AppSecNews
IaC Security Commercial Established

Lacework

by Fortinet

A cloud-native application protection platform that baselines normal cloud and workload behavior and flags deviation, now part of Fortinet's FortiCNAPP.

Visit fortinet.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Lacework in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Product naming after the Fortinet acquisition: confirm current branding and whether the Lacework name is still used
  • Integration list reflects the platform generally; confirm specifics against current vendor documentation

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Lacework's distinguishing technique is behavioral baselining rather than rule matching. It ingests cloud provider control plane logs, workload telemetry from a host agent, and configuration state, then builds a model of what normal looks like for your environment: which processes talk to which endpoints, which identities call which APIs, how containers in a given deployment behave. Deviation from that learned baseline becomes an alert. The design intent is to catch activity nobody wrote a signature for, which requires a learning period first.

Around that core sits the rest of a cloud-native application protection platform: posture assessment of cloud accounts against compliance benchmarks, agentless and agent-based vulnerability scanning of hosts and container images, Kubernetes configuration review, identity and entitlement analysis, and infrastructure as code scanning in pull requests. Findings are correlated into composite alerts rather than presented as a flat list, which is what keeps volume manageable.

Where it fits

This is primarily a production and pre-production control, operated by a cloud security or security operations team. Cloud accounts are connected through provider roles, and workload telemetry requires deploying an agent or enabling agentless collection. The IaC scanning piece reaches earlier, running in CI on Terraform, but the platform's center of gravity is the running environment. You need a triage process: anomaly detection produces findings that require investigation, not fixes a developer can simply close.

Strengths

  • Anomaly detection based on learned behavior surfaces activity that signature and configuration checks structurally cannot see.
  • Correlation across control plane, workload and configuration data means related signals arrive as one investigation rather than several tickets.
  • Broad coverage in one platform reduces the number of consoles a cloud security team has to work across.
  • Compliance reporting against common benchmarks is built in, which handles a recurring audit obligation without a separate tool.

Limitations

  • Behavioral models need time and stable workloads. Environments that change constantly produce more noise, and the first weeks after onboarding are typically heavy on tuning.
  • Agent deployment is an operational commitment across hosts and clusters, and agentless-only coverage sees less.
  • Platform consolidation means lock-in: data, policies and alert history live in the vendor's model, and moving off is a project.
  • The Fortinet acquisition has changed product packaging and naming, so confirm the current shape of the offering before relying on older documentation.

Who it suits

Suited to organizations running substantial multi-account cloud estates with a dedicated cloud security function that can act on behavioral alerts. Not a fit for a small team whose real problem is misconfigured Terraform and unpatched images, which open-source scanners in CI address more directly and with far less operational weight.

Used Lacework? Recommend it under your own name and title.

Recommend this tool