ZeroHour
GBHackerspublished ()ingested Kavichselvan
Part of a story covered by 12 sources: “Major Cyber Threat Detection Vendors Shift from MITRE to UK Testing Program” — merged summary and timeline →

12 Serverless Security Options Compared (2026): Features & Pricing

infoIndustryimportance 15
AI summary · glm-5.3-flash

A buyer-focused comparison of twelve serverless security offerings concludes no standalone SKU is worth buying in 2026, with function protection bundled inside CNAPP contracts.

The scorecard compares twelve serverless security options on function-protection depth, pricing visibility, platform attach economics, multi-runtime coverage, and vendor viability. Microsoft Defender for Cloud tops the weighted scores at 4.75, with Prisma Cloud at 4.60 and Datadog at 4.55 noted for publishing clean per-function rates. The piece warns that Thundra and Epsagon are defunct and that most vendors bill functions inside platform units where costs are hard to see. It also references the Aqua Security Trivy supply chain incident and Google's finalized acquisition of Wiz as market context.

  • Microsoft Defender for Cloud scores highest at 4.75 on the buyer-side scorecard.
  • Datadog is the only vendor publishing clean per-function pricing.
  • Thundra and Epsagon are defunct; lists still selling them are stale.
  • Most vendors bill serverless functions inside CNAPP or observability platform units.
Full article2,052 words · extracted from gbhackers.com · click to collapse

Quick Answer: There is no standalone serverless-security SKU worth buying in 2026 functions are a line item inside CNAPP or observability contracts.

Datadog publishes per-function rates (the category’s only clean anchor); Prisma Cloud carries the deepest lineage (PureSec); Aqua, Sysdig, Wiz, CloudGuard, and Fortinet (Lacework) bill functions inside platform units.

Graveyard warning: Thundra and Epsagon are gone any list still selling them is stale.

Serverless flipped the security cost model: no servers to license, but every function is an IAM role, a dependency tree, and an event surface and vendors have quietly moved that risk into platform pricing where it’s hard to see what you pay.

As a result, security vendors have absorbed serverless protections directly into Cloud-Native Application Protection Platforms (CNAPPs)
where it becomes difficult to determine what you are actually paying for function protection versus traditional cloud misconfigurations and exposed permissions.

This scorecard follows the money across twelve names from legacy shortlists: who bills what unit for function coverage, which observability path publishes real rates, where AppSec (Contrast) genuinely fits, and which two vendors no longer exist to invoice you at all.

Scores are editorial and independent nobody paid to be here, including the dead. Pricing by structure only.

Table of Contents

1. How We Scored

2. The Scorecard

3. The 12 Names: Features & Pricing Mechanics

4. Procurement Comparison

5. Buying Guide

6. Cost-Focused FAQ

How We Scored

Five buyer-side criteria: Function-protection depth (25%) permissions, dependencies, runtime; Pricing visibility (25%) can you see the function line item; Platform attach economics (20%); Multi-runtime coverage (15%) Lambda/Azure Functions/Cloud Functions; Vendor viability (15%) this category buried companies. Defunct entries score status, not features.

The Scorecard

NameDepthPrice visibilityAttach economicsMulti-runtimeViabilityWeightedPricing structure
Prisma Cloud535554.60Credits
Datadog454554.55Published/function
Wiz435554.35Per workload
Aqua434454.00Per workload
Sysdig434454.00Per workload
Check Point CloudGuard434454.00Per asset
Fortinet (Lacework)434443.85Quote/Fabric
Snyk453454.15Published/dev
Contrast Security3 (AppSec lane)33453.45Per app/dev
Rapid7 InsightCloudSec454554.55Resource-based / quote
Qualys444454.20Subscription / asset
Microsoft Defender for Cloud455554.75Consumption / resource

The 12 Names: Features & Pricing Mechanics

1. Aqua Security

Aqua Security
Aqua Security

What you get. Serverless function scanning (vulnerable open-source dependencies, embedded secrets, and over-permissive execution roles) within a container-lifecycle security architecture, maintaining resilience following investigations into the Aqua Security Trivy scanner supply chain incident.

How it’s priced. Functions count toward workload units.

Procurement notes: confirm the function-to-workload conversion ratio fractional vs full-unit counting changes serverless-heavy bills materially.

Buy when: Aqua already covers your containers.

Push back on: full-unit billing for tiny functions.

2. Snyk

Snyk
Snyk

What you get. Pre-deployment dependency and Infrastructure-as-Code (IaC) security embedded directly inside developer pipelines, preventing flawed components and supply chain vulnerabilities in automated CI/CD workflows before deployment.

How it’s priced. Published per-developer; functions don’t change the bill.

Procurement notes: for serverless-heavy shops, per-dev pricing decouples cost from function sprawl entirely a structural advantage worth modeling.

Buy when: shift-left covers most serverless risk (it often does).

Push back on: dev-count definitions.

