TL;DR: The 2025 Latio Cloud Security Market Report says teams are moving beyond one-size-fits-all CNAPPs toward AST, CTEM, and CADR, with 65% prioritising AI posture management and 53% prioritising application detection and response, according to Cyera. The governance signal is clear: posture confidence is no longer enough when runtime exposure spans data, apps, and workloads.
Editorial analysis by NHI Mgmt Group, based on content published by Cyera: “2025 Latio Cloud Security Market Report”.
Key questions
Q: How should teams choose between runtime-first and posture-led security tools?
A: Start with where your risk actually lives.
Q: Why do posture tools still leave cloud teams exposed at runtime?
A: Because posture tools mostly describe state, not behaviour.
Q: What are the signs that a cloud security programme needs CTEM or ADR?
A: Common signs include confidence in posture reporting but weak visibility into live application activity, unclear ownership of exposure validation, and response processes that only begin after a finding has already been summarised.
Practitioner guidance
- Separate posture, exposure and runtime responsibilities Document which team and control owns configuration drift, exposure validation and live detection so the programme does not assume one platform covers all three.
- Map AI workloads to runtime decision points Identify where AI systems access data, call tools, or interact with cloud services and make those points visible in identity and security workflows.
- Evaluate runtime controls against application paths Test whether current detection and response tooling can observe activity across APIs, containers, workloads and application sessions rather than only summarising posture findings.
Bottom line: The market signal is not that posture is obsolete, but that posture alone no longer defines control coverage in cloud and AI environments.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Runtime-first security is becoming the practical answer to cloud exposure, not a niche preference. The report shows buyers moving away from all-in-one platform thinking toward controls that distinguish posture, exposure management and runtime response. That shift reflects a governance reality: cloud risk now appears at execution time as often as it appears in configuration drift. Practitioners should expect budgets and evaluation criteria to follow that split.
A few things that frame the scale:
- By 2029, 40% of enterprises that successfully implement zero trust within cloud service provider environments will rely on the advanced visibility and control capabilities offered by CNAPP solutions.
A question worth separating out:
Q: How do AI posture management and cloud identity governance overlap?
A: They overlap wherever AI systems access sensitive data, call tools, or operate within cloud environments that depend on identity decisions. The governance issue is whether access, usage and response controls follow the AI system into runtime rather than stopping at approval time.
👉 Read our full editorial: Cloud security market shifts toward runtime-first controls for AI