Cloud Security Posture Management: silver bullet or another piece in the cloud puzzle?

As organisations scale their use of cloud platforms, securing these environments becomes increasingly complex. Without the right tools and processes, risks from misconfiguration, resource sprawl and other vulnerabilities can quickly overwhelm even the most capable security teams.
In this blog, we’ll explore the topic of Cloud Security Posture Management (CSPM), and highlight how the capabilities of a good CSPM tool can help organisations to align with our existing cloud guidance.
What is Cloud Security Posture Management?
Cloud Security Posture Management refers to a category of security tools designed to continuously monitor, assess and improve the security posture of cloud environments.
CSPM tools collect data from cloud platforms, including details about the workspaces, resources, services and configurations. This information is evaluated against predefined security policies and established best practises to identify common misconfigurations and other potential weaknesses. These tools often then provide remediation advice to help customers address the issues identified.
Note: CSPM is often conflated with tooling like Data Security Posture Management (DSPM), Cloud Workload Protection Platforms (CWPP) and Cloud Native Application Protection Platforms (CNAPP). While all these solutions aim to improve cloud security, they each specialise in different areas.
- DSPM focuses on identifying and protecting sensitive data
- CWPP provides runtime protection and monitoring for workloads like containers and virtual machines
- CNAPP describes a platform responsible for aggregating data from CSPM, DSPM, CWPP and other cloud security functions
Functionality requirements
The NCSC’s guidance on ‘Using a cloud platform securely’ highlights the key areas that organisations should consider when configuring cloud platforms and services. This includes the use of tooling and automation to help maintain a secure and well-managed cloud estate.
To explore the functionality of CSPM tools, we’ll talk through four key challenges often associated with the secure use of cloud platforms:
For each, we’ll explore the complexities and describe how a good CSPM tool can help organisations to align their use of cloud platforms with many of the security goals we describe in our guidance.
1. Resource visibility
In the cloud, organisations often deploy resources across many workspaces, regions, and platforms. This approach supports security and availability best practices and helps organisations to deliver on their business objectives. However, this diversity can also make it challenging to gather standardised data about the inventory and workspace configurations present across this mix of environments.
The ability to collect accurate inventory data is essential to help organisations understand what they have deployed, and therefore what they must protect. This data can help identify resource sprawl (a form of shadow IT) and support organisations in monitoring the current state of their cloud workspaces for audit and regulatory compliance. It can also be used by security tools to identify risky configurations.
We’ve found that the best CSPM tools:
- make it easy for organisations to review how they’re using cloud platforms, workspaces and resources
- maintain a comprehensive inventory of the resources and configurations associated with each workspace, and make this information available even after a resource has been deleted
- make it clear how resources and configurations are associated with one another (for example, the permissions that each resource could access, or the network paths and services it could reach)
2. Misconfiguration detection
Modern cloud platforms provide organisations with ready access to a vast number of services and capabilities. The shared responsibility model for each platform defines which security controls customers are responsible for, and those that are handled by the trusted cloud provider.
The combination of security controls required by each workload will vary (to meet each organisation's unique security requirements), so spotting unintended configurations can be hard. After all, behaviour deemed ‘undesirable’ in one workspace might be necessary and legitimate behaviour in another.
While some types of misconfiguration are comparatively easy to identify, there are many subtle examples that can be more difficult to properly evaluate. This underlying complexity in many cloud platforms means that customer misconfiguration continues to be a leading cause of cloud breaches.
We’ve found that the best CSPM tools:
- provide a comprehensive set of baseline security detections that customers can adopt as is, or customise to better suit their needs
- promptly identify any common misconfigurations, as well as other potentially unintended or overly risky platform, service or resource configurations
- clearly articulate the issue and associated risks for each finding, ideally in the context of the customer’s individual use of the cloud
- make it clear whether each finding is an ‘operational’ or ‘security’ best practice, to support triage and prioritisation
3. Risk prioritisation
Large and busy cloud estates often generate substantial numbers of security findings. These alerts are typically triaged by central security teams, who must promptly determine the risk and priority of each. Ideally, their decisions would be informed by context like the criticality of the resource and the presence (or absence) of compensating security controls. However, this information is often not readily available to the people who need it.
As a result, security teams often lack the context they need to direct their effort and expertise where it will have the most impact. This can lead to situations where findings affecting production resources are not prioritised over similar findings in development workspaces, or where alerts involving internet‑facing resources don't take precedence over those related to internally accessible systems.
We’ve found that the best CSPM tools:
- help security teams to make accurate and informed decisions about where to focus their time, effort and expertise
- consider wider context when determining the priority and/or severity of each finding, including factors like the sensitivity of the resource or data, ease of misuse or exploitation, scale of potential impact and complexity of remediation
- highlight a small number of the most critical findings, helping to encourage remediation whilst reducing alert and triage fatigue
- support investigation and prioritisation activities through features like attack path mapping or real-time network access checks (to help to identify unintended network exposures)
4. Remediation
Once the most critical findings have been identified, remediation should become the priority. CSPM tools commonly provide written, step-by-step remediation advice to support customers with activities such as reconfiguring resources, implementing additional network controls, removing unnecessary permissions, or patching workloads.
