Cloud security teams rarely suffer from a lack of alerts. Their bigger problem is knowing which alerts matter.
A security scanner might identify thousands of vulnerabilities, while cloud platforms generate configuration warnings, IAM risks, logs, and workload events. Security teams then have to determine which issue threatens production, who owns the affected resource, and how quickly it should be fixed.
That problem is becoming more serious. According to Verizon’s Data Breach Investigations Report, 31% of breaches now begin with exploitation of software vulnerabilities. IBM’s latest research puts the global average cost of a data breach at $4.99 million. IBM also reports that organizations making extensive use of AI and automation in security achieved $1.93 million in average cost savings compared with organizations using neither.
Datadog Cloud Security approaches the problem by connecting security findings with the observability data engineering teams already use to understand applications and infrastructure.
What Is Datadog Cloud Security?
Datadog Cloud Security is a cloud security solution designed to identify vulnerabilities, cloud misconfigurations, identity risks, and compliance issues while connecting those findings to operational context.
According to Datadog’s current Cloud Security documentation, its core capabilities include:
- Misconfigurations: Continuously checks cloud and infrastructure configurations.
- Identity Risks: Identifies risky permissions and entitlement problems across AWS, Azure, and Google Cloud.
- Vulnerabilities: Detects and prioritizes vulnerabilities in hosts, container images, and other cloud workloads.
- Security Inbox: Correlates important findings and helps teams decide what to investigate first.
- Compliance: Maps security controls to recognized frameworks and benchmarks.
Readers familiar with older Datadog announcements may see the name Cloud Security Management (CSM). Datadog’s current product experience is branded primarily as Cloud Security, although CSM terminology still appears in documentation and pricing.
Datadog also offers adjacent products such as Cloud SIEM, Workload Protection, Code Security, and App and API Protection. These extend security beyond the core Cloud Security capabilities.
If cloud terminology itself is unfamiliar, start with Digital Exclude’s beginner guide to cloud computing before evaluating cloud security platforms.
Why Datadog’s Approach Is Different
Traditional security tools often answer one question:
What is vulnerable?
A business needs several more answers:
Is the resource in production? Is it internet-facing? Is an exploit available? Does it handle sensitive data? Who owns it? What services depend on it?
This additional context changes prioritization.
Imagine an ecommerce company has 3,000 known vulnerabilities. Two receive a critical CVSS score. One affects an isolated development server. The other affects an internet-facing production container processing customer data.
Treating them equally wastes engineering time.
Datadog Cloud Security Vulnerabilities combines vulnerability intelligence with information such as production status, internet exposure, sensitive-data processing, privileged access, CISA Known Exploited Vulnerabilities, EPSS data, and public exploit availability.
The goal is not simply to generate more findings. It is to help teams identify the vulnerabilities most likely to create meaningful business risk.
How Datadog Cloud Security Works
Datadog supports both agentless and agent-based security monitoring.
Agentless Scanning
Datadog Agentless Scanning can examine supported AWS, Azure, and Google Cloud infrastructure without installing the Datadog Agent on every workload.
This is useful when a company wants broad visibility quickly.
Datadog currently schedules agentless vulnerability scans at 12-hour intervals. It recommends agentless scanning as an initial way to establish coverage, followed by Agent deployment on important assets where deeper context is needed.
Datadog Agent
The Datadog Agent provides more detailed runtime information and real-time vulnerability updates.
According to Datadog’s deployment guidance, agentless scanning can provide broad infrastructure coverage in minutes, while Agent-based deployment provides deeper runtime vulnerability prioritization.
A Practical Deployment Strategy
Businesses do not have to choose only one model.
A sensible rollout can use:
- Agentless scanning for broad cloud visibility.
- The Datadog Agent on production and business-critical systems.
- CI/CD container scanning to catch vulnerabilities before deployment.
This layered approach is particularly useful for Kubernetes and container-heavy environments. For additional infrastructure context, see Digital Exclude’s guide comparing Kubernetes and serverless architectures.
Key Datadog Cloud Security Capabilities
Vulnerability Management
Datadog continuously evaluates hosts and container images for known vulnerabilities and helps teams prioritize exploitable findings.
Instead of asking developers to work through a flat CVE list, security teams can focus first on vulnerabilities associated with exposed or critical production resources.
Cloud Security Posture Management
Misconfigurations remain a common source of cloud exposure.
Datadog can continuously evaluate cloud accounts, Kubernetes deployments, hosts, and containers against configuration controls.
Its documentation currently lists more than 1,000 out-of-the-box compliance rules mapped to frameworks and benchmarks such as SOC 2, PCI DSS, CIS, and AWS security best practices.
This can help businesses move from periodic configuration reviews toward continuous posture monitoring.
Identity Risk Management
Cloud permissions tend to accumulate.
A developer may receive temporary administrator access during an incident, an unused role may remain active, or one identity may gain permissions across multiple accounts.
Datadog Identity Risks looks for conditions such as lingering administrative privileges, permission gaps, privilege escalation opportunities, cross-account access, and large potential blast radii across AWS, Azure, and GCP.
That matters because cloud security is not only about vulnerable software. Identity can become the path attackers use to move from one compromised resource to the rest of the environment.
