finding becomes a fix explains each; elsewhere I use plain words.
What I'd want a new PM in this space to take away:
- Fixing: finding cloud risk is nearly free, and fixing it is the limit. Microsoft and Google give basic posture checks away, and in December 2025 AWS added attack-path findings to Security Hub at no extra charge. A cross-industry study by Cyentia Institute and Kenna Security found a typical organization closes about 1 in 10 of its open vulnerabilities a month. Context (is it reachable, is the vulnerable code running, what can the attached identity reach) cuts the list a lot, though nearly every number on how much comes from vendors measuring their own customers. More in Who owns the fix: what's real.
- Ways in: exploits now lead as the way in, and identity still decides the damage. In Google's data on its own cloud for July to December 2025, exploits of third-party software overtook weak credentials as the top route in, at about 45% of cases, and the 2026 Verizon Data Breach Investigations Report also put exploits on top. The same Google report found identity compromise behind about 83% of compromises: an exploit puts an attacker on a machine, and the credentials there decide what they can reach.
- Agents: agentless scanning won the opening sale, and runtime agents came back in 2025-2026. A read-only role takes hours to connect where agents take weeks, but snapshots miss what's running in memory and anything short-lived. The attack-path graph no longer sets vendors apart: the clouds ship one, and a patent fight over the agentless method ended without a winner. See Agentless or agents.
- Market: buyers are consolidating onto platforms faster than vendors are consolidating into a few winners. No vendor holds much more than a fifth of the market (Dell'Oro's 3Q 2025 data had Wiz at about 19% and Microsoft at about 18%), and the clouds compete through rules on which marketplace purchases count toward committed spend. In the worked example in How the money moves, staff time costs more than the licences.
- Responsibility: every cloud contract puts configuration on the customer, and AWS caps its own liability at 12 months of fees. US federal pressure eased (the SEC dropped its SolarWinds case on November 20, 2025), while New York, the EU and the UK raised theirs, and the EU and the UK now supervise the big clouds directly; more in How the rules work.
Where observability and security share agents, pipelines and buyers is in Observability: metrics, logs and traces, and securing AI agents' identities and tool permissions is in AI agents: orchestration platforms. "Identity" here means the cloud's users, roles and machine accounts; verifying customers and businesses is a different job, covered in Identity and trust.
The main players
These are the names behind the diagram's roles, layer by layer, in no particular order.
Cloud providers' own security tools
- What they do
- Posture checks, threat detection and vulnerability scans, billed on the cloud invoice
- Main players
- AWS (Security Hub, GuardDuty, Inspector, Macie), Microsoft (Defender for Cloud), Google (Security Command Center, plus Wiz and Mandiant)
- What they control
- The APIs every other tool reads, the free tier, the marketplace and the committed-spend wallet
CNAPP platforms
- What they do
- Scan configurations, workloads and permissions across clouds; rank and route findings
- Main players
- Wiz (Google), Palo Alto Networks (Cortex Cloud), CrowdStrike (Falcon Cloud Security), Tenable, Orca Security, Fortinet (FortiCNAPP, formerly Lacework)
- What they control
- The cross-cloud graph, the CISO relationship and the fix workflow
Runtime and workload specialists
- What they do
- Watch what actually runs (processes, network calls, container escapes) and block attacks
- Main players
- Sysdig, Upwind, Aqua Security, SentinelOne, Datadog, Falco (open source)
- What they control
- The agent on each host and the "is this actually loaded" context
Code and supply-chain security
- What they do
- Scan code, dependencies, infrastructure templates, images and secrets before deploy
- Main players
- Snyk, Veracode, Chainguard, GitGuardian, Trivy (open source, from Aqua)
- What they control
- The developer's pull request and the build pipeline
Identity and permissions
- What they do
- Map who and what can reach each resource, trim unused rights, govern machine identities
- Main players
- CyberArk (Palo Alto), Astrix (Cisco), Ermetic (Tenable)
- What they control
- The non-human identities most cloud breaches run through
AI security
- What they do
- Inventory AI models and agents, scan them, filter prompts and tool calls
- Main players
- Palo Alto (Prisma AIRS, from Protect AI), Check Point (Lakera), SentinelOne (Prompt Security), Google (Model Armor), Noma Security
- What they control
- Guardrails for AI workloads, mostly as platform modules
How they make money, and who's moving:
- Cloud providers charge per resource, event or gigabyte, or give the basics away. AWS's Security Hub Essentials lists at $3.75 per "resource unit" a month (one virtual machine, or 12 serverless functions), Microsoft's paid posture plan at about $5 per billable resource, and Google prices Security Command Center Premium off forecast cloud spend. Microsoft is the number two CNAPP vendor by Dell'Oro's count. Google closed its $32 billion purchase of Wiz on March 11, 2026, after US clearance in November 2025 and EU clearance in February 2026, both without conditions; Wiz keeps its brand and its support for AWS, Azure and Oracle's cloud, and Alphabet doesn't report its numbers separately.
- CNAPP platforms charge per workload or in credits. Wiz lists at about $240-380 per workload a year and said it reached $500 million of annual recurring revenue (ARR) in July 2024; later figures above $1 billion appear only in press reports. Palo Alto folded Prisma Cloud into Cortex Cloud in February 2025 and doesn't disclose cloud revenue. CrowdStrike's cloud security ARR passed $905 million in the quarter to July 2026, up 29%. Tenable bought Ermetic for $265 million in 2023, and Orca cut 15% of its staff in January 2024. Lacework, valued at $8.3 billion at its 2021 peak, sold to Fortinet for a reported $152 million in August 2024.
- Runtime specialists charge per host or sensor. Upwind raised $250 million at about $1.5 billion in January 2026 and was reported in September 2026 to be raising about $300 million at about $3.8 billion. Sysdig, which created Falco, last raised at $2.5 billion in December 2021; Aqua raised at over $1 billion in January 2024, then cut staff twice in 2025. SentinelOne's ARR reached $1.22 billion in the quarter to July 2026, up 22%, and Datadog's security products passed $100 million of ARR in 2025. Falco graduated in the CNCF (the Linux Foundation's home for cloud software) in February 2024.
- Code and supply-chain tools charge per developer. Snyk was at an estimated $326 million of ARR, growing 7%, in February 2026 (a research firm's estimate), and Chainguard, which sells hardened container images, raised at $3.5 billion in April 2025. GitGuardian counted 23.8 million secrets leaked on public GitHub in 2024 (a vendor figure).
- Identity drew some of the biggest checks. Palo Alto closed its purchase of CyberArk, about $25 billion, on February 11, 2026, and Cisco announced on May 4, 2026 that it would buy Astrix, which secures non-human and AI agent identities. Most standalone cloud permissions tools were folded into posture products, as Ermetic was.
- AI security was bought up within about 13 months, from April to October 2025: Protect AI by Palo Alto (reported at $500-700 million), Lakera by Check Point and Prompt Security by SentinelOne (about $250-300 million each, reported), and others. Noma Security, one of the independents still standing, raised $100 million in July 2025, and Cyera, in data security, was reported at a $12 billion valuation in June 2026.
As of October 2026. This market changes owners every few months, so treat the list as a map to check before relying on it.
