---
title: "Choosing Security Vendor for VM Migration Projects"
source: "https://www.tigera.io/learn/guides/vmware-migration/choosing-security-vendor-for-vm-migration-projects/"
description: "Securing a VM migration means protecting workloads in transit and after the move. Best for network segmentation: Tigera Calico; best for broad cloud protection: Wiz."
---

## Guides: Choosing Security Vendor for VM Migration Projects

# Choosing Security Vendors for VM Migration Projects: 8 Providers Compared

- [VMware Migration](https://www.tigera.io/learn/guides/vmware-migration/)

- [Choosing Security Vendor for VM Migration Projects](https://www.tigera.io/learn/guides/vmware-migration/choosing-security-vendor-for-vm-migration-projects/)

- [Multi-Cloud VM Migration Security Best Practices](https://www.tigera.io/learn/guides/vmware-migration/multi-cloud-vm-migration-security-best-practices/)

- [VM Migration Security Solutions for Enterprise](https://www.tigera.io/learn/guides/vmware-migration/vm-migration-security-solutions-for-enterprise/)

- [VMware Migration Tools](https://www.tigera.io/learn/guides/vmware-migration/vmware-migration-tools/)

- [Lift and Shift Migration](https://www.tigera.io/learn/guides/vmware-migration/lift-and-shift-migration/)

- [VMware Live Migration](https://www.tigera.io/learn/guides/vmware-migration/vmware-live-migration/)

- [VMware NSX Alternatives](https://www.tigera.io/learn/guides/vmware-migration/vmware-nsx-alternatives/)

**TL;DR:** Securing a VM migration means protecting workloads in transit and after the move. Best for network segmentation: Tigera Calico; best for broad cloud protection: Wiz.

## What Are Vendors for VM Migration Projects?

Choosing the right security vendor for a [Virtual Machine (VM) migration](https://www.tigera.io/learn/guides/vmware-migration/) project requires evaluating tools that secure your data during transit, protect workloads post-move, and maintain your specific compliance standards (e.g., GDPR, HIPAA, SOC2).

Virtual machine (VM) migration projects involve moving workloads between virtualization platforms, data centers, or cloud environments. Common goals include infrastructure modernization, cloud adoption, cost optimization, and improved resilience. While migration tools simplify the movement of workloads, they do not address all of the security challenges introduced during the process.

### Key Evaluation Criteria

The vendors in this guide are evaluated based on their ability to support secure VM migration projects across hybrid and multi-cloud environments. The primary evaluation criteria include:

- VM and cloud platform expertise

- Migration-specific security experience

- Discovery and asset inventory capabilities

- Vulnerability and configuration assessment

- Network security and microsegmentation

- Monitoring and threat detection

- Compliance and reporting

### Solutions Compared in This Guide

This guide compares solutions across two primary categories:

- **Network Security and Microsegmentation** - Tigera (Calico) - Illumio Segmentation - Akamai Guardicore Segmentation

- **Cloud-Native Application Protection Platforms (CNAPP)** - Wiz - Orca Security - Prisma Cloud - Microsoft Defender for Cloud - CrowdStrike Falcon Cloud Security

**In this article:**

- Security Risks in VM Migration Projects

- Key Criteria for Choosing a Security Vendor for VM Migration Projects

- Common VM Migration Solutions and How They Meet the Criteria

- Notable Security Solutions for VM Migration Projects

## Security Risks in VM Migration Projects

### Incomplete Asset and Dependency Visibility

One of the main risks in VM migration projects is incomplete visibility into all assets and their dependencies. Organizations often maintain complex environments with interconnected applications, services, and data flows. If the migration team lacks a comprehensive inventory of assets and an understanding of their relationships, critical components may be overlooked, resulting in broken dependencies, application failures, or security gaps post-migration. These gaps can disrupt business operations and create vulnerabilities.

**Insufficient visibility** can lead to incomplete migrations, where some VMs or services remain on legacy platforms, increasing the attack surface and complicating management. Shadow IT, undocumented services, and outdated systems may be missed during assessment. Without detailed mapping and documentation, organizations may not realize which assets require special handling or additional security controls, leaving sensitive workloads exposed to threats in the new environment.

### Data Exposure During Migration

VM migration projects frequently involve moving sensitive data across different environments, often over public or semi-trusted networks. If proper encryption and secure transfer protocols are not enforced, data can be intercepted or tampered with during transit. Attackers may exploit weak or misconfigured connections to eavesdrop, exfiltrate, or alter critical information. This risk is heightened when migrations span geographic regions or involve third-party service providers without strong security controls.

