VOOZH about

URL: https://thenewstack.io/why-you-no-longer-need-cloud-security-posture-management/

⇱ Why You No Longer Need Cloud Security Posture Management - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2024-10-29 09:15:35
Why You No Longer Need Cloud Security Posture Management
sponsor-firefly,sponsored-post-contributed,
Cloud Services / Operations / Security

Why You No Longer Need Cloud Security Posture Management

CSPMs are proving to be great for surfacing issues, but addressing them through Infrastructure as Code is where the real power lies.
Oct 29th, 2024 9:15am by Ido Neeman
👁 Featued image for: Why You No Longer Need Cloud Security Posture Management
Image from Aree_S on Shutterstock.
Firefly sponsored this post.

While cloud security posture management (CSPM) tools are everywhere, they are not the right solution for a secure cloud.

Getting your cloud infrastructure under control starts with Infrastructure as Code (IaC). Security best practices and cloud configuration management aren’t just about scanning for vulnerabilities or misconfigurations; they are about establishing a sustainable, scalable and secure cloud environment from the ground up.

Traditional tools like cloud native application protection platforms (CNAPP) and CSPM have played a significant role in optimizing cloud configurations and scanning for security best practices. The cloud security companies behind these platforms have been pioneers in this space, helping organizations identify issues like publicly accessible S3 buckets or identity and access management (IAM) roles without multifactor authentication (MFA), and other known cloud pitfalls and misconfigurations that expose your cloud and organization to unnecessary risk.

However, as cloud environments become more complex, CSPMs are proving to be great for surfacing these issues, but addressing them through IaC is where the real power lies. Eventually, scanning for vulnerabilities is not the goal — it’s the means to keeping our cloud secure and governed. Which means we need to make sure we don’t enslave the entire platform engineering team to chasing security tickets from the scanner’s output.

Imagine all your cloud configurations — from MFA-enforced IAM roles to automated key rotations — being managed through IaC. Not only are they configured securely today, but any changes made in the future will be validated against the same security best practices before deployment. This is what gives you true control over your cloud security. And this is just one example.

If you don’t fix security issues in IaC, the fixes won’t last. Your changes will create drifts, they will not be documented or immutable, and they will be out of scope for testing. The crux of the problem remains in security teams’ dependency on platform teams to generate the IaC, and that’s where automation tools like Firefly help achieve this automatically. The future of cloud security lies in IaC, which is the backbone to ensuring consistency, security and efficiency in dynamic cloud environments.

Why CSPMs Became Popular

In the early stages of cloud adoption, organizations faced a significant challenge: managing and securing a rapidly expanding and complex cloud environment. Traditional security tools weren’t designed to handle the dynamic nature of cloud infrastructure, leading to a gap that needed to be filled. This is where CSPM solutions came into play.

CSPMs became popular for several reasons:

  • Visibility into cloud assets: They provided organizations with much-needed visibility into their cloud resources, configurations and potential vulnerabilities.
  • Automated misconfiguration detection: CSPMs could automatically scan cloud environments to identify misconfigurations, such as publicly accessible S3 buckets or IAM roles without MFA.
  • Compliance assurance: They helped ensure that cloud configurations adhered to industry standards and regulatory requirements by continuously monitoring and reporting compliance status.
  • Risk mitigation: By identifying security gaps early, CSPMs allowed organizations to address issues before they could be exploited by malicious actors.

These tools were essential at a time when the rapid pace of cloud adoption outstripped the ability of organizations to manage security manually. CSPMs filled a critical need by providing automated scanning and reporting capabilities that were otherwise lacking.

This, however, raises a pertinent question. We’ve been using CSPMs for almost a decade now, yet we still have so many vulnerabilities, misconfigurations and alerts being thrown non-stop. Why is that? Because, we aren’t treating the root problem.

The cloud is so complex and built on so many moving parts that security simply can’t be treated only after the fact. We need to establish a secure baseline, with “golden images” of proper architecture and high security standards before deployment and as a shared responsibility of the entire engineering team. We also need to enforce changes to the cloud when it doesn’t meet those criteria. After a secure baseline is established, it’s then possible to closely monitor for drift, and then also quickly remediate it.