Back to the inventory software company. Its order API runs on Kubernetes in AWS and faces the internet. A library in its container image has a remote-code-execution bug on CISA's list of known exploited vulnerabilities; Snyk flagged it in a pull request three weeks earlier, and the ticket went to the backlog. The API's pods run under a role that can read every S3 bucket in the account, including customers' order exports. Wiz joins those facts into one critical issue, and its runtime sensor confirms the vulnerable library is loaded. Wiz's AI remediation agent, in preview since March 2026, drafts two pull requests, one bumping the library and one trimming the role in Terraform. The orders team gets a Jira ticket, and one of its engineers merges both, while GuardDuty watches the account's API calls in case someone got there first. Out of 40,000 findings, it's one of the dozen fixed that week (the vendors in the story are illustrative).
How a finding becomes a fix, step by step
Here's the order API's risk from the moment the code ships to the fix. Scanners find far more than any team can fix, so the work is picking the few risks that are both exposed and exploitable. Some get accepted as exceptions, and a fix made by hand in the console instead of in code tends to drift back.
- Deployed: a resource is created by code (Terraform, CloudFormation or Bicep templates, run from a CI/CD pipeline) or by hand in the cloud console. Code can be scanned in the pull request, the cheapest place to catch a mistake. Breaks: resources created in the console skip that check, and no code describes them.
- Found: the tool inventories every account through the cloud's APIs and checks each configuration against policy (a public bucket, a firewall rule open to the world, logging off). It looks inside workloads for vulnerable packages, secrets and malware, from a disk snapshot or an agent, and reads audit logs and runtime events for attacks in progress. Breaks: Microsoft's agentless scan runs once every 24 hours on running machines only, so a workload that lives less than a day can go unseen.
- Prioritized: context is added. Is the resource reachable from the internet? Is the bug known to be exploited? Is the vulnerable package loaded? What can the attached identity do, and is sensitive data within reach? Datadog found only 18% of vulnerabilities rated critical by their CVSS score (the standard severity score) stayed critical once runtime context was added. Breaks: a queue sorted by CVSS sends engineers after bugs nobody can reach while a chain of medium findings stays open, and a rule written to cut noise can hide the inputs a detection engine needs (see Exceptions & reversals).
- Assigned: the tool maps the resource to an owner using the account, tags, the repository that deployed it and the on-call schedule, then opens a ticket in Jira or ServiceNow, or a pull request. Breaks: an untagged resource with no link to a repository sits with nobody. In a 2021 Cloud Security Alliance survey, 70% said their security, operations and development teams weren't aligned on policy, and only 37% fixed a misconfiguration within a day.
- Fixed: from most to least durable, a team can fix the shared infrastructure module (every future copy is fixed too), fix this one template, add a guardrail such as an AWS service control policy so the class of mistake can't recur, rebuild the image, rotate the key, or fix it in the console (fast, and likely to drift). The next scan verifies it. Breaks: at AWS a resolved finding flips back to new when the check fails again, and Security Hub's older posture product deletes active findings after 90 days, so an auditor asking for a year of history needs an export.
Two exits sit off that path. Accepted is a finding the team has decided not to fix, recorded as an exception. A good exception has an owner, a reason and an expiry date, and the tools don't all enforce that: AWS's "suppressed" status has no built-in expiry, while Microsoft's exemptions and Google's dynamic mute rules can expire. Drifted is a fix that didn't stick: an engineer fixes a Terraform-managed resource in the console and the next deployment puts the old setting back, or a console change never reaches code and the next environment built from code repeats the mistake.
Posture management (CSPM)
- What it checks
- Configuration against policy: public buckets, open ports, logging off, CIS controls
- Data it needs
- The cloud's APIs, through a read-only role
- Agent?
- No
- Product or bundle (Oct 2026)
- Commoditized; free tiers at Microsoft and Google
Entitlement management (CIEM)
- What it checks
- Effective and unused permissions, escalation paths, cross-account trust, old keys
- Data it needs
- Identity and resource policies, access logs
- Agent?
- No
- Product or bundle (Oct 2026)
- Mostly folded into posture products
Workload protection (CWPP) and runtime
- What it checks
- Malware, exploits, suspicious processes, container escapes
- Data it needs
- System calls via eBPF or a kernel module, process trees, network
- Agent?
- Yes
- Product or bundle (Oct 2026)
- Real; regained weight in 2025-2026
Data security posture (DSPM)
- What it checks
- Where sensitive data lives and who can reach it
- Data it needs
- Data store inventory plus samples of the contents
- Agent?
- No
- Product or bundle (Oct 2026)
- A real standalone category, also bundled
Vulnerability management
- What it checks
- Known vulnerabilities (CVEs) in packages on machines, images and functions
- Data it needs
- Disk snapshots, registry images or an agent
- Agent?
- Either
- Product or bundle (Oct 2026)
- Real; agentless made it a posture add-on
Code, secrets and infrastructure-as-code scanning
- What it checks
- Misconfigured templates, vulnerable dependencies, code flaws, leaked keys
- Data it needs
- Repository access, CI hooks, pull requests, snapshots
- Agent?
- No
- Product or bundle (Oct 2026)
- A separate market, converging in
Cloud detection and response (CDR)
- What it checks
- Attacks in progress: credential misuse, data theft, crypto-mining
- Data it needs
- Audit logs, flow logs, Kubernetes audit, runtime events
- Agent?
- Logs, optional agent
- Product or bundle (Oct 2026)
- Real; overlaps the SIEM
AI security posture (AI-SPM)
- What it checks
- Models and agents in use, exposed endpoints, AI keys, agent permissions
- Data it needs
- The cloud's AI service APIs, code dependencies, identities
- Agent?
- No
- Product or bundle (Oct 2026)
- Mostly a module as of 2026
Gartner's baseline for a full CNAPP, as vendors summarize its 2025 market guide, is posture, workload protection, entitlements, and infrastructure-as-code and container scanning, with attack-path correlation as what sets products apart. Vendors stretch the label over whatever else they sell.
Agentless or agents
Agentless means the vendor runs the scanner in its own account and reads yours through a role you grant: the APIs for configuration and permissions, and copies of your disks for what's installed. Microsoft's version analyzes each snapshot in the same region, deletes it within minutes and keeps only metadata. It still needs rights to create snapshots and, on AWS, encryption keys, so an outside party holds a lot of access either way.
| Agentless (APIs and disk snapshots) | Agent or eBPF sensor | |
|---|---|---|
| Time to set up | Hours: one role per account or organization | Weeks to months: per host or cluster, through change management |
| Coverage | Everything the APIs see, including forgotten resources | Only where installed |
| Freshness | Periodic (Microsoft: every 24 hours) | Continuous |
| What it sees | Installed packages, files and secrets on disk, configuration, permissions | Running processes, loaded libraries, system calls, network flows |
| Can it block an attack? | No | Yes |
| Cost to the workload | Snapshot storage and API calls | CPU and memory on each host; modern eBPF needs a Linux kernel of about 5.8 or later |
| Blind spots | Time between scans, short-lived workloads, runtimes with no disk to snapshot | Hosts without the agent, managed services you can't install on |
The clouds settled on agentless as a default: Amazon Inspector has scanned EC2 machines without an agent since April 2024, and Microsoft's paid plans scan Azure, AWS and Google machines the same way. Then runtime came back. Wiz, born agentless, sells a runtime sensor and shipped forensics for it in May 2026, Palo Alto's Cortex Cloud pairs agentless scanning with its endpoint agent, and Unit 42 found high-severity runtime alerts twice as common as high-severity configuration alerts in 2024 (a vendor figure).
