Cloud workload protection platforms (CWPP)
Security for the servers, containers and serverless functions running in AWS, Azure and Google Cloud, rather than the network around them.
Know the exact item? Search above to go straight to it. Or buy from the options below.
| Area | What it covers |
|---|---|
| Runtime protection | Malware and exploit activity inside the running workload |
| Configuration drift | Workloads that move away from their intended secure state |
| Vulnerability detection | Known vulnerabilities in the workload and its container images |
| Container and serverless | Coverage beyond traditional virtual machines |
| Why it is separate | Network security sits outside the workload and cannot see what runs inside it |
What is a cloud workload protection platform?+
CWPP secures the servers, containers and serverless functions running in public cloud, covering runtime protection, configuration drift and vulnerability detection in the workload itself rather than the network around it.
Does my firewall not already cover this?+
No. A firewall inspects traffic entering and leaving the network. It has no visibility inside a cloud workload, which is why CWPP is a separate layer.
Which clouds are covered?+
AWS, Azure and Google Cloud are the common targets. Which you need depends on where your workloads actually run.
Is this the same as cloud security posture management?+
No. CSPM checks your cloud configuration for misconfiguration and exposure. CWPP protects the running workload. They are complementary.

