Lacework
Cloud security and workload protection platform
Lacework is a cloud security platform that uses behavioral anomaly detection to identify threats and misconfigurations across cloud accounts, containers, and workloads. It is known for its Polygraph technology, which builds a baseline…
Definition
Lacework is a cloud security platform that uses behavioral anomaly detection to identify threats and misconfigurations across cloud accounts, containers, and workloads. It is known for its Polygraph technology, which builds a baseline model of normal activity in a customer's environment to surface deviations without relying primarily on predefined rules, and it is now part of Fortinet's security portfolio. It also covers vulnerability scanning and runtime threat detection across the same environments, competing in the cloud-native application protection platform market.
Overview
Lacework is a cloud security platform whose core approach differs from many competitors in that it leans on automated behavioral baselining rather than a large library of hand-written detection rules, addressing the problem of alert fatigue that purely rule-based tools generate in dynamic cloud environments. Its Polygraph feature ingests activity data from cloud accounts, workloads, and Kubernetes clusters, then constructs a model of what normal behavior looks like for that specific environment, flagging deviations such as unusual process execution, anomalous network connections, or unexpected privilege use. Mechanically, the platform covers the now-standard set of cloud-native application protection capabilities: cloud security posture management for configuration drift against compliance benchmarks, vulnerability scanning for container images and hosts, and runtime threat detection for workloads already running in production, all analyzed through the same behavioral model rather than as separately engineered detection paths. Lacework markets this combination as reducing the volume of low-value alerts compared to purely rule-based tools, since a behavioral baseline can filter out expected variation that a static rule set might otherwise flag repeatedly. Where Lacework differs from neighbors like Orca Security or Aqua Security is this reliance on automated baselining as the primary detection mechanism rather than agentless scanning or container-specific runtime enforcement as the lead feature; the trade-off is that building an accurate baseline takes an initial observation period, during which highly variable or seasonal workloads can make the model less immediately reliable than in a steady-state environment. Lacework has gone through notable business changes, including a period of rapid growth followed by a valuation correction and eventual acquisition by Fortinet, which folded its cloud security capabilities into Fortinet's broader security portfolio, a consolidation pattern common in the CNAPP market where point-solution vendors are frequently absorbed by larger security platform companies. In practice, Lacework is used to detect anomalous behavior in dynamic cloud and container environments, reduce alert fatigue compared to rule-based tools, scan container images for vulnerabilities before deployment, monitor Kubernetes clusters for unusual runtime activity, and assess cloud configuration compliance, making it best suited to environments with relatively dynamic workloads rather than ones with highly seasonal or unpredictable traffic patterns that resist stable baselining. Teams comparing Lacework against a rule-based posture tool should weigh the upfront baselining period against the long-term reduction in repetitive alerts, since the behavioral approach trades some initial signal clarity for lower ongoing noise once the model stabilizes. Teams should also plan for an initial tuning period after deployment, during which security staff review early Polygraph findings to confirm the baseline reflects genuinely normal activity rather than an artifact of a temporary migration or unusual one-time event in the environment.
Key Features
- Polygraph behavioral baselining to detect anomalous activity automatically
- Cloud security posture management against compliance benchmarks
- Container and host vulnerability scanning across the build pipeline
- Runtime threat detection for workloads already in production
- Kubernetes-aware monitoring across clusters and namespaces
- Reduced reliance on manually written detection rules
- Now integrated into Fortinet's broader security platform