Meanwhile the graph stopped being a moat. AWS's Security Hub has drawn "potential attack paths" since December 2025, and Microsoft's paid posture plan has attack path analysis too. Orca sued Wiz in July 2023 over six patents on agentless scanning; on December 8, 2025 the US patent appeals board found the challenged claims unpatentable, and in early January 2026 both sides dropped their suits for good.
My default: agentless everywhere for coverage, and sensors on the production machines that face the internet or hold sensitive data.
Which cloud security setup? Five questions
- How many clouds? If you're almost all on one cloud, its native tools may cover most of what you need, for roughly $100,000-165,000 a year at 2,000 workloads. With two or more clouds, independent platforms earn their price, because each native tool is strongest on its home cloud.
- Who triages? Price the people alongside the licence. The cheapest licence can turn into the most expensive option once a team of four to six has to build the ranking and routing that a platform sells.
- Agents or not? Start agentless to see everything within days, then add sensors where you need to catch or stop an attack in progress.
- How will you pay? If you have a committed-spend contract with a cloud, check whether a vendor's marketplace listing counts toward it. Since May 1, 2025, AWS counts only software that runs on AWS.
- Which rules apply? Card data (PCI DSS), US federal customers (FedRAMP), New York financial licences (NYDFS) and EU financial firms (DORA) each set fix windows and reporting clocks. Export the evidence your auditor wants before the tool deletes it.
My defaults: for a B2B software company on one cloud with a couple of thousand workloads, I'd turn on the cloud's own posture checks and threat detection, since they're cheap and count toward the commitment. I'd add a platform once there's a second cloud or once the team spends more time stitching findings together than getting them fixed, and buy it through the marketplace if it qualifies. I'd route every finding to the owning team's tracker with a named owner, require an expiry date on every exception, and measure the program on exposed, exploitable risks closed each month rather than on findings found.
The primitives
01
Entity & identity
What is the unit of record, and how do we know it is the same one?
The unit is the cloud resource: an AWS ARN, an Azure resource ID, a Google resource name. Vendors bill on it, and each counts it differently:
| Billing entity | Who uses it | Rough list price (Oct 2026) |
|---|---|---|
| Workload (a running VM, container or serverless function) | Wiz | $240-380 a year, less at volume |
| Resource unit (1 VM = 12 functions = 18 images = 125 identities) | AWS Security Hub | $3.75 a month |
| Billable resource (servers, storage accounts, databases) | Microsoft Defender CSPM | About $5 a month |
| Host | Datadog, Sysdig | $10-25 a month at Datadog |
| Developer | Wiz Code, Snyk | About $585 a licence a year for Wiz Code |
The same estate can come out very differently under each, so comparing quotes starts with converting them to one unit.
Cloud identity is the other entity: people, roles, service accounts, workload identities and integration roles. Machine identities far outnumber people, though estimates run from 10 to 1 (Microsoft, 2023) to "up to 40,000" to 1 (Sysdig, 2025), which mostly shows the definitions differ. Microsoft's 2023 research found identities use about 1% of the permissions they're granted. Non-human identities are where cloud breaches run: old access keys, OAuth tokens, CI tokens and, in Microsoft's Storm-0558 case, a signing key. The scanner is one too: a CNAPP holds read rights, and often snapshot and encryption-key rights, in every account you connect.
Customers and businesses that a platform verifies are a different kind of identity, covered in Identity and trust; AI agents' identities are in AI agents: orchestration platforms.
02
State & lifecycle
What states exist, and what moves an entity between them?
A finding at AWS carries three separate states at once: a workflow status (new, notified, suppressed, resolved), a record state (active or archived) and a compliance result (passed, failed, warning or not available). They change independently. The detail I'd remember: a resolved finding goes back to new if the check fails again, while a suppressed one stays suppressed. A suppression is sticky and a fix is fragile.
Severity is a state too. A finding becomes critical when something next to it changes: a firewall rule opens, a role gains a permission, a bucket starts holding customer data. Graph-based tools recompute as the inputs change.
Credentials have a lifecycle that nobody closes. In Datadog's October 2025 data, 59% of AWS IAM users had an active access key more than a year old, and in the 2024 Snowflake breaches some stolen credentials dated back to 2020 and still worked. "Decommissioned" is the state most often missing.
Regulators add states of their own: an incident becomes "material" at the SEC or "major" under DORA, and a cloud provider becomes "designated" as critical in the EU and the UK.
03
System of record & ledger
Who owns the truth, and how do systems reconcile?
There's no single system of record.
| Record | System of record |
|---|---|
| What's actually configured | The cloud's own API |
| What was meant to be configured | The infrastructure-as-code repository |
| Risk across clouds, code and runtime | The security platform's graph, minutes to a day behind |
| Who's fixing it | The ticketing system |
| What happened during an attack | The cloud's audit logs (AWS CloudTrail, Microsoft Entra, Google Cloud audit logs) |
| Every technology contract of an EU financial firm | Its DORA register of information |
| What security costs | The cloud bill, when bought natively or through the marketplace |
Drift is the gap between the repository and the cloud; staleness is the gap between the cloud and the graph. Retention is short by default: AWS Security Hub's older posture product deletes findings after 90 days active or 30 days archived, while PCI, SOC 2 and FedRAMP auditors usually want longer, so evidence gets exported to storage or a SIEM (the security team's log analysis system). And because Security Hub Extended and marketplace purchases land on the AWS bill, finance and FinOps teams see security spend alongside the CISO.
04
Rules & policy
What logic decides outcomes, and who can change it?
Policy comes from CIS benchmarks (prescriptive technical checks; AWS added version 5.0 of its AWS benchmark to Security Hub in October 2025, with 40 automated controls), the providers' own benchmarks, mappings to PCI or FedRAMP, custom rules, and preventive guardrails such as AWS service control policies and resource control policies, Azure Policy and Google organization policies. Detection dominates prevention in practice: in Datadog's 2025 data, 40% of AWS Organizations users had service control policies and 6% had resource control policies.
The metadata fix is my favourite example of a cheap rule left unapplied. Version 2 of the EC2 instance metadata service needs a session token, which blocks the request-forgery trick behind the Capital One breach. Datadog found it enforced on 49% of EC2 instances in 2025, up from 7% in 2022, while 82% of instances had used only version 2 in the previous two weeks and could have enforced it without breaking anything.
Regulators and insurers write rules too. New York now requires MFA for any individual accessing a covered firm's systems, and insurers increasingly reject text-message MFA and ask for phishing-resistant keys for administrators, endpoint detection and backups.
05
Effective dating
Which version of the rule applied at that moment?
Dates I'd keep on a calendar as of October 2026:
| Change | Effective | Status (Oct 2026) |
|---|---|---|
| PCI DSS 4.0's future-dated requirements (51 of the 64 new ones) | March 31, 2025 | Live |
| NYDFS Part 500 final phase: MFA for any individual, asset inventory | November 1, 2025 | Live |
| DORA designates 19 critical providers, including AWS, Google Cloud, Microsoft and Oracle | November 18, 2025 | Live |
| AWS's new Security Hub, with exposure findings and attack paths | December 2, 2025 | Live |
| FedRAMP Consolidated Rules for 2026 published | June 25, 2026 | Mandatory January 1, 2027 |
| UK designates AWS, Google Cloud, Microsoft and Oracle as critical | July 13, 2026 | Live |
| Snowflake's MFA phase 3: people can no longer sign in with a password alone | August-October 2026 | Rolling out |
| Sentencing in the Snowflake attack case | October 27, 2026 | Upcoming |
| FedRAMP's vulnerability detection and response rules required | December 7, 2026 | Upcoming; grace period to March 7, 2027 |
Some changes have no date yet: SEC Item 1.05 is under pressure to be rescinded, the EU proposed NIS2 amendments on January 20, 2026, and the UK's Cyber Security and Resilience Bill is still in Parliament. And since December 2025, "CSPM" also names an AWS product, the old Security Hub.
