The latest Latio Cloud Security Market Report confirms what we’ve known for a long time: the future of cloud security isn’t CNAPP. It’s runtime.
Practitioner-driven analyst firm Latio recently unveiled its 2025 Cloud Security Market report. Through rigorous product testing and conversations with practitioners, the report captures a clear inflection point: Cloud Native Application Protection Platforms (CNAPPs), once synonymous with cloud security, are being replaced by a new generation of focused, outcome-oriented technologies.
Chief among them is Cloud Application Detection and Response (CADR) — the category Latio calls “the best workload security capabilities you can get.” We’re proud that Oligo was named a 2025 CADR Leader and Cloud Security Innovator, recognized for our ability to protect cloud workloads and applications at runtime with deep, function-level visibility.
Below, we walk through key takeaways from the report, including:
- Why the market is moving beyond CNAPP
- How Latio defines Cloud Application Detection and Response (CADR)
- Why runtime context is essential to separate real threats from noise
- How Oligo’s runtime protection leads this shift across the cloud, workloads, applications, and AI
Why the Market Is Moving Beyond CNAPP
Over the past few years, CNAPP tools have become broader in scope, but not necessarily better in results. Latio highlights that while most organizations are satisfied with posture and visibility, they remain dissatisfied with runtime and application-layer protection.
In fact:
- 53% of practitioners ranked Application Detection and Response among their most requested features.
- 65% said they want better visibility into how AI models and applications behave at runtime.
- Many security teams reported alert fatigue from posture-heavy tools that lack meaningful context.
These findings echo what we hear from customers every day: today’s dynamic environments don’t need passive visibility – they need active protection where it matters most. The new mandate is clear: protect what’s running, not just what’s deployed.
From Posture to Protection: What CADR Means
The report formally defines Cloud Application Detection and Response (CADR) as the evolution of cloud workload security, unifying runtime visibility, application context, and response capabilities.
CADR represents the convergence of:
- Network, container, OS, and application-layer telemetry
- Function-level reachability to reduce noise and false positives
- Real-time threat detection and mitigation across hybrid environments
In short, CADR operationalizes runtime security and recognizes that most breaches now begin at the application layer. Traditional CNAPPs were built to identify potential risk and the symptoms of successful attacks. CADR unifies real-time context across cloud, workloads, applications, and AI to actually stop them.
Runtime Context Is King
Latio puts it best: “CNAPPs simply didn’t pay enough attention to the application part.” That gap is what runtime awareness finally closes.
Runtime security brings together the signals that once lived in isolation, from infrastructure posture to application behavior and even AI activity, to create a single, coherent understanding of what’s happening in production. It’s not just deeper visibility – it’s context that drives better decisions and faster action.
With runtime context, teams can:
- Focus remediation on vulnerabilities that are actually exploitable
- Eliminate redundant alerts and reduce operational noise
- Align AppSec, CloudSec, and DevOps around what’s really happening
- Confidently adopt AI knowing its behavior can be observed and controlled
Posture management will always be a piece of the puzzle. But runtime security is what makes the picture complete, transforming insight into action and uncertainty into control.
Why Oligo Was Named a CADR Leader
Latio’s analysts highlighted Oligo for delivering “robust runtime protection for cloud services, workloads, and applications of all kinds – whether AI, cloud, web, on-premise, or third-party.”
Our differentiated approach combines:
- Non-intrusive runtime protection across cloud services, applications, workloads, and AI that blocks modern attacks without disrupting performance
- Function-level reachability to prioritize the 1% of vulnerabilities that truly matter
- AI runtime defense, securing models and agents in real time as organizations adopt GenAI and LLM-driven workflows
Latio’s recognition validates Oligo’s founding belief: true security starts with understanding what actually happens at runtime.
Runtime Protection: The Security Backbone
The cloud has unlocked extraordinary innovation, and equally complex risk. Cloud services, workloads, applications, and AI systems are not siloed – they’re dynamic, interdependent, and constantly evolving. As organizations adopt AI-driven development and autonomous services, the attack surface expands in real time.
Cloud Application Detection and Response (CADR) meets these challenges by correlating activity across environments to deliver:
- Active defense that blocks attacks without disrupting critical business services
- Context-aware detection that separates real threats from false positives, even as AI introduces new, adaptive behaviors
- Unified visibility that connects the dots between applications, infrastructure, networks, and AI processes
- Scalability through a lightweight sensor architecture that runs seamlessly in modern, distributed environments
The Latio report makes one thing clear: cloud security’s next decade will be defined by runtime protection: the ability to detect, prioritize, and stop real attacks as they happen.
Oligo’s leadership in CADR reflects the work we’ve done to make that future real. By delivering active, intelligent, and application-aware runtime protection, we help organizations move from observing risk to addressing it, ensuring that innovation in the cloud, and now with AI, happens securely.
This is why runtime is the new foundation of modern security.
It’s how visibility becomes meaningful action.
It’s where cloud, workloads, applications, and AI protection converge.
And it’s how we’re changing the game.
Access the Full 2025 Latio Cloud Security Market Report
The Latio report goes far beyond rankings. It explains why runtime protection is reshaping the industry.
Get the data, see the analysis, and understand why leading organizations are adopting Cloud Application Detection and Response (CADR) to secure what’s running.