Cloud Security Tools: The Complete List for 2026

Cloud security tools reference chart showing CSPM CIEM CNAPP and CASB categories

Cloud security tools span ten major categories, from posture management to compliance automation, and this list catalogues every one of them with named examples. If tracking what CSPM, CIEM, CWPP and CNAPP actually mean feels impossible, this reference sorts the entire market into one place you can bookmark and return to.

How to Use This Cloud Security Tools List

Every category below links to a dedicated post already covering it in full technical and buying depth elsewhere in this series. This page’s job is entirely different from that depth. It exists to help you quickly locate the right category for your current need, not to repeat what those dedicated posts already explain well.

Here is the direct difference from the platform comparison already published in this series. That post evaluates eight full platforms against each other, ranked by fit and use case. This post catalogues every distinct tool category the cluster has covered, including several that platform comparison never touches at all: network gateways, GRC automation platforms, dedicated SOAR tooling. One post answers which is best for you. This one answers what exists, and where to go to learn more about it.

Navigate by need rather than reading end to end. If you are wrestling with misconfiguration, jump to posture management. If SaaS sprawl is the problem, jump to access and identity. If you already know your categories and want to compare specific full platforms against each other, that evaluative comparison is the better next stop, not this page.

One more thing worth stating plainly before the list starts. This market consolidates fast through acquisition, and several tools commonly cited elsewhere have changed hands recently. Every named example below has been checked against that reality rather than repeated from an older, possibly outdated source.

Top Trending Cloud Security Tool Categories

Here is every category in one table before the detailed breakdown below.

CategoryWhat It DoesExample ToolsRelated Guide
Posture management (CSPM, SSPM, DSPM, CIEM)Scans configuration and entitlements for drift and exposureWiz, Cortex Cloud, Orca, Cyera, BigIDCSPM, SSPM, DSPM, CIEM guides
Access and identity (CASB, IAM, PAM)Governs authentication, access policy and privileged accessNetskope, Okta, Entra ID, DelineaCASB, Cloud IAM guides
Cloud-native protection (CNAPP, CWPP, container)Unifies posture, workload and entitlement risk with correlationWiz, Cortex Cloud, Orca, TrivyCNAPP, CWPP, Container Security guides
Application and code securityScans code, dependencies and IaC before deploymentGitleaks, Checkov, SigstoreCode to Cloud, Application Security guides
Network securitySegments, routes and filters cloud network trafficAWS Shield, Cloud Armor, Security GroupsNetwork security guide
GRC automationContinuously collects compliance evidence across frameworksVanta, Drata, OneTrustAudit guide
Monitoring, SIEM and XDRCorrelates telemetry to detect and investigate threatsSentinel, Google SecOps, GuardDutyMonitoring guide
Automation and SOAROrchestrates automated action across connected systemsCortex XSOAR, TinesAutomation guide
Native cloud provider toolsFirst-party security tooling scoped to one providerAWS, Azure, Google Cloud native stacksProvider-specific guides
AI-powered tools (emerging)Machine learning layered into prioritisation and detectionEmbedded across existing categoriesDedicated AI security guide

Posture Management Tools: CSPM, SSPM, DSPM and CIEM

CSPM

CSPM continuously scans infrastructure configuration for misconfiguration and drift. Wiz, Palo Alto Networks Cortex Cloud, Orca Security, AWS Security Hub, Microsoft Defender for Cloud and Google Security Command Center all deliver this capability, usually as one module within a wider platform today rather than a standalone purchase. The full explainer covering how CSPM actually works lives elsewhere in this series.

SSPM

SSPM continuously scans SaaS application configuration, Microsoft 365, Salesforce, Slack, for that same class of drift and misconfiguration. AppOmni, Obsidian Security and Valence Security are established, independent examples. CrowdStrike Falcon Shield is worth naming specifically here, since it began life as Adaptive Shield before CrowdStrike’s acquisition, a rename worth knowing if you encounter the older name in other research. The full SSPM versus CSPM breakdown lives in its own dedicated post.

DSPM

DSPM discovers and classifies sensitive data across cloud storage, databases and data warehouses, correlating sensitivity with actual exposure. Cyera, BigID, Securiti, Normalyze and Microsoft Purview each deliver this capability. The full DSPM explainer covers how this differs from simply having a data inventory.