06
Interfaces & standards
What format and protocol do counterparties speak?
The findings side is converging on a few shared formats:
- OCSF (the Open Cybersecurity Schema Framework) is the format for AWS's new Security Hub findings and for partner findings sold through Security Hub Extended. Shared formats make it cheaper to swap one tool for another, and they make whoever collects everyone's findings more valuable.
- CVE, CVSS, EPSS and KEV describe vulnerabilities: CVE names one, CVSS scores its severity, EPSS estimates how likely it is to be exploited, and KEV is CISA's catalog of vulnerabilities known to be exploited.
- CIS benchmarks define configuration checks, and MITRE ATT&CK names attacker techniques; GuardDuty maps its attack sequences to it.
The rest is plumbing: cross-account roles for reading, Jira, ServiceNow and Slack for ownership, Git for pull requests. The newest piece is MCP, the protocol AI agents use to call tools: Wiz offers its remediation agent over MCP, and Google's Model Armor screens MCP tool calls.
07
Networks & counterparties
Who sits between us and the outcome, and what do they want?
| Party | What they control | What they absorb when it goes wrong |
|---|---|---|
| Security team (CISO, cloud security engineers, SOC) | Tool choice, policy, triage, exceptions | Blame and disclosure decisions |
| Platform or cloud team | Accounts, guardrails, the roles tools need, the commitment | Rework from bad guardrails |
| App teams | The code and most fixes | Engineering time |
| Cloud provider | Infrastructure, defaults, log tiers, the marketplace | Product changes, capped liability |
| Security vendors | Detection, the graph, routing | Reputation; their access can become the attacker's |
| Auditors (QSAs for PCI, CPA firms for SOC 2, 3PAOs for FedRAMP) | Which evidence and exceptions pass | Nothing directly |
| Insurers | Eligibility, price, exclusions | Covered losses |
Outside parties are now the usual shape of a breach. The 2026 Verizon report, as summarized by others, found partners or vendors involved in 48% of breaches, up from 30%. The chains I'd keep in mind run from a contractor's laptop to Snowflake (2024), from a chat vendor's stolen tokens to Salesforce data to AWS keys (Salesloft Drift, 2025), and from a poisoned scanner to a CI pipeline to AWS keys (Trivy, 2026). The tools are counterparties too: Datadog's 2025 data found 12.2% of vendors' integrations into customers' clouds dangerously over-privileged.
One company now sits in several seats. Google runs a cloud, owns Wiz, owns Mandiant (whose report traced the Snowflake breaches to customers' credentials), publishes threat data from its own incidents and sells Model Armor. That's a lot of the story told and sold by one party, which I'd keep in mind when reading their reports.
08
Regulatory layering
Jurisdiction × activity × entity type: is it a license or a certification?
Nobody licenses cloud security vendors; the rules arrive in layers.
Contract
- What it covers
- Shared responsibility, the customer agreement
- Binds
- Customer and provider
- Enforced by
- Courts, under the contract's caps
Standards with contractual teeth
- What it covers
- PCI DSS, SOC 2, ISO 27001
- Binds
- Whoever signed up for them
- Enforced by
- Card networks, customers, certification bodies
Government buyers
- What it covers
- FedRAMP, CISA directives
- Binds
- Vendors selling to US agencies; agencies themselves
- Enforced by
- FedRAMP, CISA
Sector and disclosure law
- What it covers
- SEC, NYDFS, bank regulators, the FTC, HIPAA, GDPR, NIS2, DORA
- Binds
- The breached company
- Enforced by
- Each regulator
Supervision of the clouds
- What it covers
- DORA critical providers, UK critical third parties, NIS2 (cloud is an "essential" sector)
- Binds
- AWS, Microsoft, Google, Oracle and others
- Enforced by
- EU supervisors, UK regulators
A New York-licensed, SEC-listed lender on AWS answers to its bank regulators, NYDFS, the SEC, PCI DSS through its card processors, state breach laws, and GDPR and DORA if it operates in the EU. Compliance dashboards map one technical check to all of these; the auditors and the evidence they accept differ.
09
Exceptions & reversals
What goes wrong, and how is it undone?
Suppressed finding
- Where
- AWS Security Hub
- Expiry
- None built in
- The catch
- Sticky; new findings for the same issue still appear
Exemption (waiver or "mitigated")
- Where
- Microsoft Defender for Cloud
- Expiry
- Optional
- The catch
- Marking a resource mitigated raises the secure score; up to 5,000 per subscription
Mute rule (static or dynamic)
- Where
- Google Security Command Center
- Expiry
- Dynamic rules can expire
- The catch
- Static rules mute future findings indefinitely
Suppression rule
- Where
- AWS GuardDuty
- Expiry
- None
- The catch
- Archived findings drop out of attack-sequence detection
Targeted risk analysis
- Where
- PCI DSS 11.3.1.1
- Expiry
- Reviewed by the assessor
- The catch
- "Addressed" can mean mitigated another way
The GuardDuty case is the one I'd teach. Its Extended Threat Detection, on by default since December 2024, correlates events over a rolling 24 hours into a single critical "attack sequence" finding, and it ignores archived findings, including ones archived by suppression rules. A rule written to cut noise can blind the engine meant to catch the attack, which is why AWS advises reviewing suppression rules.
Rules reverse as well. The SEC's SolarWinds case was dismissed with prejudice on November 20, 2025, and the members of the US Cyber Safety Review Board, which had called Storm-0558 "a cascade of security failures", were dismissed in January 2025. Snowflake moved its MFA deadline twice, from November 2025 to August and then October 2026. And the UK's data regulator cut Capita's proposed £45 million fine to £14 million.
10
Liability allocation
When it fails, who pays?
The customer carries almost all of it, and the contracts say so. AWS's customer agreement (updated August 14, 2026) says "You are responsible for properly configuring and using the Services" and caps AWS's liability at the fees paid for the service involved in the 12 months before the claim. Microsoft lists configurations, identities and data as the customer's in every column, though its page is "not intended to convey legal conclusions". Google says customers "always remain responsible for their access policies and data", and its "shared fate" program adds blueprints and an insurance channel without changing legal liability.
| Failure | Who pays first | How |
|---|---|---|
| Misconfiguration or a leaked customer key | The customer | Clean-up, settlements, fines |
| The provider's own key or flaw (Storm-0558) | Customers in clean-up; the provider in engineering and reputation | No fine; free logs; a security program |
| A platform default (MFA optional) | Customers so far; the platform is being tested in court | Snowflake's multidistrict litigation |
| A security tool as the way in (Trivy) | Every downstream customer, rotating keys | The vendor's reputation |
| A long cloud outage | Customers, mostly uninsured below waiting periods | Insurers' estimates for the October 2025 AWS outage ran from $38 million to $581 million |
Snowflake is the case to watch. It's a defendant in federal multidistrict litigation in Montana, and October 2025 rulings let negligence and consumer-protection claims proceed on several tracks; two plaintiffs' claims against it were dropped in December 2025 after their companies settled. With no liability finding and no certified class, the theory that an optional-MFA default is negligence is alive and unproven, and I found no public case where a customer recovered breach losses from a cloud provider.
