Cloud security has become a major priority as companies move applications, data, and workloads to cloud platforms. Lacework became one of the most recognized names in cloud security by using artificial intelligence and machine learning to detect threats based on normal behavior instead of relying only on traditional security rules.
Originally launched as an independent cybersecurity company, Lacework built a reputation around automated cloud protection, reducing security noise, and helping teams understand complex cloud environments. In 2024, the company was acquired by Fortinet and its technology became part of FortiCNAPP, Fortinet’s cloud-native application protection platform.
Today, many security teams still search for Lacework because they want to understand its technology, features, migration options, and how its capabilities continue through Fortinet’s security ecosystem.
What Was Lacework and Why Did It Become Popular?
Lacework was a cloud security company focused on protecting modern cloud environments such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud. The company’s main goal was to help organizations detect threats automatically by analyzing large amounts of security data and identifying unusual behavior.
Unlike older security tools that depended heavily on manually created rules and signatures, Lacework used machine learning models to create a baseline of normal activity. When something unusual happened, such as unexpected access, suspicious processes, or risky configuration changes, the platform could identify potential threats quickly.
The company gained significant attention because businesses were struggling with increasing cloud complexity. Security teams needed solutions that could provide visibility across multiple cloud accounts without creating thousands of unnecessary alerts.
The Rise of Lacework as a Cybersecurity Unicorn
Lacework became one of the fastest-growing cybersecurity startups and reached a valuation of approximately $8.3 billion in 2021. Investors viewed the company as a major competitor in the rapidly expanding cloud security market.
Several factors contributed to its growth:
- Growing adoption of cloud infrastructure
- Increasing cybersecurity threats
- Demand for automated security solutions
- Need for better cloud workload visibility
- Rising importance of compliance requirements
However, the cybersecurity market became more competitive. Companies faced changing customer demands, economic pressure, and increased competition from established vendors.
Acquisition by Fortinet and Rebranding
In August 2024, Fortinet acquired Lacework and integrated its technology into the Fortinet Security Fabric. The platform was reintroduced as FortiCNAPP, combining Lacework’s cloud security capabilities with Fortinet’s broader cybersecurity portfolio.
For existing users, this transition meant that Lacework technology continued but under a new product direction. Organizations using Lacework tools needed to understand migration paths, updated services, and how their security operations would change.
How Lacework’s AI-Powered Security Technology Worked

The biggest innovation behind Lacework was its data-driven approach to cloud security. Instead of depending only on predefined rules, the platform continuously analyzed activity across cloud environments.
This allowed security teams to detect threats that traditional systems might miss. For example, if a server normally accessed specific databases but suddenly started communicating with unknown external locations, Lacework could identify this behavior as suspicious.
The platform focused on understanding relationships between users, applications, processes, and cloud resources.
The Polygraph Engine Explained
The Polygraph Engine was one of Lacework’s most important technologies. It used machine learning to create a security model of normal cloud behavior.
Instead of asking:
“Does this activity match a known threat?”
The system focused on:
“Is this activity unusual compared with normal behavior?”
This approach helped reduce alert fatigue by filtering out unnecessary warnings. Lacework claimed its technology could reduce security alerts by up to a 100:1 ratio compared with traditional approaches.
Key benefits included:
- Automated behavioral analysis
- Faster threat identification
- Reduced false positives
- Better cloud visibility
- Less manual investigation work
Cloud-Native Threat Detection
Modern companies often operate across multiple cloud platforms. Managing security manually across AWS, Azure, and Google Cloud can become difficult.
Lacework helped security teams monitor:
- Cloud accounts
- Applications
- Containers
- Kubernetes environments
- User activities
- Workloads
- Infrastructure changes
By continuously collecting and analyzing security data, the platform helped organizations identify vulnerabilities before attackers could exploit them.
Key Lacework Features and Cloud Security Capabilities
Lacework was designed as a complete cloud security platform rather than a single-purpose security tool. Its capabilities covered several important areas of cloud protection.
| Feature | Purpose | Main Benefit |
|---|---|---|
| CNAPP | Combines multiple cloud security functions | Centralized cloud protection |
| CSPM | Finds cloud configuration risks | Prevents security mistakes |
| CWP | Protects workloads and applications | Detects runtime threats |
| Kubernetes Security | Monitors containers | Protects modern applications |
| AI Detection | Finds unusual behavior | Reduces alert overload |
Cloud-Native Application Protection Platform (CNAPP)
A Cloud-Native Application Protection Platform (CNAPP) combines multiple cloud security solutions into one unified system.