CIEM

CIEM calculates actual effective permissions across nested groups, roles and cross-account trust to surface shadow access nobody granted on purpose. AWS IAM Access Analyzer, Microsoft Entra Permissions Management and Google Cloud IAM Recommender are the native starting points. The full CIEM guide covers the entitlement risk this category exists to solve.

Worth naming honestly before moving on: the boundaries between these four categories are blurring in practice, not just in marketing copy. CIEM vendors increasingly add data-sensitivity context that looks a lot like DSPM. DSPM vendors increasingly extend into SaaS coverage that overlaps with SSPM. Do not treat this list as four hard, non-overlapping boxes. Treat it as four distinct jobs that a growing number of platforms now do together.

Access and Identity Tools: CASB and Cloud IAM

CASB discovers shadow IT, enforces DLP across cloud data flows and applies adaptive access policy at the point of connection. Microsoft Defender for Cloud Apps, Netskope, Palo Alto Prisma SASE and Skyhigh Security are established examples. The full CASB guide covers exactly what this category catches that other tools miss, particularly around unsanctioned SaaS apps nobody in IT actually approved.

Cloud IAM platforms are the identity systems governing authentication and authorization across cloud resources. AWS IAM, Microsoft Entra ID, Google Cloud IAM, Okta, Ping Identity and JumpCloud all sit in this category. The full cloud IAM guide covers how identity became the primary control plane this entire series keeps returning to, since almost every other category on this page ultimately depends on identity being right first.

Privileged Access Management is a related identity category worth naming specifically here. PAM extends core IAM with just-in-time and zero-standing-privilege capability for the most sensitive administrative access. Delinea and BeyondTrust remain independent examples. CyberArk, historically named alongside them constantly, is worth a specific correction: Palo Alto Networks completed its acquisition of CyberArk in February 2026, folding privileged access management directly into a much larger security platform rather than leaving it as a standalone purchase.

Cloud-Native Protection Tools: CNAPP, CWPP and Container Security

CNAPP is the consolidated category unifying CSPM, CWPP and CIEM with cross-tool attack path correlation, the single biggest structural trend this entire series keeps naming. Wiz, Palo Alto Networks Cortex Cloud, Orca Security and CrowdStrike Falcon Cloud Security are current, independent examples.

Lacework deserves a direct correction here, since it still gets cited constantly under its old standalone name. Fortinet acquired Lacework in August 2024, and the product now operates as Lacework FortiCNAPP, folded into the wider Fortinet Security Fabric alongside FortiGate and FortiSOAR. If you see Lacework referenced as an independent platform anywhere else, that reference is out of date.

CWPP delivers vulnerability scanning and runtime threat detection for VMs, containers and serverless functions specifically. It is typically delivered as a CNAPP module today rather than a pure standalone purchase, exactly as the dedicated CWPP explainer covers in depth, since very few buyers in 2026 shop for workload protection as an entirely separate line item anymore.

Container and Kubernetes security tools handle image scanning, admission control and runtime protection specific to containerized workloads. Trivy, Grype, Docker Scout, Snyk Container, OPA Gatekeeper and Kyverno are the named examples worth knowing, several of them genuinely free, open source projects rather than commercial products. The full container security guide covers best practices for using several of these together rather than picking just one.

Application and Code Security Tools

Web Application Firewalls and API Gateways inspect and filter malicious traffic at the application and API layer, a distinct job from the network-layer controls covered next in this list. These sit closer to runtime than the tools below them in this section, which mostly act before code ever reaches a live environment at all.

SAST and secrets scanning tools scan source code directly and stop credentials from ever being committed to a repository in the first place. Gitleaks and TruffleHog are widely used, genuinely free examples that plug directly into most existing pipelines.

IaC scanning checks Terraform and CloudFormation templates for misconfiguration before anything is actually provisioned, catching the problem before it ever reaches a live environment. Checkov, tfsec and Terrascan are the named examples, each free to start with.