**Additionally**, the process may temporarily expose data to broader access within the migration environment, particularly if staging areas or intermediary storage are used. If access controls are not strictly maintained, unauthorized personnel or malicious insiders could gain access to confidential information. Organizations must ensure robust end-to-end encryption, strict authentication, and continuous monitoring during all phases of the migration to prevent data leaks and maintain regulatory compliance.

***Related content: Read our detailed guide to [VMware live migration](https://www.tigera.io/learn/guides/vmware-migration/vmware-live-migration/).***

### Identity and Access Misconfigurations

Identity and access management (IAM) is a critical concern during VM migrations. Transferring workloads between environments often requires recreating or mapping user accounts, roles, and permissions. Misconfigurations in this process can result in excessive privileges, orphaned accounts, or unintended access to sensitive resources. Attackers can exploit these weaknesses to escalate privileges or move laterally within the environment, increasing the risk of data breaches or operational disruption.

**Differences in IAM models** between source and target platforms can introduce inconsistencies. For example, migrating from an on-premises Active Directory to a cloud-based IAM service may require careful mapping of group policies, service accounts, and authentication mechanisms. Failure to align these configurations can break application functionality or create security loopholes. Rigorous access reviews, privilege minimization, and automated policy enforcement are essential to mitigate these risks during and after migration.

### Vulnerabilities in Migrated Workloads

Migrated workloads may carry existing vulnerabilities from the source environment into the target platform. If VMs are not properly assessed and patched before migration, known security flaws can persist and be exposed to new threats in the cloud or hybrid infrastructure. Attackers may exploit unpatched operating systems, outdated libraries, or misconfigured applications, especially if the migration process bypasses standard vulnerability management workflows.

**Differences in security controls** or default configurations between environments can introduce new vulnerabilities. For instance, workloads may lose network segmentation or inherit weaker firewall policies post-migration. It is crucial to perform comprehensive vulnerability assessments, apply all necessary patches, and validate configurations both before and after migration. Continuous vulnerability scanning and compliance checks should be integrated into the migration process to ensure workloads remain secure in their new environment.

### Network Security Gaps

VM migration projects can introduce network security gaps if firewall rules, segmentation policies, or intrusion detection systems are not correctly replicated or adapted in the new environment. Misaligned network configurations may inadvertently expose critical workloads to the public internet or untrusted internal segments. Attackers can exploit these gaps to gain unauthorized access, launch denial-of-service attacks, or move laterally within the network.

**Cloud and hybrid environments** often require new approaches to network security, such as [microsegmentation](https://www.tigera.io/learn/guides/microsegmentation/) or software-defined networking, which differ from traditional on-premises models. If organizations fail to update their security architectures accordingly, they may leave migrated VMs vulnerable. Ongoing network monitoring, automated policy enforcement, and regular reviews of network security postures are vital to maintaining a strong security posture during and after VM migration projects.

## Key Criteria for Choosing a Security Vendor for VM Migration Projects

### 1. VM and Cloud Platform Expertise

A security vendor for VM migration projects should have deep experience with the virtualization platforms and cloud environments involved in the migration. This includes technologies such as VMware vSphere, Microsoft Hyper-V, KVM, AWS, Microsoft Azure, and Google Cloud. The vendor should understand the security models, networking, identity services, and migration tools used by each platform to ensure workloads remain protected throughout the migration process.

**Evaluation criteria:**

- Supports all source and target virtualization and cloud platforms

- Demonstrates experience with hybrid and multi-cloud migrations

- Understands platform-specific security controls and best practices

- Provides certified engineers or recognized cloud partnerships

- Can secure both migration workflows and production workloads

- Has customer references for similar migration projects

### 2. Migration-Specific Security Experience

General cybersecurity expertise is valuable, but VM migrations introduce unique risks that require specialized knowledge. Vendors should have established processes for securing migration activities, protecting data in transit, validating workloads after migration, and minimizing operational disruption. Experience with complex enterprise migrations reduces the likelihood of security issues during the project.

**Evaluation criteria:**

- Proven track record with VM migration security projects

- Documented migration security methodology

- Experience securing large-scale or business-critical migrations

- Ability to identify and mitigate migration-specific risks

- Post-migration validation and security testing capabilities

- Customer case studies relevant to the organization’s environment

### 3. Discovery and Asset Inventory Capabilities

A successful migration starts with accurate visibility into the existing environment. Vendors should provide automated discovery tools that identify virtual machines, applications, dependencies, network connections, and sensitive assets. Comprehensive inventories reduce the risk of overlooked systems, broken dependencies, and incomplete migrations.