Before CNAPP solutions became popular, companies often used separate tools for:
- Cloud configuration security
- Vulnerability management
- Workload protection
- Compliance monitoring
Lacework helped simplify this process by bringing these capabilities together through one platform.
A CNAPP solution provides:
- Cloud visibility
- Risk assessment
- Threat detection
- Compliance support
- Application protection
Cloud Security Posture Management (CSPM)
Cloud misconfigurations are one of the most common causes of security problems. A simple mistake, such as exposing a storage bucket publicly, can create serious risks.
Lacework CSPM capabilities helped organizations:
- Scan cloud infrastructure
- Identify security weaknesses
- Monitor compliance standards
- Detect risky configurations
- Improve security policies
Common compliance frameworks supported by cloud security platforms include:
- SOC 2
- HIPAA
- PCI DSS
- CIS Benchmarks
Cloud Workload Protection (CWP)
Cloud Workload Protection focuses on securing applications and systems while they are running.
Lacework monitored:
- Servers
- Hosts
- Containers
- Kubernetes workloads
- Active processes
This helped detect:
- Malware activity
- Suspicious processes
- Vulnerabilities
- Unauthorized changes
- Zero-day threats
Lacework vs Traditional Cloud Security Solutions
Traditional security tools often depend on fixed rules and known threat databases. While useful, they may struggle with new attack methods and complex cloud environments.
Lacework introduced a more automated approach using behavioral analysis.
| Category | Traditional Security Tools | Lacework Approach |
|---|---|---|
| Detection Method | Rules and signatures | Machine learning behavior analysis |
| Cloud Visibility | Often limited | Multi-cloud monitoring |
| Alerts | Higher volume | Reduced alert noise |
| Management | More manual work | Automated analysis |
| Threat Discovery | Known threats | Known and unusual behaviors |
Why Companies Adopted Lacework
Many organizations selected Lacework because cloud environments were becoming harder to manage.
Major advantages included:
- Better understanding of cloud activity
- Faster security investigations
- Reduced manual monitoring
- Improved compliance visibility
- Protection across multiple cloud providers
For security teams with limited resources, automation helped reduce workload while improving protection.
Lacework Migration and Developer Tools

Although Lacework transitioned into FortiCNAPP, many organizations still need to understand its operational tools and development resources.
Security teams managing existing environments may work with automation systems, command-line tools, and infrastructure templates.
Terraform Provider and Infrastructure Automation
Infrastructure-as-code has become essential for modern cloud operations. The Lacework Terraform Provider allowed developers and DevOps teams to manage security configurations through automated workflows.
Terraform-based security management helps teams:
- Create repeatable cloud security configurations.
- Reduce manual setup errors.
- Maintain consistent policies.
- Integrate security into development pipelines.
This approach supports the idea of DevSecOps, where security becomes part of the software development process.
CLI Tools and Open Source Resources
Command-line tools allow engineers to manage security operations directly from development environments.
These tools help teams:
- Run security checks
- Retrieve compliance information
- Automate workflows
- Integrate security into CI/CD pipelines
Open-source resources and developer repositories also provide additional support for teams working with cloud security technologies.
Lacework After Fortinet: Understanding FortiCNAPP
The acquisition by Fortinet changed the future direction of Lacework technology. Instead of operating as a standalone company, its capabilities became part of Fortinet’s larger cybersecurity ecosystem.
FortiCNAPP combines cloud security features with Fortinet’s existing solutions, creating a broader security approach for enterprises.
What Changed After the Acquisition
The main changes include:
- Lacework branding moved toward FortiCNAPP
- Technology became integrated with Fortinet Security Fabric
- Customers received access to broader security capabilities
- Cloud security became part of a larger enterprise platform
This transition reflects a wider cybersecurity trend where companies prefer integrated platforms instead of managing many disconnected security products.
Who Should Consider FortiCNAPP Today?
FortiCNAPP is designed for organizations that need stronger cloud protection.
It can benefit:
- Enterprise security teams
- Cloud engineers
- DevOps teams
- Compliance departments
- Organizations running multi-cloud environments
Companies managing sensitive data, customer applications, or regulated workloads can benefit from centralized cloud security management.
Conclusion
Lacework played an important role in the evolution of cloud security by introducing behavior-based machine learning and automated threat detection. Its Polygraph Engine, CNAPP capabilities, CSPM features, and workload protection tools helped organizations manage complex cloud environments more effectively.
After Fortinet’s acquisition, Lacework technology continued through FortiCNAPP as part of a broader security ecosystem. For businesses searching for modern cloud protection, understanding Lacework provides valuable insight into how AI-driven cybersecurity continues shaping the future of cloud defense.