Providers pay in engineering instead: AWS shipped instance metadata version 2 in November 2019, about four months after Capital One, Snowflake is making MFA mandatory, and Microsoft made logs free after Storm-0558.
What's different here
How the money moves
The customer pays almost everyone: the CISO usually signs for the platform, the cloud team's commitment often pays for it, and app teams pay in time.
| Flow | Who pays whom | Rough amount (Oct 2026, list) |
|---|---|---|
| Platform licence | Customer → CNAPP vendor, often through a marketplace | $240-380 per workload a year (Wiz) |
| Runtime sensors | Customer → vendor | About $280 per sensor a year (Wiz); $15 per host a month (Datadog) |
| Code security | Customer → vendor | About $585 per licence a year (Wiz Code); about 2 credits per active developer a day at $1 each (Snyk) |
| Native posture | Customer → cloud | Free (Microsoft and Google basic tiers) to $3.75 per AWS resource unit or about $5 per Defender resource a month |
| Threat detection | Customer → cloud | $4 per million AWS management events; $1.50 per vCPU a month for runtime monitoring |
| Partner tools on the cloud bill | Customer → AWS → partner | For example Upwind at $3.75 per resource a month |
| Fixing | App teams' time | Usually the largest line; see below |
Enterprise deals land 15-35% below list in third-party data. One buyer-data platform puts the average saving on Wiz at 21-22% across 78 purchases, with a median contract of about $115,000 a year.
A year of cloud security for 2,000 workloads and 200 engineers
Back to the inventory software company: about 2,000 workloads (1,000 machines and Kubernetes nodes, 1,200 serverless functions), 3,600 container images, 2,500 IAM users and roles, 200 engineers of whom about 150 commit code in a month, and AWS spend of $6-12 million a year under an $8 million commitment. The security team is four to six people. Every figure is a rough annual range.
One platform, priced from Wiz's list
- Licence (after typical discounts)
- About $310,000-830,000
- People to run it (my estimate)
- Up to half an engineer
- Counts toward the AWS commitment?
- Yes, through a marketplace private offer, up to a negotiated cap
- Main risk
- Price rise at renewal; a change of owner
AWS native tools (Security Hub, GuardDuty, Inspector)
- Licence (after typical discounts)
- About $100,000-130,000; $130,000-165,000 at list with Defender on the Azure tenant
- People to run it (my estimate)
- Half to one engineer, $90,000-250,000
- Counts toward the AWS commitment?
- Yes, all of it
- Main risk
- Depth gaps, seams between clouds, routing built in-house
Point tools, one per layer
- Licence (after typical discounts)
- About $270,000-650,000
- People to run it (my estimate)
- One to two engineers, $180,000-500,000
- Counts toward the AWS commitment?
- Only the eligible listings
- Main risk
- Sprawl, duplicate agents, unranked findings
The platform range runs from the cheaper tier alone ($480,000 at list) to the richer tier with sensors, code scanning and detection (about $1.04 million at list).
Then add the fixing. If the platform surfaces about 40 exposed, exploitable criticals a month and each takes an engineer half a day to a day to fix and verify, that's 20-40 engineer-days a month: one to two full-time engineers of app-team time, roughly $200,000-400,000 a year. That's my own assumption, and it fits the one solid number on capacity, about 1 in 10 open items fixed a month. At this size, who does the triage and the fixing matters more to the total than which licence you buy.
As a share of the AWS bill, by my rough arithmetic, native tools come to 1-3%, a platform 3-14% and point tools 5-19% once the overhead is counted.
The commitment can matter more than list prices. Bought as an AWS private offer, Wiz counts toward the $8 million commitment because it runs on AWS. If the company expects to fall $500,000 short of its commitment, a $400,000 platform deal costs it close to nothing at the margin, and I suspect that's often why a deal closes in a particular quarter. Outside advisers say the marketplace share of a commitment is often capped at about 25%.
| Cloud | Committed-spend program | What marketplace spend counts |
|---|---|---|
| AWS | EDP or PPA | Only "Deployed on AWS" listings, since May 1, 2025; Security Hub Extended purchases count |
| Minimum commitment | Up to 100%, excluding services not running on Google Cloud | |
| Microsoft | MACC | Enrolled offers, and only licences "exclusively used in Azure" |
Wiz runs on AWS and holds AWS's "Deployed on AWS" badge, so Google's largest security asset draws down its rival's commitments.
For scale: a mid-size company with a few hundred workloads on one cloud spends roughly $50,000-200,000 a year on cloud security tools, and a large one with 10,000 or more workloads across clouds about $1-5 million.
Budget ownership is murky, and I haven't found a neutral survey. My read: the CISO owns the platform line and the vendor choice, the cloud platform team owns the commitment it's paid from, and engineering owns the fix and, more and more, the per-developer code security line.
Who holds the power
Power follows whoever controls the data the tools read, the bill they're paid from and the engineers who make the fix.
- Cloud providers hold the APIs and logs, the free tier, the bill, the commitment and the marketplace rules, and since March 2026 Google owns Wiz. Their weakness is that buyers are wary of a cloud grading its own homework.
- Security platforms (Palo Alto, CrowdStrike, SentinelOne, Check Point, Fortinet, Tenable) hold the enterprise security budget and fold cloud into bigger deals through credit pools. CrowdStrike's cloud line is about 15% of its $5.84 billion of ARR.
- Independent CNAPP vendors hold multicloud neutrality, the graph and the CISO relationship, and depend on marketplaces whose rules the clouds write. Wiz's neutrality is now a promise to be defended contract by contract.
- Observability vendors hold an agent on every host and the engineers' daily tools, and are small in security revenue; that convergence is in Observability: metrics, logs and traces.
- Engineers and platform teams hold the fix. Whoever routes findings into their pull requests and trackers gets used daily, and vendors pay for that path: Wiz bought the remediation startup Dazz (about $450 million) in 2024, and Tenable bought Vulcan Cyber for $150 million in January 2025.
- Auditors decide which exceptions pass. Insurers gatekeep through MFA and endpoint-detection attestations; as far as I can tell they don't yet read posture data at scale, though Google lets customers share theirs with insurers for quotes.
- Regulators are splitting, with the EU, the UK and New York tightening while the SEC has eased off.
How the rules work
Nobody needs a licence to sell cloud security. The rules land on the breached company, on buyers such as US federal agencies, and since 2025 on the big clouds.