This more manual approach is suited to production workspaces, where remediation should typically only take place through updates to an organisation’s infrastructure as code (IaC) templates. This ensures that security improvements apply consistently to all future deployments and helps minimise the risk of unexpected changes to critical live workloads.
In addition, many tools now also offer automated capabilities designed to resolve certain types of finding in place. This reactive approach is more suited to development workspaces, where platform guardrails for deployments are often less strict. It allows organisations to support experimentation, while still maintaining a baseline level of platform security (by applying ad-hoc fixes to resources and configurations after they’ve been deployed).
We’ve found that the best CSPM tools:
- explain how organisations can reduce the risks associated with each finding, ideally in the context of the customer’s individual use of the cloud
- consider wider platform context when suggesting improvements (for example, to suggest a suitable workspace-level control rather than multiple ad-hoc fixes for common problems)
- encourage remediation through changes to an organisation’s IaC templates or platform-level controls, rather than applying reactive fixes to deployed resources
Maximising the value of CSPM
Deployed in isolation, even the best CSPM tools are unlikely to deliver lasting or meaningful security improvements. Their effectiveness relies on being properly integrated with existing business processes and standard day-to-day security workflows. By considering these factors early, organisations can ensure that security tools complement, rather than complicate, how teams and individuals already work.
In addition, organisations should also consider the following factors:
The market for CSPM tools is diverse and still evolving. It’s a crowded market with tools at varying levels of maturity, so it’s essential to understand the strengths and limitations of each option when selecting an effective CSPM tool.
The most convenient choice for many organisations is the native security tooling built into the cloud platform. These capabilities typically provide an effective CSPM solution, offering tight integration within their own ecosystem, which can simplify access and onboarding. However, they often require deeper platform-specific knowledge to operate and configure, increasing the burden on security teams. They also commonly lack support for data collection and visibility across multi-cloud environments, limiting their use in more complex cloud estates.
There’s also a broad market of third-party and open-source CSPM tools. These solutions typically prioritise visibility across multiple cloud platforms, helping organisations to standardise security checks and consolidate findings. In many cases, these tools integrate with (and even source their data from) the native security tools in each platform. They are often easier to use and adapt, even for teams with limited expertise in a particular cloud provider. However, because they are not tied to a single cloud platform, the process of deploying, integrating and granting access to these tools across an entire cloud estate (and organisation) can be more complex.
CSPM tools can perform different functions across development and production workspaces, helping to deliver security value across the entire cloud estate.
The role of CSPM tools remain broadly consistent in development workspaces. They uncover misconfigurations and other weaknesses, and provide insights into how each workspace is used and maintained. Deployments in these environments can be frequent and varied, so CSPM tools will typically generate new findings regularly throughout their operation.
In contrast, the role of CSPM tools evolves as production workspaces mature. Initially, they can help uncover security issues (much like in development workspaces), encouraging organisations to update their IaC templates and platform guardrails to strengthen future deployments. Beyond this initial phase, CSPM tools typically migrate to an audit and compliance function, monitoring for configuration drift and other unexpected changes in these more constrained environments.
The less secure a cloud platform’s default configuration, the more organisations must rely on CSPM tools and other security capabilities to compensate. By choosing a ‘secure by default’ cloud platform, organisations can reduce this dependency.
This shift allows security tools (and the teams that operate them) to focus on the more complex, customer-specific risk areas, rather than the common platform and service configuration weaknesses that all customers must contend with. This, in turn, enables CSPM tools to deliver more value in the area it matters most.
Other considerations
- To gain confidence in a CSPM tool’s approach to security, organisations should consider using the NCSC’s cloud security principles. Tools with remediation features require particular attention, as they rely on elevated permissions that can directly impact the security posture of cloud environments.
To configure and use a CSPM tool securely, organisations should consider the NCSC’s ‘Using Software as a Service (SaaS) securely’ guidance. Tools are trusted with detailed knowledge of configuration gaps and other security weaknesses, so they must be well managed and protected.
Tools should access cloud workspaces using an authentication mechanism designed for cloud integration, removing the need for long-term credentials. This access should follow the principle of least privilege, which includes using narrowly scoped write permissions for remediation activities.
The severity rating of findings will vary between security tools. If combining data from multiple sources, organisations should aim to standardise or adapt these ratings based on their own risk assessments.
Remember that CSPM is just one part of the wider cloud security ecosystem. For some organisations, the features provided by a CNAPP, CWPP, DSPM or other security capability, might better support their data collection and risk evaluation needs.
To wrap up
Whether organisations use native cloud security tooling, adopt an independent solution, or rely on alternative capabilities that achieve similar outcomes, CSPM can play an important role in maintaining visibility and control across complex cloud environments.
Ultimately, CSPM represents a foundational piece of a broader cloud strategy, designed to operate alongside other security controls and to integrate with existing business processes. It’s not a silver bullet that can solve all cloud security problems, but when a good CSPM tool is used effectively, it can provide organisations with the information they need to make informed and data-driven decisions about the security posture of their cloud estate.


