FortiCNAPP (formerly Lacework)
AI-driven cloud security (CNAPP) — formerly Lacework, now part of Fortinet.

About the product
FortiCNAPP (formerly Lacework) is an AI-driven cloud-native application protection platform that helps organizations identify and remediate risks across their cloud infrastructure. It offers Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWPP), providing comprehensive visibility and protection for cloud assets. Its AI-powered threat detection prioritizes critical vulnerabilities and misconfigurations so security teams can focus on the most impactful threats.
Update: Lacework was acquired by Fortinet (completed August 2024) and is now offered as FortiCNAPP.
Features
Cloud security posture management (CSPM), Cloud workload protection (CWPP), AI-powered threat detection, Compliance
Pros
Pros
- Strong CSPM and CWPP capabilities
- AI-powered threat detection with low false positives
- Good compliance automation
- Clear, actionable remediation guidance
Cons
Cons
- Custom pricing only
- Less brand recognition than CrowdStrike or Wiz
- Limited endpoint protection compared to dedicated EDR
Our Verdict
FortiCNAPP (formerly Lacework) provides solid cloud security with behavioral analytics that reduce false positives. Now backed by Fortinet, it's best for organizations needing cloud security with intelligent alerting — especially existing Fortinet customers.