Disclosure. Listed US companies must file an 8-K under Item 1.05 within four business days of deciding a cyber incident is material. Many file under the voluntary Item 8.01 instead: in the two years to May 2026, 29 issuers filed under 1.05 and 50 under 8.01. The SEC fined four companies about $1-4 million each in October 2024 over misleading disclosures, then dropped its case against SolarWinds and its CISO on November 20, 2025. Trade groups want Item 1.05 rescinded, though I found no proposal as of October 2026, and US federal pressure on breach disclosure looks to have peaked in 2024.
| Rule | Who it covers | Clock |
|---|---|---|
| SEC Item 1.05 | US listed companies | 4 business days after deciding an incident is material |
| NYDFS Part 500 | New York banks, insurers, money transmitters | 72 hours after determining an incident occurred |
| GDPR and UK GDPR | Controllers of EU and UK personal data | 72 hours to the regulator |
| NIS2 | EU essential and important entities, cloud providers included | Early warning in 24 hours, notification in 72, final report in a month |
| DORA | EU financial firms | Initial notice within hours of classifying a major incident; final report in a month |
| HIPAA | US covered entities and their vendors | Within 60 days of discovery |
New York. The final phase of NYDFS Part 500 took effect on November 1, 2025: MFA for any individual accessing covered systems, and a full asset inventory. Penalties run $250,000-2 million an order (PayPal and a New York dental benefits company paid $2 million each in 2025, the latter partly for annual certifications that turned out false), and they can't be paid from insurance.
EU and UK. DORA, the EU's operational resilience law for financial firms, has applied since January 17, 2025. On November 18, 2025 the EU's financial supervisors designated 19 critical technology providers, including AWS, Google Cloud, Microsoft and Oracle, and the UK designated the same four from July 13, 2026. Both regimes are about outages and concentration more than breach liability; banks stay responsible for their own technology risk. NIS2 treats cloud providers as essential entities, with fines up to €10 million or 2% of turnover, and the UK's data regulator fines missing MFA (Capita £14 million, Advanced £3.07 million).
Standards and buyers. PCI DSS 4.0.1 requires critical security patches within a month of release and a responsibility matrix for each service provider. FedRAMP's 2026 rules set fix windows by how exposed and exploitable a vulnerability is, from 12 hours at the top tier to as long as 192 days at the bottom, required from December 7, 2026, and its consolidated rules replace narrative security plans with machine-checked indicators from January 1, 2027. CISA's BOD 25-01 (December 17, 2024) was the first binding US federal mandate on SaaS settings, and FTC orders against Chegg (shared AWS root credentials without MFA) and GoDaddy read like a posture checklist.
Insurance. Global cyber premium was about $15-16 billion in 2025. Lloyd's has required exclusions for state-backed attacks since March 31, 2023, and long cloud outages often fall inside waiting periods of 8-12 hours, so they go largely uninsured.
What mistakes cost
IBM's 2026 survey put the average breach at a record $4.99 million worldwide, up 12%, and $11.5 million in the US. Fines are small next to that: NYDFS orders run up to about $2 million and SEC penalties $1-4 million, while class actions and the incident itself dominate. The cases below show who actually paid.
| Case | What happened | Who paid |
|---|---|---|
| Capital One, 2019 | A misconfigured web application firewall let an attacker make a server fetch its role credentials from the instance metadata service; the role could read S3; about 106 million people affected | Capital One: an $80 million OCC penalty, a $190 million class settlement and $100-150 million of 2019 costs, against a $400 million insurance tower. AWS, also sued, paid nothing on record |
| Snowflake customers, 2024 | Passwords stolen by infostealer malware, often years earlier, with no MFA, no rotation and no network allow list; about 165 organizations notified | The customers: AT&T a $177 million settlement covering two breaches (final approval pending) and a reported ransom of about $370,000; Advance Auto Parts $10 million; Neiman Marcus $3.5 million |
| Microsoft Storm-0558, 2023 | Attackers forged tokens with a stolen 2016 Microsoft consumer signing key; 22 organizations and over 500 people | Microsoft, in engineering and reputation: no fine, free logs for customers, a company-wide security program |
| Trivy and the European Commission, 2026 | Attackers poisoned Aqua's open-source scanner Trivy on March 19, 2026; a copy in the Commission's CI pipeline exposed an AWS key, and the attackers added a key to an existing user and took about 340 GB | Not quantified; 71 hosting clients of the Europa.eu service affected; credentials revoked |
| LiteLLM, 2026 | An unpinned Trivy in LiteLLM's CI leaked a package-publishing token, and the attackers published a backdoored LiteLLM that harvested cloud and Kubernetes credentials | Not quantified; every downstream user rotates keys |
Capital One is the textbook toxic combination: an exposed app, a reachable metadata service and a role with too much access. Snowflake is the textbook identity case: Mandiant found no breach of Snowflake's own environment, and at least 79.7% of the accounts used had credentials exposed in earlier infostealer leaks. One attacker pleaded guilty on August 5, 2026, with sentencing set for October 27, 2026. Storm-0558 is the one customers couldn't have prevented with posture; US agencies spotted it only because they paid for a premium log tier, a story told in Observability: metrics, logs and traces.
Trivy is the newest pattern, and the most uncomfortable for this industry, because the security tool became the way in. The Commission detected suspicious AWS API activity on March 24, five days after the key was stolen, and CERT-EU tied the breach to the Trivy compromise with high confidence.
Smaller patterns repeat: Microsoft AI researchers published a storage token on GitHub that opened 38 TB of data in 2023, and attackers who steal cloud keys often run hosted AI models on the victim's bill, called LLMjacking, at reported costs above $100,000 a day.
Who owns the fix: what's real
My view as of October 2026: finding cloud risk is cheap and getting cheaper, ranking it is expected of every tool, and the gap is getting fixes merged by the teams that own each service. The evidence on fix capacity is strong and old. The evidence on how much context helps comes mostly from vendors grading themselves. And AI remediation exists, with no published results yet.
What the evidence says about fixing
- Capacity: the Cyentia and Kenna study (about 300 organizations, published 2019) found a typical organization can close about 1 in 10 of its open vulnerabilities in a month, regardless of size; about half fall further behind, and the median vulnerability took 100 days to fix. It predates CNAPP and covers all infrastructure, so I'd use it for the shape of the problem more than the exact rate.
- Known-exploited bugs: secondary summaries of the 2026 Verizon report say only about 26% of vulnerabilities on CISA's known-exploited list were fully fixed, down from 38%, and the median time to patch rose to 43 days. Wiz, citing an outside tracker, puts the gap from disclosure to exploitation at about 21.5 days.
- Code and alerts: Veracode's 2026 report found 82% of organizations carrying security debt, and Palo Alto's Unit 42 reported the average organization's cloud alerts rose 388% during 2024 (a vendor figure).
- Cheap fixes left undone: the metadata setting most instances could enforce without breaking anything, in Rules & policy, and the 59% of IAM users with keys over a year old.
What context really cuts
| Vendor (date) | Claim |
|---|---|
| Datadog (2025) | Only 18% of CVSS-critical vulnerabilities stay critical with runtime context |
| Sysdig (March 2025) | Under 6% of critical and high vulnerabilities sit in packages actually in use at runtime |
| Wiz (2026) | Reachability, risky permission combinations and data access cut initial high-priority findings by more than half (no customer count published) |
| Tenable (June 2025) | The share of organizations with a workload that's internet-facing, critically vulnerable and highly privileged fell from 38% to 29% |
Every row is a vendor measuring its own customers with its own checks; nobody runs a neutral census of cloud findings. The direction is consistent across competitors, so I believe context cuts the list a lot, but I wouldn't quote any one percentage to a buyer.
Where the fix gets stuck
- No owner: findings on untagged resources with no link to a repository sit unassigned, and the newest survey I found on who fixes cloud findings is from 2021.
- Split budgets: the CISO buys the tool and engineering pays in time, so the team that owns the fix doesn't own the goal.
