$ techbeacon▋
Threats

Serverless Security Becomes a Feature of Broader Platforms, Not a Standalone Product

Serverless Security Becomes a Feature of Broader Platforms, Not a Standalone Product

In 2026, organizations seeking to protect serverless workloads are no longer offered a dedicated security product that can be purchased on its own. Instead, protection for functions now appears as a component of larger cloud-native application protection platforms (CNAPP) or observability suites, a shift that reflects the maturing of the market and the difficulty of isolating serverless risk from broader cloud security concerns.

The trend is evident across major vendors. Datadog, for example, is the only provider that still lists a clear per‑function pricing model, making it a useful benchmark for customers trying to compare costs. However, even Datadog’s rates are presented as part of its overall observability contract rather than as a separate SKU, underscoring the broader industry move toward bundled services.

Prisma Cloud, which absorbed PureSec’s serverless lineage, now offers the most extensive set of capabilities for functions, ranging from runtime protection to detailed provenance tracking. The depth of its integration is a legacy of PureSec’s focus on serverless, but the offering is packaged within Prisma’s CNAPP suite, meaning buyers must engage with a larger platform to access those features.

Aqua Security also participates in this bundled approach, positioning its serverless controls alongside container and workload protections. While Aqua’s marketing highlights strong scanning and compliance checks for functions, the pricing and licensing are tied to its broader security suite, leaving enterprises to evaluate the total cost of ownership rather than a simple per‑function fee.

Analysts note that the lack of a standalone serverless security SKU may benefit enterprises that already invest in comprehensive cloud security platforms, as they can leverage existing contracts to extend coverage to functions without additional procurement steps. Conversely, smaller teams or niche use‑cases might find the bundled pricing less transparent, potentially leading to higher spend for limited serverless workloads.

Looking ahead, industry observers expect the integration of serverless protection into CNAPP and observability tools to deepen, with vendors adding more granular telemetry, automated remediation, and AI‑driven risk scoring. As serverless adoption continues to rise, the ability to assess function security within the context of an organization’s entire cloud footprint will likely become a decisive factor in vendor selection.

Source: GBHackers
Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related