**Evaluation criteria:**

- Automated VM and asset discovery capabilities

- Application dependency mapping

- Identification of unmanaged or shadow IT assets

- Classification of sensitive systems and data

- Regularly updated inventory throughout the migration

- Exportable reports for planning and documentation

### 4. Vulnerability and Configuration Assessment

Before workloads are migrated, they should be evaluated for security weaknesses and configuration issues. Vendors should assess operating systems, applications, security settings, and cloud readiness to identify vulnerabilities that could be transferred into the new environment. They should also verify that workloads remain securely configured after migration.

**Evaluation criteria:**

- Pre- and post-migration vulnerability scanning

- Configuration and security baseline assessments

- Detection of missing patches and outdated software

- Validation against security best practices and benchmarks

- Risk prioritization with remediation guidance

- Continuous assessment after migration completion

### 5. Network Security and Segmentation

Migrated workloads often require redesigned network architectures to match cloud or hybrid environments. Vendors should help maintain secure network segmentation, firewall policies, and access controls while adapting them to the target platform. Proper network design limits the impact of attacks and prevents unauthorized lateral movement.

**Evaluation criteria:**

- Assessment of existing network security architecture

- Support for cloud-native firewall and segmentation technologies

- Ability to implement or maintain microsegmentation

- Validation of network policies after migration

- Secure connectivity between on-premises and cloud environments

- Continuous monitoring of network security posture

### 6. Monitoring and Threat Detection

Migration projects can temporarily increase the attack surface, making continuous monitoring essential. Vendors should provide visibility into migration activities and deployed workloads, using threat detection technologies to identify suspicious behavior, unauthorized access, or configuration changes that could indicate a security incident.

**Evaluation criteria:**

- Real-time monitoring during migration activities

- Integration with SIEM, XDR, or SOC platforms

- Detection of anomalous user and workload behavior

- Alerting for unauthorized configuration changes

- Incident investigation and response support

- Continuous monitoring after migration completion

### 7. Compliance and Reporting

Organizations must ensure that VM migrations do not violate regulatory or internal security requirements. Vendors should provide compliance assessments, evidence collection, and reporting that demonstrate workloads remain compliant before, during, and after migration. Detailed reporting also supports audits and internal governance processes.

### Evaluation criteria:

- Support for relevant regulatory frameworks and standards

- Automated compliance assessments and reporting

- Audit trails for migration activities and security events

- Documentation of security controls and remediation actions

- Executive and technical reporting options

- Integration with governance, risk, and compliance (GRC) tools

## Common VM Migration Solutions and How They Meet the Criteria

The table below summarizes how each solution maps to the selection criteria. We explore each one in more detail further down.

**Category**
**Solution**
**How It Meets the Criteria**

Network Security & Microsegmentation
**1. Tigera (Calico)**
Runs on any Kubernetes distribution and extends policy to VMs and bare metal, with a dedicated VM migration use case. Core strengths are microsegmentation, egress controls, and workload IDS/IPS, WAF, and DDoS detection. Adds service-graph visibility and audit-ready compliance reporting, though it is not a general vulnerability scanner.

Network Security & Microsegmentation
**2. Illumio Segmentation**
Delivers consistent Zero Trust segmentation across clouds, data centers, endpoints, containers, and VMs, mapping traffic and dependencies in real time to contain lateral movement. Illumio Insights adds detection and response, and compliance is a named use case. It focuses on segmentation and exposure rather than workload vulnerability scanning.

Network Security & Microsegmentation
**3. Akamai Guardicore Segmentation**
Covers hybrid cloud, VMs, servers, containers, and OT from one console, and explicitly extends to on-premises to cloud migrations. Runs continuous AI discovery and dependency mapping, enforces microsegmentation, and reports against PCI-DSS, HIPAA, and SWIFT. Exposure analysis flags risky paths but is not a full vulnerability scanner.

Cloud-Native Application Protection Platforms (CNAPP)
**4. Wiz**
Provides agentless coverage of multi-cloud VMs, containers, serverless, and PaaS, discovering assets and prioritizing risk through the Security Graph and attack-path analysis. Runtime protection comes from the Wiz Sensor, and it improves compliance posture. It gives exposure context rather than in-line segmentation and is not a dedicated migration tool.