3. Palo Alto (Prisma Cloud)

Palo Alto (Prisma Cloud)

What you get. Deep function-level protection (PureSec lineage) delivering runtime event-injection inspection, automated least-privilege role generation, and cross-cloud coverage evaluated across enterprise cloud security solutions.

How it’s priced. Serverless Defenders consume credits.

Procurement notes: ask specifically what a serverless Defender costs in credits versus a host Defender the ratio is negotiable and rarely volunteered.

Buy when: function-level runtime defense is a hard requirement.

Push back on: credit opacity on function units.

4. Rapid7 InsightCloudSec

Rapid7 InsightCloudSec
Rapid7 InsightCloudSec

What you get. A cloud-native security platform providing real-time multicloud visibility, risk prioritization, CIEM, compliance management, IaC security, and automated remediation. It also provides dedicated serverless-function visibility and controls for AWS Lambda, including checks for cross-account access, code signing, and IAM execution roles.

How it’s priced. Consumption-based pricing by monitored cloud resources, with published tiers; Rapid7 currently lists pricing starting at $5,775/month for up to 500 instances.

Procurement notes: clearer pricing than a pure quote-only model, with unlimited managed clouds, containers, users, compliance packs, and automated remediation included in subscriptions.

Buy when: multicloud posture, compliance, CIEM, and automated remediation need to be consolidated into one platform.

Push back on: resource-based billing if your environment has a large and rapidly changing cloud-resource footprint.

5. Wiz

Wiz
Wiz

What you get. Agentless inventory, secret identification, and dependency risk mapping across AWS Lambda, Azure Functions, and GCP Cloud Functions, with platform dynamics shaped by Google’s finalized acquisition of Wiz.

How it’s priced. Functions inside per-workload tiers (typically fractional units).

Procurement notes: get the fractional-unit math in writing; serverless-heavy estates can negotiate function bundling.

Buy when: Wiz is your platform.

Push back on: function-count true-ups.

6. Qualys

 Qualys
Qualys

What you get. A broad cloud-security platform with serverless security capabilities, including AWS Lambda vulnerability scanning
, dependency analysis, and risk visibility across cloud workloads and runtime compute.

How it’s priced. Quote-based, typically structured around Qualys platform subscriptions and the assets or workloads being protected.

Procurement notes: strong fit for organizations already using Qualys for vulnerability management and asset discovery; validate exactly how Lambda/function coverage is counted in the commercial proposal.

Buy when: you want serverless security alongside an established vulnerability and cloud-security platform.

Push back on: expanding the Qualys footprint when your requirement is limited specifically to serverless protection.

7. Sysdig

Sysdig
Sysdig

What you get. FRuntime threat detection and posture management built for AWS Fargate and containerized serverless tasks, with the Sysdig Threat Research Team tracking active cloud compromises to detect anomalous execution.

How it’s priced. Per workload.

Procurement notes: Fargate task counting is the line to scrutinize tasks churn fast and bills follow.

Buy when: Fargate-heavy estates.

Push back on: task-hour billing surprises.

8. Microsoft Defender for Cloud

 Microsoft Defender for Cloud
Microsoft Defender for Cloud

What you get. A broad CNAPP platform covering multicloud and hybrid environments, with CSPM, DevOps security, workload protection, and serverless security for resources such as Azure Functions and AWS Lambda.

How it’s priced. Pay-as-you-go, with billing varying by enabled Defender plans and resource type. Microsoft also offers prepaid Defender for Cloud Commit Units for eligible workloads.

Procurement notes: strong fit for Microsoft/Azure estates and organizations consolidating cloud posture and workload protection under an existing Microsoft security agreement. Serverless CSPM billing counts 8 functions/web apps as 1 billable resource.

Buy when: Azure/multicloud coverage + Microsoft security-stack consolidation.

Push back on: complex resource-based billing if serverless workloads are numerous or highly dynamic.

9. Check Point (CloudGuard)

 Check Point (CloudGuard)
Check Point (CloudGuard)

What you get. Protego-lineage serverless posture management and runtime protection integrated into Check Point’s prevention fabric, addressing enterprise infrastructure and critical Check Point management platform updates.

How it’s priced. Per asset within CloudGuard.

Procurement notes: Infinity ELA customers can often absorb function coverage nearly free ask for the line item anyway.

Buy when: Check Point incumbency.

Push back on: ELA opacity.

10. Contrast Security

Contrast Security
Contrast Security

What you get. AppSec lane, honestly labeled: Code-level application security (IAST and RASP) instrumenting serverless execution directly, evaluated among top application security testing companies to block SQL injection and broken access logic from within the application layer.

How it’s priced. Per application/developer.

Procurement notes: buy it from the AppSec budget for code-level depth; don’t double-count it against CNAPP function posture.

Buy when: application-layer serverless risk (injection, logic) leads.

Push back on: category confusion in scoping.

11. Datadog

 Datadog
Datadog

What you get. Deep AWS Lambda and serverless observability combined with threat detection on incoming function traffic, backed by Datadog research into exploitable vulnerabilities in deployed services.

How it’s priced. Published per-function/month rates.