The Shift Toward IaC and Policy as Code

As cloud technology matured, so did the strategies for managing it. Organizations began to recognize the limitations of relying solely on CSPMs — particularly, the reactive nature of detecting and remediating issues after deployment. This realization sparked a shift toward infrastructure and policy as code.

By governing cloud infrastructure through code, organizations can prevent and mitigate misconfigurations, drift, ghost assets and more, rather than just detect them. This shift reduces the overhead associated with managing and remediating issues identified by CSPMs.

The Power of IaC

We speak about the power of everything-as-code tirelessly, as we truly believe the “*-as-code” revolution has affected and evolved every single engineering domain, from the systems themselves to how they are secured, scaled and governed.

Just to reiterate the benefits, IaC governs your entire cloud infrastructure through version control, deriving all the same benefits it has brought to other engineering domains.

In the context of security, this includes:

  • Consistent configurations: All deployments follow predefined security best practices.
  • Automated deployments: Changes are made through CI/CD pipelines, reducing the risk of human error.
  • Controlled changes: Unauthorized manual deployments or changes via CLI are minimized.
  • Drift detection: It’s easier to monitor and rectify configuration drift or unmanaged resources.

When you manage your cloud through code, every change is deliberate and traceable. Security checks become an integral part of your deployment pipeline, ensuring that only compliant configurations make it to production.

The Reality of Cloud Deployments

Even the most secure CI/CD pipelines can’t prevent all risks. Manual interventions, command-line changes, or actions by external contractors can introduce vulnerabilities. These changes often bypass standard security checks, leading to a contaminated cloud environment.

IaC addresses this by enforcing strict governance. Since all changes must go through code reviews and automated pipelines, the chances of unauthorized modifications diminish significantly. This not only enhances security but also improves overall operational efficiency.

Moving Beyond Scanning

Simply scanning for misconfigurations is an outdated approach. A decade ago, it was innovative, but today’s cloud environments require proactive measures. CSPM tools add layers of complexity — from having to manage the tool itself, to interpreting the findings, prioritizing the many issues they output, and then, hopefully, manually fixing them.

With IaC, you eliminate many of these steps. Security is baked into your infrastructure from the start. Instead of reacting to problems, you’re preventing them from occurring in the first place.

Injecting CSPM Functionality Into Cloud Asset Management 

As organizations strive for more efficient and integrated approaches to cloud security and governance, cloud asset management is emerging as a core solution. These platforms extend the capabilities of IaC by not only managing and provisioning resources but also by codifying existing assets, detecting drift and misconfigurations, and identifying ghost or unmanaged assets within the cloud environment.

Platforms like Firefly operate by scanning your cloud infrastructure to discover all assets, including those that may have been created outside of your standard IaC pipelines — often referred to as “shadow IT.” Once these assets are identified, the platform codifies them into your IaC framework, bringing them under the same governance and management processes as your existing codebase. This codification ensures that all resources, regardless of their origin, are now managed as code.

By integrating these unmanaged assets into your IaC practices, these platforms enable continuous detection of drift — the divergence between the desired state defined in your code and the actual state in the cloud. They alert you to any unauthorized changes or misconfigurations, allowing for prompt remediation through your established IaC pipelines. This continuous monitoring and enforcement help maintain compliance with security policies and regulatory standards.

Firefly is a Cloud Control Plane that enables DevOps and Platform Engineering teams to scan and discover their entire cloud footprint, detect cloud configuration drifts, classify assets using Policy-as-Code, and manage a single inventory of cloud resources across Multi-Cloud and Kubernetes clusters.
Learn More
The latest from Firefly
TRENDING STORIES
Ido Neeman is CEO and co-founder of Firefly, and the former CEO and co-founder of Nuweba, the fast and secure serverless platform. To the diversity of roles he has held, he brings more than a decade's experience in the elite...
Read more from Ido Neeman
Firefly sponsored this post.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Simply.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.