- Console fixes and open-ended exceptions: the fastest fix drifts back at the next deployment, and suppressions without expiry make the dashboard look better while the risk stays put.
- Ticket overload: I'd expect a tool that files every finding as a ticket to train engineers to ignore the queue. AWS now creates Jira and ServiceNow tickets from findings, and Wiz assigns owners in one click, so routing is getting easier while deciding what deserves a ticket stays hard.
What AI changes so far
- Remediation agents: Wiz's Green Agent, in public preview since March 26, 2026, investigates the top risks, finds the owner, writes command-line, Terraform or Kubernetes fixes and opens pull requests or hands context to coding agents. It doesn't apply changes by itself. No vendor I found publishes how often its AI fixes get merged or how often they break something.
- Testing: AWS's Security Agent became generally available for on-demand penetration testing on March 31, 2026, with no independent data on its quality yet.
- Analysts: Microsoft's randomized trial with 147 security professionals found Security Copilot made them about 7% more accurate and 14-39% faster on lab tasks, while a benchmark from CrowdStrike and Meta found models got malware analysis right only about 15-34% of the time. IBM's 2026 survey links extensive security AI to cheaper breaches ($4.00 million against $5.93 million), a correlation among breached companies.
- Attackers: Anthropic reported a campaign it calls GTG-1002 in which AI agents performed 80-90% of the tasks against about 30 targets, with few successes (Anthropic's own account).
AI investigation of incidents is covered in Observability: metrics, logs and traces.
Securing AI workloads
AI security posture is the posture, data and secrets checks above pointed at AI resources: model endpoints, notebooks, training data buckets, AI API keys and agent identities. It's sold as a module of the platforms more than as a category of its own, and the clouds bundle it. AWS made AI inventory free in Security Hub Essentials in July 2026, Microsoft's paid posture plan covers Azure OpenAI, Azure Machine Learning and Amazon Bedrock, and Google's Model Armor screens prompts, responses and MCP tool calls on any cloud.
The demand is real even if the numbers are soft: Wiz said in 2025 that 85% of organizations host AI in their cloud (a vendor figure), and IBM's 2026 survey found unsanctioned "shadow AI" in 43% of breached organizations. Runtime filters for prompts and tool calls are usually a separate purchase, and how agents get identities and tool permissions is in AI agents: orchestration platforms.
Questions to ask a vendor about fixes
- Of the issues you ranked critical for us last quarter, how many did our teams close, and how fast?
- How do you find the owner of a resource with no tags, and what share of our findings have one?
- Does the fix go back into code, and do you flag it when a console fix drifts?
- Do exceptions require an expiry date, and do suppressed findings still feed your threat detection?
- When your AI opens a pull request, what share are merged unchanged, and who's accountable when one breaks something?
What usually goes wrong
| Symptom | Likely cause | First thing to check |
|---|---|---|
| 40,000 findings and the count never falls | Ranked by CVSS instead of exposure; no owners | Share of findings with an owner; criticals that are reachable and exploitable |
| The same misconfiguration is back a week after the fix | Fixed in the console; the next deploy reverted it | Whether the resource is managed in code; drift reports |
| Secure score up, risk unchanged | Exemptions marked "mitigated" with no expiry | Exemptions by age and reason |
| No attack-sequence finding during a real attack | Suppression rules archived the inputs | GuardDuty suppression rules |
| A short-lived workload was exploited and nothing saw it | Agentless scans every 24 hours, no runtime sensor | Sensor coverage on internet-facing nodes |
| Auditor asks for last year's evidence | Findings deleted after 90 and 30 days | Exports to storage you own |
| Year-old access keys everywhere | IAM users with long-lived keys, including in CI | Key age; short-lived federated credentials for CI |
| A security tool becomes the way in | Unpinned versions or mutable tags in CI; broad scanner roles | Pinned versions; permissions on integration roles |
| Marketplace purchase didn't count toward the commitment | Listing not "Deployed on AWS", or not Azure-only for Microsoft | Eligibility before signing |
Words that mean something else here
| Term | What you'd assume | What it means here |
|---|---|---|
| Agent | An AI agent | Usually a host agent or sensor; also an AI agent, and part of product names ("AWS Security Agent", "Wiz Green Agent") |
| Agentless | Nothing runs anywhere | The vendor's scanner reads your APIs and disk snapshots with roles you grant, including rights to create snapshots and keys |
| Finding, issue, exposure, alert | Synonyms | A finding is one check result; an issue (Wiz) or exposure finding (AWS) is a ranked combination; an alert is activity seen at runtime. Counts differ 10-1,000 times depending on the noun |
| Critical | Urgent | A CVSS score, a contextual ranking (exposed and exploitable) or, under DORA, a provider the system depends on |
| Workload | An application | Wiz's billing unit: one running VM, container or serverless function |
| Posture | Overall security | Configuration at a point in time |
| Toxic combination | A chemistry term | Low and medium findings that together make a critical path (Wiz's phrase; others say attack path) |
| Suppressed, muted, exempted, accepted | Different states | Four ways to say "known, not fixing"; they differ on expiry and on whether scores change |
| Shift left | Doing work earlier | Scanning in code and CI; more and more, also sending the fix to the developer as a pull request |
| LLMjacking | Hacking a model | Using stolen cloud keys to run AI models on the victim's bill |
What surprised me
Placeholders in your voice, drafted from the research and the earlier guides. Rewrite each with your own moment.
"Security tools find the problems." Every tool found them, by the tens of thousands. The weeks went into getting an engineer on another team to merge a fix for the twelve that mattered.
"Agentless won." It won the opening sale. By 2026 the same vendors were selling sensors again, because a disk snapshot can't see what's running.
"Attackers get in through misconfigurations." In the latest data, exploits led as the way in. What they could reach once inside still came down to identity and permissions.
"The cloud provider shares the risk." Every contract I read put configuration on the customer and capped the provider at a year of fees.
"The security tool is the safe part of the stack." In March 2026 a poisoned scanner handed attackers the keys it was meant to protect.
Sources
Undated entries were read on October 8, 2026; "search result" means seen only as a search snippet or summary. Company figures are self-reported unless they come from a filing or a regulator, and vendor research measures each vendor's own customers.