Procurement notes: this rate card is your universal anchor bring it to every CNAPP conversation about function counting.

Buy when: Datadog owns your observability.

Push back on: ingestion-cost creep alongside function fees.

12. Fortinet (Lacework FortiCNAPP)

 Fortinet (Lacework FortiCNAPP)
Fortinet (Lacework FortiCNAPP)

What you get. Polygraph behavioral anomaly detection mapped across cloud accounts and serverless executions, connecting telemetry across the Fortinet Security Fabric and enterprise appliances.

How it’s priced. Quote/Fabric bundles.

Procurement notes: Fortinet-fabric estates should bundle; others should demand the anomaly-detection value case for functions specifically.

Buy when: Fortinet consolidation.

Push back on: fabric lock for a niche need.

Procurement Comparison

NameStatusFunction billing unitPublished?Attach home
AquaActiveWorkload conversionNoContainer estate
SnykActiveDeveloper (decoupled)YesDev budget
Prisma CloudActiveCredits (Defender)PartialPalo Alto ELA
Rapid7 InsightCloudSecActiveResource-basedYesRapid7 cloud-security platform
WizActiveFractional workloadNoWiz tier
QualysActiveSubscription / assetPartialVulnerability & cloud-security estate
SysdigActiveWorkload/taskPartialContainer estate
Microsoft Defender for CloudActiveConsumption / resourceYesMicrosoft security / Azure estate
CloudGuardActiveAssetNoInfinity ELA
ContrastActive (AppSec)App/developerPartialAppSec budget
DatadogActiveFunction (published)Yes — fullObservability
Fortinet (Lacework)ActiveQuoteNoFabric

Buying Guide

Refuse the standalone SKU that doesn’t exist. Serverless security is a clause in a CNAPP or observability contract negotiate it there: function-to-unit conversion (Wiz/Aqua), Defender credit ratios (Prisma), task counting (Sysdig).

Anchor on Datadog’s published per-function rates the one visible price in the category disciplines every hidden one.

Route code-level risk to the right budget: Snyk (pre-deploy, per-dev) and Contrast (runtime AppSec) solve different layers than cloud posture fund them accordingly, don’t double-buy.

Shift security left into build pipelines: Address third-party open-source vulnerabilities before code reaches production by integrating scanning with leading DevSecOps platforms and secure CI/CD tools.

And run the graveyard check: Thundra and Epsagon on any proposal, deck, or “2026 top tools” list means the source predates the market’s consolidation including, ideally, checking this article’s own date.

Free floor stays free: per-function IAM hygiene, native scanning, and CI dependency checks cover startups without a single new line item.

Cost-Focused FAQ

How much does serverless security cost?

Usually nothing separable: functions ride CNAPP units (fractional workloads, credits, assets) or observability bills. Datadog is the exception with published per-function rates; Snyk decouples cost entirely via per-developer pricing.

Which vendor publishes serverless security pricing?

Datadog (per-function/month) fully, Snyk (per-developer tiers) by proxy. Every CNAPP hides function economics inside platform units — use the published pair as negotiation anchors.

Are Thundra and Epsagon still available?

No. Epsagon was acquired by Cisco (2021) and sunset as a standalone product; Thundra faded from the market. Their appearance on a list is a reliable staleness indicator.

What’s the cheapest way to secure Lambda?

Free discipline: least-privilege IAM per function, dependency scanning in CI (Snyk free tier), secrets out of env vars, and native tooling. Paid depth (Prisma’s runtime defense) is for regulated, function-heavy estates.

How do CNAPPs count functions for billing?

Inconsistently fractional workload units (often 10:1 or similar), credit consumption per Defender, or asset counts. Get the exact conversion in writing; serverless-heavy estates can and should negotiate it.

Is Contrast Security a serverless security tool?

It’s runtime application security (IAST lineage) that covers serverless code the application layer, not cloud posture. Fund it from AppSec for injection/logic risk; keep CNAPP for permissions/config.

Bottom Line

Serverless security in 2026 is a contract clause, a rate card, and a graveyard. Prisma sells the deepest function defense inside credits; Wiz, Aqua, Sysdig, CloudGuard, and Fortinet (Lacework) bill functions inside platform units worth interrogating; Datadog publishes the only real price; Snyk and Contrast solve the code layer from different budgets; Cloud Defense needs diligence; Thundra and Epsagon need obituaries, not evaluations.

Anchor on the published rates, negotiate the conversion math, and let the graveyard date-stamp every list you read.

More on GBHackers:

•  Best CNAPP Platforms, Compared and Priced

• Best CWPP Solutions, Compared and Priced

• Best Container Security Tools, Compared and Priced

• Best AWS Security Tools, Compared and Priced

• Best Kubernetes Security Tools, Compared and Priced

• Best CIEM Tools, Compared and Priced

• Best DevSecOps Tools, Compared and Priced

• Best API Security Tools, Compared and Priced

• Best Secrets Management Tools, Compared and Priced

• Best Cybersecurity Companies

•  Best Zero Trust Solutions

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/best-serverless-security-compared/