Cybersecurity

Microsoft Named a Leader in Frost Radar Report on Cloud Workload Protection for 2026

Frost & Sullivan named Microsoft a visionary leader in its 2026 report on cloud workload protection platforms, highlighting Microsoft Defender for Cloud’s capabilities in connecting runtime security with identities, code, and security operations center processes.

2026-08-19
4 min read
9 views
فريق تحرير certi.news
Microsoft Named a Leader in Frost Radar Report on Cloud Workload Protection for 2026

Frost & Sullivan named Microsoft a visionary leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 report, which evaluated the cloud workload protection platforms market. The assessment was based on Microsoft Defender for Cloud’s capabilities to unify runtime protection and connect infrastructure, workload, identity, and application data with security response operations.

According to the article published on the Microsoft Security blog, Frost & Sullivan examined more than 45 qualified vendors and evaluated 20 of them. It also stated that Microsoft is the largest provider of cloud workload protection platforms by revenue, with an estimated share exceeding 22% of the global market. These figures and classifications appear in Microsoft’s presentation of the report, while the organization’s full report remains the primary reference for verifying the details of the methodology and findings.

From Pre-Deployment Scanning to Runtime Protection

The report focuses on a shift in the definition of cloud workload protection. Scanning software images, remediating vulnerabilities, and hardening configurations before deployment remain important practices, but they alone do not reveal risks that emerge after a workload is running. A known vulnerability may become more serious when combined with a misconfigured cloud environment, an identity with excessive privileges, or malicious activity inside a production environment.

Microsoft says Defender for Cloud brings these signals together within a single framework, rather than distributing security posture, workload scanning, activity monitoring, and response across separate tools. The article indicates that the cloud workload protection market is moving toward a model that connects code, cloud, runtime, identity, and the security operations center.

What Does Defender for Cloud Provide in Practice?

The capabilities highlighted in the article include a lightweight eBPF-based sensor for monitoring Kubernetes events, process activity, and network traffic, while linking detections to the MITRE ATT&CK framework. They also include protection for Kubernetes containers on Azure AKS, Amazon EKS, and Google GKE; malware prevention; protection for the EKS Bottlerocket environment; and detection of unauthorized changes to executable files at runtime.

At the prevention level, policies can be applied at the cluster and namespace levels in Kubernetes to prevent high-risk or noncompliant images from running before they reach production. The platform sends runtime data, Kubernetes audit logs, and identity signals to Microsoft Defender XDR and Microsoft Sentinel, allowing incidents to reach security teams with broader context instead of appearing as separate alerts.

Microsoft also connects runtime findings to developer workflows through GitHub Advanced Security and Copilot Autofix, with the aim of routing the issue to the code owner and addressing it at its source. The capabilities mentioned extend to AI workloads, including model scanning, protection against prompt injection, and suspicious-access detection in Azure AI Foundry and Azure OpenAI, alongside AI security posture management in Google Vertex AI and Amazon Bedrock.

Why Does This Assessment Matter?

The report matters to security teams comparing workload protection platforms because it shifts the evaluation standard from the number of alerts and compliance checks to the ability to identify and stop an exploitable path and connect its details to the party capable of remediating it. Microsoft states that Frost & Sullivan expects spending in this market to grow from $6.43 billion in 2025 to approximately $7.95 billion in 2026, with an annual growth rate of 19.1% through 2030.

This result remains an assessment from an analytical firm as conveyed by Microsoft, not an independent certification of the platform’s suitability for every organization. Organizations considering adoption therefore need to review the full report and test the actual coverage of their cloud environments, containers, and AI workloads, as well as their existing integration with security operations center tools.

News source
Microsoft Security Blog
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news