A cloud workload protection platform (CWPP) is security software that protects the workloads running in cloud and hybrid environments: virtual machines, containers, Kubernetes clusters and serverless functions. It finds vulnerabilities and malware in those workloads and, in many products, watches them while they run to detect and block attacks. CWPP is one of the two core building blocks of a cloud-native application protection platform (CNAPP), and is also sold on its own.
At a glance
- A CWPP protects workloads: virtual machines, containers and serverless functions, wherever they run.
- Common capabilities are vulnerability scanning, malware detection and visibility into what each workload is running.
- Many products add runtime threat detection, application control, file integrity monitoring and network segmentation.
- Products may use agents, agentless scanning through cloud APIs, or both.
- Many cover public cloud, private cloud and on-premises servers, which suits hybrid environments.
What problem it solves
Cloud workloads look very different from office laptops. Servers are created and destroyed automatically, containers may live for minutes, and serverless functions have no server you can install software on. Traditional endpoint antivirus was built for long-running machines with a person at the keyboard, and it struggles with this model. Meanwhile, attackers target cloud workloads to steal data, mine cryptocurrency or use them as a foothold, often through an unpatched vulnerability in an internet-facing application.
A CWPP gives security teams consistent protection across these workload types. It shows which workloads have critical vulnerabilities or malware, which are exposed, and, with runtime protection, what is happening inside them right now. Because many organizations run workloads across several clouds and their own data centers, a CWPP can apply one policy across environments rather than relying on each platform’s native tools.
How it works
Discovery and inventory. The platform connects to cloud accounts, virtualization platforms and container orchestrators to find workloads and record what software each one runs.
Vulnerability and malware scanning. It scans operating systems, packages and application libraries for known vulnerabilities and malware. Many products scan container images in registries and build pipelines before deployment, so issues are caught earlier.
Runtime protection. Agents or container sensors watch processes, file changes and network connections on running workloads. Depending on the product, they detect suspicious behavior, block it, or enforce rules such as allowing only expected processes to run. For serverless functions, runtime coverage is usually more limited.
Segmentation and hardening. Many CWPPs map traffic between workloads and support microsegmentation policies, plus checks against hardening benchmarks for operating systems and Kubernetes.
Alerting and integration. Findings go to the CWPP console, ticketing systems, a SIEM or a managed detection service, often with context about how exposed and important each workload is.
When it matters for buyers
- When running production applications in cloud infrastructure. Under the shared responsibility model, securing the workload is your job, not the cloud provider’s. See our public cloud and private cloud overviews.
- When adopting containers and Kubernetes. Container environments need tools built for short-lived workloads and image scanning.
- When workloads span several environments. One tool across clouds and data centers avoids gaps between native tools.
- When considering a CNAPP. Decide whether you need a full platform or a focused workload protection tool.
- When compliance requires vulnerability management and monitoring on servers. CWPP reports can support that evidence.
Questions to ask vendors
- Which workload types do you protect: virtual machines, containers, Kubernetes, serverless?
- Which clouds, hypervisors, operating systems and container platforms are supported?
- What is agentless, what needs an agent, and what does each give us?
- Can you block threats at runtime, or only detect and alert?
- Do you scan container images and infrastructure code before deployment?
- How is pricing calculated: per workload, per host, per container or by cloud spend?
- How do you integrate with our endpoint security, SIEM and managed detection provider?
How it differs from CNAPP
A CWPP protects the workloads themselves. A CNAPP is a broader platform that combines workload protection with cloud security posture management (CSPM), which checks how cloud accounts and services are configured, and, depending on the vendor, cloud infrastructure entitlement management (CIEM), code scanning and data security. The CNAPP connects those findings so teams can see, for example, that a vulnerable workload is also internet-exposed and has broad permissions. Some organizations buy CWPP alone, especially for hybrid or on-premises workloads, while others get it as part of a CNAPP. Endpoint detection and response (EDR) overlaps for traditional servers, and some vendors sell one agent for both.