Security Inbox and Prioritization
Security Inbox consolidates important findings instead of forcing analysts to jump between separate security views.
Datadog explains that Security Inbox prioritizes findings using severity, correlated risks, and the number of impacted resources and services.
This can help solve a common operational problem: finding the handful of security issues that deserve immediate attention among thousands of lower-value alerts.
Where Observability Creates Business Value
Datadog’s strongest advantage may be most visible for organizations already using it for monitoring.
The company now supports more than 1,000 integrations spanning infrastructure, cloud services, security platforms, SaaS applications, and AI technologies.
When security and observability share context, a security engineer investigating a vulnerable workload may also be able to inspect logs, infrastructure metrics, application dependencies, ownership information, and production behavior.
That reduces handoffs between security and DevOps.
For businesses exploring the broader relationship between automation and defensive technology, Digital Exclude’s guide to AI in cybersecurity explains how modern security teams are increasingly using automation to reduce alert volume and speed investigation.
What Does Datadog Cloud Security Cost?
Datadog pricing is modular, which means buyers should evaluate the total platform configuration rather than one headline number.
At the time of research, Datadog’s published pricing list shows:
| Product | Annual List Price |
| Cloud Security Management Pro | $10 per CSM host/month |
| Cloud Security Management Enterprise | $25 per CSM host/month |
| Workload Protection | $15 per host/month |
| Cloud SIEM | $5 per 1 million analyzed events/month |
Container, on-demand, logging, application-security, and other charges can apply separately.
Before purchasing, model the full cost based on hosts, containers, security events, logs, retention, and additional Datadog products.
This is where FinOps becomes relevant. Digital Exclude’s FinOps guide explains how engineering, finance, and business teams can evaluate cloud spending based on business value rather than subscription price alone.
Who Should Consider Datadog Cloud Security?
Datadog Cloud Security is particularly compelling for organizations already using Datadog observability and operating complex AWS, Azure, GCP, Kubernetes, container, or multi-cloud environments.
It may make sense when your organization wants to:
- Reduce security and DevOps tool silos.
- Prioritize vulnerabilities using production context.
- Continuously detect cloud configuration problems.
- Reduce excessive IAM permissions.
- Connect findings to resource owners.
- Improve compliance visibility.
- Consolidate monitoring and security workflows.
It may be less compelling for a small company with simple infrastructure or an organization that already has a deeply established CNAPP and security operations ecosystem.
A Practical Implementation Roadmap
Step 1: Establish Visibility
Connect cloud accounts and identify which resources, clusters, containers, identities, and production systems require coverage.
Step 2: Prioritize Critical Assets
Tag production services, define ownership, and identify systems processing sensitive or business-critical data.
Step 3: Combine Agentless and Runtime Monitoring
Use agentless scanning for broad coverage and deploy Agents where real-time runtime context matters most.
Step 4: Create a Remediation Workflow
Route security findings to responsible engineering teams through ticketing, chat, or workflow integrations.
Step 5: Measure Outcomes
Track business-oriented metrics such as:
- Critical exposed vulnerabilities
- Mean time to remediation
- Excessive privileged identities
- Repeat misconfigurations
- Findings resolved within SLA
- Percentage of production infrastructure covered
Buying another security platform has little value if these numbers do not improve.
Final Verdict
Datadog Cloud Security makes the most sense when security teams need more context, not simply more alerts.
Its combination of vulnerability management, cloud posture checks, identity-risk analysis, compliance capabilities, Security Inbox, and Datadog’s broader observability ecosystem can help DevOps and security teams work from a shared view of production risk.
The business case is strongest for existing Datadog customers because operational and security telemetry can live within related workflows.
However, companies should evaluate coverage requirements, deployment methods, existing security tools, and total cost before consolidating around Datadog. The right question is not whether Datadog can detect security issues. It is whether the platform can help your organization identify, assign, and remediate its most important risks faster.
Frequently Asked Questions
1. What is Datadog Cloud Security used for?
Datadog Cloud Security helps organizations detect vulnerabilities, cloud misconfigurations, identity risks, and compliance issues while connecting security findings to infrastructure and observability context.
2. Does Datadog Cloud Security require an agent?
No. Datadog supports agentless scanning for supported AWS, Azure, and GCP environments. Organizations can also deploy the Datadog Agent for deeper runtime visibility and real-time vulnerability updates.
3. Is Datadog Cloud Security a CNAPP?
Datadog provides many capabilities commonly associated with CNAPP platforms across its broader security portfolio, including posture management, vulnerability management, identity security, workload protection, application security, and cloud threat detection. Buyers should compare the exact Datadog products included in their plan with their required CNAPP capabilities.
4. Does Datadog support AWS, Azure, and Google Cloud security?
Yes. Core Datadog Cloud Security capabilities support major cloud environments including AWS, Microsoft Azure, and Google Cloud, although feature coverage can differ by resource and deployment type.
5. Is Datadog Cloud Security worth it?
It can provide strong value for businesses already using Datadog and organizations that want security findings correlated with production observability data. Companies with simple infrastructure or mature standalone security platforms should compare functionality, operating effort, and total cost before switching.