SCA and artefact signing scan dependencies for known vulnerabilities and cryptographically verify build provenance. Sigstore and Cosign are the named examples here, both open source projects with genuinely wide industry adoption already. Every category in this section gets full treatment in this series’ code to cloud and application security guides.

Network Security Tools for Cloud Environments

Native network gateways, Internet Gateway, NAT Gateway, VPN Gateway and Transit Gateway, are the routing components that actually connect and segment cloud networks, and understanding the difference between them matters more than most teams assume until something breaks. Choosing the wrong gateway type for a given connection is a common, quiet source of the exact misconfiguration this entire cluster keeps warning about.

Native DDoS protection comes built into every major provider. AWS Shield, Azure DDoS Protection and Google Cloud Armor each offer baseline and advanced paid tiers of volumetric attack protection, with the paid tier usually adding financial guarantees and dedicated response support the free tier does not include.

Security Groups and Network ACLs are the stateful and stateless traffic control mechanisms at the resource and subnet level respectively, a distinction worth knowing before you configure either one incorrectly and assume the other is covering the gap. The full network security guide covers all of these in working, practical detail, including exactly when each mechanism is the right one to reach for.

Governance, Risk and Compliance Automation Tools

Dedicated GRC platforms continuously and automatically collect compliance evidence across multiple frameworks simultaneously, rather than making someone assemble that evidence manually in a scramble before every audit. Vanta, Drata, Secureframe and OneTrust are the named examples, each supporting several overlapping frameworks, SOC 2, ISO 27017, HIPAA and more, from the same underlying evidence base.

Provider-native compliance tools cover the same territory scoped to a single cloud. AWS Audit Manager, Microsoft Purview Compliance Manager and Google Security Command Center’s own compliance reporting each work well if your estate genuinely sits on one provider, though multi-cloud organizations tend to outgrow this option quickly. The full audit guide covers how continuous evidence collection changes what an actual audit day looks like, and why it matters far more than the tool label itself.

Monitoring, SIEM and XDR Tools

Cloud-native and cloud-capable SIEM platforms solve a specific problem: traditional SIEM was never built to parse cloud-specific log formats, and organizations migrating to cloud routinely discover their existing SIEM investment needs significant extension to actually work. Microsoft Sentinel, Google Security Operations, cloud-extended Splunk, now a Cisco company since 2024, and Datadog each address this directly.

XDR platforms correlate telemetry across endpoint, network, email and cloud into one detection layer instead of forcing an analyst between separate consoles for each domain. CrowdStrike is the most frequently named example in this specific space.

Native threat detection rounds this category out. AWS GuardDuty, Microsoft Defender for Cloud’s own threat protection and Google Security Command Center’s threat detection capability each provide this natively for their respective platform without a separate vendor relationship. The full monitoring guide covers the operational metrics that actually matter beyond simple detection speed alone, including how fast a team actually responds once something fires.

Automation and SOAR Tools

Native cloud automation runs directly inside each provider’s own tooling. AWS Systems Manager Automation, Azure Logic Apps and Sentinel playbooks, and Google Cloud’s own automated response capability all fall into this category without requiring a separate purchase to get started.

Dedicated SOAR platforms orchestrate action across multiple, otherwise disconnected systems in response to one defined trigger, rather than automating within a single tool alone. The value sits specifically in coordinating several systems’ APIs into one coherent response sequence. Palo Alto Cortex XSOAR, Splunk SOAR and Tines are the named examples. The full automation guide covers which findings are actually safe to hand over to a playbook and which still genuinely need a human reviewing them first.

Native Cloud Provider Security Tools

AWS’s own baseline stack covers Security Hub, GuardDuty, Config, IAM Access Analyzer, Audit Manager and Shield, forming a genuinely workable security foundation for AWS-only environments without a single third-party purchase required to get started.

Microsoft Azure’s equivalent stack covers Defender for Cloud, Entra ID, Sentinel, Purview and Azure DDoS Protection, deeply integrated with the wider Microsoft ecosystem in a way that shows clearly once you are actually inside it, particularly for organizations already running Microsoft 365 across the business.

Google Cloud’s own stack covers Security Command Center, Cloud IAM, Cloud Armor and VPC Service Controls, offering a similarly workable native foundation for teams running predominantly on that platform.