Cloud providers: documentation, pricing and contracts
- AWS: shared responsibility model; Customer Agreement (Aug 2026); Security Hub pricing; new Security Hub generally available (Dec 2025); Security Hub Extended (Feb 2026); CIS benchmark v5.0 in Security Hub CSPM (Oct 2025, search result); finding workflow status (search result); findings retention (search result)
- AWS GuardDuty, Inspector and AI: GuardDuty pricing; Extended Threat Detection (Dec 2024, search result) and its documentation (search result); Inspector agentless EC2 scanning (Apr 2024, search result); Help Net Security, Security Hub AI workload protection (Jul 2026); Security Agent penetration testing (Mar 2026, search result)
- AWS Marketplace: SaaS deployment locations and commitments (May 2025, search result); Wiz listing
- Microsoft: shared responsibility in the cloud (Aug 2026); agentless machine scanning (Aug 2026); exempting resources (search result); AI security posture (search result); Azure retail prices API (queried Oct 2026); Azure consumption commitment enrollment (Oct 2026)
- Google Cloud: shared responsibility and shared fate; Security Command Center pricing (search result) and service tiers (search result); muting findings (search result); Marketplace commit drawdown (search result); Model Armor (search result)
Standards, regulators and courts
- CNCF, Falco graduation (Feb 2024, search result); Falco, modern eBPF probe (search result)
- FedRAMP: vulnerability detection and response (2026); Consolidated Rules for 2026 (Jun 2026, search result)
- PCI Security Standards Council, FAQ on targeted risk analysis (search result); Adyen, PCI DSS 4.0 future-dated requirements (search result)
- CISA: BOD 25-01 implementation guidance (Dec 2024, search result); Cyber Safety Review Board report on Storm-0558 (Mar 2024)
- SEC: final rule 33-11216 (2023); litigation release on SolarWinds (Nov 2025, search result); petition 4-856 (2025, search result); Debevoise, Form 8-K tracker, two-year update (May 2026); Hunton, SEC fines four companies (Oct 2024, search result)
- NYDFS: PayPal consent order (Jan 2025, search result); Hunton, Healthplex settlement (Aug 2025, search result); Hogan Lovells, final Part 500 requirements (2025, search result)
- FTC, Chegg complaint (2022, search result); Teiss, FTC finalizes GoDaddy order (2025, search result)
- DORA and UK: Finanstilsynet summary, first list of critical ICT third-party providers (Nov 2025, search result); Regulation Tomorrow, first UK critical third party designations (Jul 2026, search result); Cyber Security and Resilience Bill (search result); ICO, Capita penalty (Oct 2025, search result); Tech Monitor, ICO fines Advanced (search result)
- NIS2: Freshfields, proposed NIS2 amendments (Jan 2026, search result)
- US District Court for Montana, Snowflake MDL 3126; Bloomberg Law, Snowflake loses bids to dismiss (Oct 2025); Bloomberg Law, Advance Auto and Neiman Marcus settle (Dec 2025, search result)
Breach cases
- Capital One: Krebs on Security, what we can learn (Aug 2019, search result); Willkie, OCC fines Capital One $80 million (Aug 2020, search result); Mealey's, $190 million settlement approved (search result); Reinsurance News, $400 million tower (2019, search result)
- Snowflake customers: Mandiant, UNC5537 investigation (Jun 2024); Snowflake, MFA rollout; BankInfoSecurity, AT&T $177 million settlement (search result); OpenClassActions, AT&T final approval pending (Aug 2026, search result); TechRadar, AT&T's reported payment (search result); The Record, guilty plea (Aug 2026, search result)
- Storm-0558: Microsoft, Secure Future Initiative progress report (Nov 2025, search result); The Record, senators on the review board (search result)
- Trivy, the European Commission and LiteLLM: Help Net Security, European Commission cloud breach (Apr 2026, search result); CSO Online, CERT-EU blames the Trivy attack (2026, search result); CyberInsider, 29 Union entities affected (2026, search result); ITPro, LiteLLM compromise (Mar 2026, search result)
- Other cases: Security Affairs, Salesloft Drift token theft (Aug 2025, search result); TechTarget, Microsoft AI researchers expose 38 TB (2023, search result); CyberInsider, LLMjacking costs (search result)
Industry surveys and vendor research
- Verizon, Data Breach Investigations Report (May 2026); nhimg, DBIR 2026 summary (search result); SAFE Security, DBIR 2026 third-party summary (search result); OffSeq, DBIR 2026 key findings (2026)
- Google Cloud, Threat Horizons report H1 2026 (search result)
- IBM Cost of a Data Breach 2026: HIPAA Journal, summary (Jul 2026); Baker Donelson, ten takeaways (2026)
- Cyentia Institute and Kenna Security, Prioritization to Prediction, volume 3 (2019)
- Datadog: State of Cloud Security (Oct 2025); State of DevSecOps 2025 (search result)
- Wiz: State of Cloud Risk 2026 (2026); State of AI in the Cloud (2025, search result); introducing Green Agent (Mar 2026)
- Tenable, 2025 Cloud Security Risk Report (Jun 2025); Sysdig, 2025 usage report (Mar 2025, search result); Palo Alto Unit 42, 2025 cloud security alert trends (Apr 2025, search result)
- Veracode, State of Software Security 2026 (Feb 2026); GitGuardian, State of Secrets Sprawl 2025 (search result)
- Infosecurity Magazine, Microsoft on unused cloud permissions (2023, search result); Cloud Security Alliance, posture management survey (Sep 2021, search result); Security Boulevard, a vendor's summary of Gartner's 2025 CNAPP market guide (Sep 2025)
- AI evidence: SSRN, Security Copilot randomized trial (search result); arXiv, CyberSOCEval (2025, search result); Infosecurity Magazine, Anthropic's GTG-1002 report (search result)
Market, companies and deals
- Dell'Oro: CNAPP to reach $12.9 billion by 2030 (Jan 2026)
- Google and Wiz: Google, completes acquisition of Wiz (Mar 2026, search result); Cleary Gottlieb, Google completes Wiz (Mar 2026, search result); Wiz, runtime sensor (search result); TechCrunch, Wiz's ARR target (Oct 2024, search result); Techzine, Wiz stays deployed on AWS (May 2025); BankInfoSecurity, Orca and Wiz end their patent suits (Jan 2026); PrivSource, Wiz and Dazz (Nov 2024, search result)
- Palo Alto Networks: FY2026 10-K (Sep 2026); Constellation Research, Cortex Cloud launch (Feb 2025, search result); SecurityWeek, Protect AI acquisition (Apr 2025, search result)
- CrowdStrike: Q2 FY2027 results (Aug 2026); MLQ, cloud security ARR (Aug 2026)
- Tenable: SecurityWeek, Ermetic acquisition (2023, search result); Techleap, Vulcan Cyber acquisition (Jan 2025, search result)
- Orca, Fortinet and Lacework: Globes, Orca layoffs (Jan 2024, search result); ChannelWeb, Fortinet completes Lacework acquisition (Aug 2024, search result)
- Runtime vendors: SecurityWeek, Sysdig raises $350 million (Dec 2021, search result); Pulse 2.0, Upwind Series B (Jan 2026, search result); Runtime Wire, Upwind raising at $3.8 billion (Sep 2026, search result); Calcalist, Aqua Security coverage (2024-2025, search result); MarketBeat, SentinelOne Q2 call (Aug 2026, search result); Datadog, cloud security pricing
- Code and supply chain: Sacra, Snyk at $326 million ARR (Feb 2026, search result); Snyk, plans; Sacra, Chainguard (search result)
- Identity, AI security and data security deals: 24/7 Wall St., the biggest buyers in cybersecurity (Oct 2026); Globes, Cisco to acquire Astrix (May 2026, search result); Globes, Check Point and Lakera (Sep 2025, search result); Channel Insider, September 2025 M&A recap (search result); Globes, Noma raises $100 million (Jul 2025, search result); ValueAdd VC, Cyera at $12 billion (Jun 2026, search result)
- Buyer data and marketplace terms: Vendr, Wiz buyer guide (search result); Redress Compliance, AWS commitment offset for marketplace purchases (search result)
Insurance
- Business Insurance, Munich Re on market size (search result); WTW, Lloyd's state-backed attack exclusions (Sep 2022); Insurance Insider, CyberCube estimate for the AWS outage (Oct 2025, search result); SiliconANGLE, Google Cloud and cyber insurers (Apr 2025, search result)
Field Guides are learning notes, not legal or compliance advice. Rules and fees change; check the cited primary sources before you act on anything here.