Get a Demo
Under Attack?
Upwind is a Visionary Leader in Frost & Sullivan report

Upwind Named a Strong Visionary Leader in Frost & Sullivan’s 2026 Cloud/Application Runtime Security Radar

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>33</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>33</b><br />
Tomer Hadassi July 20, 2026

Upwind Named a Strong Visionary Leader in Frost & Sullivan’s 2026 Cloud/Application Runtime Security Radar

We’re excited to share that Frost & Sullivan has recognized Upwind as a Strong Visionary Leader in the Frost Radar™: Cloud/Application Runtime Security, 2026. This recognition highlights the company’s innovation, growth, and leadership in the emerging Cloud-Native Application Detection and Response (CNADR) market.

For us, the recognition is meaningful not simply because of where Upwind landed on the Radar, but because of what the report says about the future of cloud security.

Cloud environments have fundamentally changed. Static inventories, configuration snapshots, and point-in-time vulnerability scans can identify potential risk, but they can’t determine what is actually exploitable in production. As applications become increasingly distributed across containers, Kubernetes, serverless services, APIs, identities, and AI systems, runtime context has become essential for gaining real-time visibility, prioritizing risk and accelerating response.

Frost & Sullivan sees the industry moving in the same direction.

Banner-Cloud-Application-Run-Time-Security_Upwind

As the report notes:

“Upwind’s runtime cloud security platform is an evolution of modern cloud security, well aligned with the market shift from visibility to active runtime TDR, from static scanning to runtime validation, and from separate posture, workload, API, and application tools to one unified runtime security model.”

The report also highlights the architectural approach that has defined Upwind since day one:

“Instead of starting with static inventory, configuration checks, or vulnerability scanning like other traditional cloud security competitors, Upwind uses runtime data as the single source of truth for its platform operation.”

By correlating runtime behavior across infrastructure, workloads, APIs, applications, identities, and data, organizations can reduce noise, prioritize what is truly exploitable, and respond faster to active threats. Frost & Sullivan specifically cites Upwind’s ability to reduce noisy alerts by as much as 95% through runtime-powered prioritization and correlation.

The report further recognizes Upwind as:

“one of the few credible CNADR vendors, making it a visionary leader that converges CDR, CWPP, and API security.”

For security leaders evaluating the future of cloud security operations, we believe that convergence matters. Attack paths no longer stop at infrastructure or workloads. They move across identities, APIs, applications, and data. Security platforms need the runtime context to follow them.

Beyond technology innovation, Frost & Sullivan also highlighted Upwind’s market momentum, citing more than 4,000% year-over-year growth, adoption across Fortune 50, 100, 200, and 500 organizations, and continued expansion across global enterprises.

We’re honored by the recognition and even more encouraged by what it signals about where cloud security is heading.

Download the Report

The Frost & Sullivan Frost Radar™: Cloud/Application Runtime Security Radar offers valuable insight into the emergence of CNADR, the evolution of runtime security, and the vendors shaping the future of cloud and AI security.

Download the full report to explore Frost & Sullivan’s analysis and learn why Upwind was recognized as a Strong Visionary Leader in cloud and application runtime security.

Contents

Further Reading

API Custom Threat Detection

Upwind brings Custom Detection Policies for APIs

Every API has a different risk profile. An internal billing endpoint and a public-facing authorization endpoint don't fail the same way. They don't get attacked the same way either. A generic ruleset can't account for that. Custom rules can, and now those rules can see sensitive data too. This new release brings two things together…
KSPM-Agentless-Scanning

Complete KSPM: From Pull Request to Production Runtime

Kubernetes environments move fast. Workloads appear and disappear, container images change continuously, services are exposed, permissions evolve, and development teams deploy updates throughout the day. But most cloud security platforms force practitioners to investigate Kubernetes risk through interfaces designed for the broader cloud, leaving teams to manually filter the noise before they can begin investigating…
Upwind MCP Server

Revolutionizing Security Investigations with the Upwind MCP Server

Frontier AI models combined with a rampant rate of new critical vulnerabilities mean speed and context are everything. When a critical production service starts behaving suspiciously, every second spent jumping between different tools and dashboards is a second lost to a potential attacker. At Upwind, we are excited to introduce a game-changer for security teams:…