This section stays deliberately brief here. Full platform-specific depth, configuration guidance and native-versus-third-party trade-offs get their own full treatment in dedicated posts covering AWS, Azure and Google Cloud specifically, each still forthcoming in this series and each worth returning to once you know which single provider, if any, dominates your actual footprint.

An Emerging Category Worth Watching: AI-Powered Cloud Security Tools

Machine learning is increasingly embedded across posture prioritization, entitlement analysis and threat detection throughout every category named above, rather than existing as one single, separate tool category of its own. A CSPM platform using AI to rank which misconfiguration actually matters most, or a CIEM tool using it to predict which dormant permission is genuinely risky, is this trend in action already, today, inside tools you may already own.

That is exactly why it earns a brief mention here instead of its own dedicated section in this list. AI capability is a cross-cutting layer increasingly built into CSPM, CIEM and monitoring tools simultaneously, not a category you shop for on its own the way you would shop for a CASB. A dedicated post covering this trend in full detail is coming soon to this series.

How Do You Build a Tool Stack from This List?

Start from your own architecture and risk assessment, not this list. Tool selection should follow identified risk and architectural need, not the other way around, a principle this series has established repeatedly and one worth resisting the temptation to skip when a vendor demo looks impressive.

Most organizations do not buy every category separately anymore. The CNAPP consolidation trend means CSPM, CWPP and CIEM are increasingly one purchase, not three, and DSPM is increasingly joining them as a fourth. Buying all four separately today usually means paying for overlapping capability and running more consoles than your team can realistically keep tuned.

Mapping which of these categories an organization already owns, versus which it genuinely still needs, is the first exercise Cyber Security Solutions Ltd runs in any tool stack review, well before any specific vendor conversation starts. It is remarkable how often this exercise alone surfaces a tool nobody remembered buying, sitting unused, doing a job three other tools already cover.

Use the evaluative platform comparison once you actually know which categories you need. This list tells you what exists. That comparison’s depth helps you choose between specific full platforms once your category needs are already clear. Consider build, buy or managed for every category too, since owning a tool and having the operational capacity to actually run it remain two separate decisions, and the second one is where most tool investments quietly go to waste.

Conclusion

This list will not tell you which specific platform to buy. It tells you what exists, what each category actually solves, and exactly where to go for the depth behind any one of them. Start with your own architecture and risk profile, map that against the categories above, and consolidate wherever CNAPP genuinely lets you.  

Cloud Security Tools and Categories FAQs

FAQs

CSPM scans cloud infrastructure configuration for misconfiguration and drift. SSPM scans SaaS application configuration for that same class of drift instead. DSPM discovers and classifies sensitive data wherever it lives. CIEM calculates effective permissions to surface shadow access nobody intended to grant. Each protects a genuinely different layer, and increasingly all four bundle into one CNAPP platform.

No, not anymore. The market has consolidated significantly over the past few years. CNAPP platforms now typically bundle CSPM, CWPP and CIEM as one single purchase, and increasingly DSPM too. Smaller, more specialized categories like SSPM, CASB and GRC automation are still more often bought as separate, dedicated tools today.

This is a category directory listing every tool type and named examples with links to deeper coverage. The comparison guide evaluates eight specific full platforms against each other by fit and use case. This answers what exists; that guide answers which is best for you.

No, it is not independent anymore. Fortinet acquired Lacework in August 2024. The product is now called Lacework FortiCNAPP and operates inside the wider Fortinet Security Fabric alongside FortiGate and FortiSOAR, rather than continuing on as a separate, standalone company the way it used to.

SIEM collects and correlates security telemetry to surface findings for a human to review. SOAR goes a step further, orchestrating automated action across multiple connected systems, identity, cloud, chat and ticketing, in response to a defined trigger rather than just surfacing an alert.

AWS offers Security Hub, GuardDuty, Config, IAM Access Analyzer and Shield. Azure offers Defender for Cloud, Entra ID, Sentinel and Purview. Google Cloud offers Security Command Center, Cloud IAM, Cloud Armor and VPC Service Controls. Each forms a genuinely workable baseline stack for a single-provider environment without any third-party purchase.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *