Skip to main content
Has your work email already leaked?Run the 10-second check
Glossary

CWPP Cloud Workload Protection Platform

What is CWPP?

Runtime protection for cloud compute, containers and serverless functions.

A workload here means anything that runs: virtual machines, containers, Kubernetes pods and serverless functions, across cloud providers and on-premises hosts. A CWPP protects those at runtime, watching process behavior, file integrity, network connections and privilege changes while the workload is live, and intervening when something deviates from what the workload is supposed to do.

That is a different job from scanning. Image scanning and infrastructure-as-code checks catch known-vulnerable packages and bad configuration before anything is deployed, which is valuable and insufficient: an image can be clean at build time and compromised at run time through a newly disclosed vulnerability, a supply-chain dependency or stolen credentials. Runtime protection is what covers the window between deployment and the next rebuild.

Container and serverless workloads make this harder, because they are short-lived and numerous. A function may exist for a few hundred milliseconds, which is no time at all for a human to intervene, so detection and response have to be automated at the platform layer and reviewed by analysts afterwards. Vijilan delivers runtime coverage for cloud workloads as part of Managed Cloud Security.

How Vijilan covers this
See Managed Cloud Security

Common questions

What does CWPP stand for?

CWPP stands for Cloud Workload Protection Platform. It describes security tooling that protects running workloads, including virtual machines, containers, Kubernetes and serverless functions, wherever they execute.

What is the difference between CWPP and CSPM?

CSPM secures the configuration of the cloud environment, asking whether resources are set up safely. CWPP secures what runs inside it, asking whether a workload is behaving as it should right now. One is about the shape of the building, the other about what is happening in the rooms.

Is CWPP part of CNAPP?

Yes. CNAPP, the Cloud-Native Application Protection Platform, is the umbrella category that combines posture management, entitlement management, vulnerability and image scanning, and workload protection into a single platform. CWPP is the runtime component of that bundle.

Glossary

CWPP is one signal.
We watch the rest.

Vijilan runs a 24/7 SOC across endpoint, identity, cloud, network, SaaS and mobile, and acts on what it finds rather than forwarding an alert.