Dig Security Rounds Out Palo Alto Networks’ Prisma Cloud Strategy

Dig Security Rounds Out Palo Alto Networks’ Prisma Cloud Strategy

Palo Alto Networks was represented by Vinayak Shastri, Product Line Manager, and Mohit Bhasin, Sr. Product Marketing Manager, at Security Field Day 11. Bhasin and Shastri introduced Palo Alto Networks Prisma Cloud as a cloud-native platform for securing applications, data, and infrastructure. Specifically, core functions include obtaining visibility and control, including identifying and remediating misconfigurations and other vulnerabilities, detecting threats by using machine learning (ML)/artificial intelligence (AI), and ensuring compliance. The vision spans “code to cloud”—that is, security across the application lifecycle, including building, deploying, and running applications.

The objective is to reduce and prevent breaches and to provide insight that IT and security teams can then act on. For example, the solution can identify not only that an EC2 instance is considered vulnerable but also the owner and packet that the EC2 instance came from as well as who is responsible for addressing the vulnerability. It is relevant to note that cloud hosting creates particular challenges when it comes to obtaining visibility into vulnerabilities because it causes data proliferation, increases abstraction of application and infrastructure stacks, and often introduces new microservices-based architectures. Additionally, there are a variety of touchpoints into the data, beyond applications themselves. Another issue is so-called “orphaned snapshots” that are created and subsequently not deleted when they are no longer needed. Identifying who is using valuable and sensitive data, and as a result uncovering if there is a misuse occurring, becomes opaque and challenging.

In support of its efforts to address this challenge, Palo Alto Networks acquired Data Security Posture Management (DSPM) provider Dig Security last year, in 2023. Key capabilities that Dig brings to Palo Alto and its Prisma Cloud include data discovery and classification, and risk assessment. The Dig solution is agentless and proxy-less, and it analyzes cloud logs, backups, and snapshots to discover and classify data.

The Dig technology adds value to Prisma Cloud by providing insight into knowing how to protect the data based on what type of data it is. For example, in addition to uncovering a vulnerability such as misconfigured, overly permissive access controls for an EC2 instance that is exposed to the internet, it could identify whether that EC2 instance is connected to an RDS database containing sensitive data. It also could provide granular visibility into not only whether a web application firewall is connected to sensitive data but specifically whether it has access to the sensitive data. Given that lateral movement, and as a result the spread of attacks, happens via the network, this is important. It is also important because security and IT operations teams are strapped with time, and at the same time face the onslaught of increasingly sophisticated cyberattacks. Anything to help them optimize their time and efforts by pinpointing the most critical vulnerabilities will be invaluable.

Customers should know that the Dig platform historically has focused on cloud-hosted resources, including Amazon Web Services (AWS), Azure, Google Cloud Platform, and Microsoft 365. However, on-premises sources – specifically, NFS arrays – are beginning to be supported, as well. Data classification occurs within the source environment, so that customers do not need to incur egress fees as a part of the data classification process. More than 100 data classifiers are supported, and the customer can create their own, as well.

DSPM is garnering attention and investment. In other notable announcements joining Palo Alto Networks’ acquisition of Dig, data protection and security provider Rubrik acquired Laminar last year, and CrowdStrike, provider of a variety of security solutions including Extended Detection and Response (XDR), announced last month its intention to acquire Flow Security. This activity underscores the business criticality of data, and how much attackers are targeting organizations’ most valuable and sensitive data – creating the need for a more proactive and preventative approach. For its part, Palo Alto Networks will differentiate its approach in the space by emphasizing the ability to protect the entire cloud environment, extending from data and infrastructure to also include code and applications themselves, via its “code to cloud” approach.

Disclosure: The Futurum Group is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.

Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of The Futurum Group as a whole.

Other Insights from The Futurum Group:

Rubrik Enhances Protection for Amazon S3 and EKS

Rubrik Files S-1 To Go Public

Rubrik’s AI-Powered Cyber Recovery Minimizes Data Loss and Downtime

Author Information

Krista Case

Krista Case brings over 15 years of experience providing research and advisory services and creating thought leadership content. Her vantage point spans technology and vendor portfolio developments; customer buying behavior trends; and vendor ecosystems, go-to-market positioning, and business models. Her work has appeared in major publications including eWeek, TechTarget and The Register.

Related Insights
The Data Foundation Problem: Why "Bring AI to Your Data" Beats the AI Data Lake
August 3, 2026

The Data Foundation Problem: Why “Bring AI to Your Data” Beats the AI Data Lake

OpenText's Waqas Ahmed and Futurum's Keith Kirkpatrick on why the fastest AI pilots fail for a data-governance reason nobody names in the demo. From Utilizing AI, "Trusted Data Foundations for...
Are Enterprises Ignoring Two-Thirds of Their AI Security Risks?
August 3, 2026

Are Enterprises Ignoring Two-Thirds of Their AI Security Risks?

Snyk's 2026 report reveals enterprises can identify only one-third of their AI attack surface, while agentic AI adoption has nearly doubled—leaving security governance dangerously behind....
N-able's Security Vulnerability Exposes Critical Risks for Legacy Systems
August 3, 2026

N-able’s Security Vulnerability Exposes Critical Risks for Legacy Systems

N-able's N-central breach exposes critical gaps in Software Lifecycle Engineering practices, underscoring the urgent need for robust patch governance and automated security testing across MSP platforms....
OPSWAT Enhances Metascan™ with BKAV Pro: A Major shift for Linux Security?
August 3, 2026

OPSWAT Enhances Metascan™ with BKAV Pro: A Major shift for Linux Security?

OPSWAT integrates BKAV Pro into Metascan Multiscanning Linux packages, expanding threat detection capabilities across 5-engine and 10-engine tiers as enterprise supply chain security investments accelerate....
Thales' 2025 Results Highlight Strategic Shifts in Defense and Cybersecurity
August 2, 2026

Thales’ 2025 Results Highlight Strategic Shifts in Defense and Cybersecurity

Thales presented its 2025 full-year results on March 3, 2026, showcasing how its cybersecurity division aligns with an 11.6% CAGR market growth forecast through 2029, reaching $287.6 billion globally....
Akamai's New Security Framework: A Major shift for AI-Driven Commerce?
August 2, 2026

Akamai’s New Security Framework: A Major shift for AI-Driven Commerce?

Akamai Technologies completes its acquisition of LayerX, a secure enterprise browser provider, to address growing shadow-AI risks and enable enterprises to govern employee AI tool consumption across their security stack....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.