Join our Newsletter — 33% off our NHI Course

CNAPP, CIEM and agentic AI: what Forrester’s wave suggests

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Forrester named Orca Security a Strong Performer in The Forrester Wave for CNAPP after 14-vendor evaluation results that highlighted top scores in CSPM, CIEM, agentless cloud workload protection, IaC security, agentic AI and co-pilots, and third-party integrations. CNAPP is now being judged on whether it can connect visibility, identity, and runtime action across cloud and AI workloads, not just surface findings.

Editorial analysis by NHI Mgmt Group, based on content published by Orca Security: “Orca Security: A Strong Performer in the 2026 Forrester Wave™ for Cloud Native Application Protection Solutions”.

Key questions

Q: How should teams respond when CNAPP is expected to govern both cloud access and runtime risk?

A: Treat CNAPP as part of the identity control plane, not just a posture tool.

Q: Why does CIEM matter more when cloud workloads include AI and third-party integrations?

A: Because access graphs become useful only when they explain how identities actually interact with workloads, data, and external dependencies.

Q: What are the signs that a CNAPP programme is still posture-only?

A: The clearest signs are good visibility but weak response, limited entitlement context, and no clear path from detection to enforcement.

Practitioner guidance

  • Audit entitlement graphs for cloud blast radius Review whether your CNAPP can expose excessive access across human users, service accounts, and third-party identities, then tie those findings to remediation ownership.
  • Test runtime enforcement on high-risk workloads Validate that the platform can do more than alert by enforcing policy against privilege escalation, suspicious process activity, or unusual network behaviour in live workloads.
  • Map AI workload telemetry into identity governance Check whether AI-related workload events, access grants, and integrations flow into the same governance workflow used for cloud roles and machine identities.

Bottom line: CNAPP is moving beyond visibility toward identity-aware runtime control, which makes entitlement data and enforcement capability equally important.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 23 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

CNAPP is being evaluated as an identity and action control plane. The significance of this wave is that cloud security platforms are no longer judged mainly on what they can observe. They are being compared on how well they connect entitlement context, workload behaviour, and enforcement decisions across cloud and AI workloads. For identity practitioners, that means CNAPP is moving into the same governance conversation as CIEM, runtime policy, and workload authorisation.

A few things that frame the scale:

A question worth separating out:

Q: What does the move toward agentic AI support mean for cloud security architecture?

A: It means cloud security tools must understand AI-driven execution paths as part of the same governance model used for workloads and identities. Teams need correlation across access, integrations, and runtime signals so AI behaviour is assessed in context, not treated as a separate silo.

👉 Read our full editorial: Cloud-native application protection is shifting toward AI and access control


This post was modified 23 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.