Cloud-Native Application Protection Platforms (CNAPP)
**5. Orca Security**
Uses agentless SideScanning across all major clouds to inventory workloads and protect VMs, containers, and serverless. Combines vulnerability management and CSPM to prioritize critical risks, adds CDR for monitoring, and supports multi-cloud compliance. It centers on posture and workload risk rather than segmentation.

Cloud-Native Application Protection Platforms (CNAPP)
**6. Prisma Cloud**
Secures multi-cloud workloads from code to runtime, inventorying assets via agentless scanning and CSPM and detecting misconfigurations and vulnerabilities before and after deployment. Runtime threat detection blocks attacks in real time, and posture management supports compliance. Segmentation is not the primary focus.

Cloud-Native Application Protection Platforms (CNAPP)
**7. Microsoft Defender for Cloud**
Covers hybrid and multicloud with strong Azure integration, giving end-to-end visibility and using CSPM and DevOps security to catch misconfigurations, vulnerabilities, and secrets from code to runtime. Threat detection is integrated into the Microsoft Defender portal, with posture-based compliance. It provides attack-path context rather than segmentation.

Cloud-Native Application Protection Platforms (CNAPP)
**8. CrowdStrike Falcon Cloud Security**
Secures AWS, Azure, GCP, and OCI with unified agent and agentless coverage, prioritizing reachable vulnerabilities through runtime code analysis and CSPM. Real-time CDR and workload protection are led by adversary intelligence, with automated cloud compliance. It focuses on detection and posture rather than in-line segmentation.

 

## Notable Security Solutions for VM Migration Projects

**How we selected these solutions:** We shortlisted security solutions for VM migration based on their ability to discover and map workloads, segment and protect them across environments, assess vulnerabilities and configurations, detect threats, and support compliance from the source environment through the target platform.

### Network Security and Microsegmentation

#### 1. Tigera (Calico)

![Calico Logo](https://www.tigera.io/app/uploads/2026/01/Calico-logo-2026-black-text.svg)

**Best for:** Securing Kubernetes and migrated workloads with microsegmentation

**Strengths:** Microsegmentation, threat detection, and compliance for Kubernetes

**Things to consider:** Built around Kubernetes; VMs covered via host endpoints

Calico is a unified platform for Kubernetes networking and network security, available as self-managed Calico Enterprise or fully managed Calico Cloud SaaS. It works across any Kubernetes distribution in the cloud, on-premises, or at the edge.

It extends network security controls to multi-cluster applications, virtual machines, and bare-metal hosts. For teams moving workloads into Kubernetes as part of a migration, it applies consistent network policy, microsegmentation, and observability across source and target environments, and offers a dedicated VM migration use case.

**Key features include:**

- **Unified networking across environments:** Provides a choice of eBPF, iptables, nftables, Windows, or VPP data planes and unifies networking across hosts, virtual machines, bare metal, and containers, with WireGuard encryption for pod-to-pod traffic.

- **Microsegmentation and egress controls:** Isolates namespaces to limit lateral movement and enforces DNS policies, network sets, and Layer 7 policies, with segmentation by environment, application tier, compliance need, or workload.

- **Network policy lifecycle management:** Offers a single pane to view, recommend, stage, preview, order, and troubleshoot policies, with policy tiers and support for deny rules, DNS names, and IP ranges beyond native Kubernetes.

- **Workload threat detection:** Delivers workload-level IDS/IPS using threat intelligence feeds, a workload-centric WAF for HTTP-based attacks, and DDoS detection and prevention.

- **Observability and troubleshooting:** Correlates flow logs with Kubernetes context and provides a dynamic service graph, DNS, L7, and TCP dashboards, and targeted packet capture with RBAC integration.

- **Compliance and audit:** Continuously monitors against PCI DSS, HIPAA, GDPR, SOC 2, NIST, CCPA, and custom frameworks, generates audit-ready reports, and lets teams author controls as code.

**How Calico meets the selection criteria:**

**Criterion**
**How Calico addresses it**

VM and cloud platform expertise
Runs on any Kubernetes distribution across AWS EKS, Azure AKS, Google GKE, OpenShift, and Rancher, and extends policy to VMs and bare-metal hosts.

Migration-specific security
Provides a dedicated VM migration use case with consistent policy and microsegmentation across source and target Kubernetes environments.

Discovery and asset inventory
Maps workload communication and network topology through a dynamic service graph and flow logs; focused on network flows rather than a full asset inventory.

Vulnerability and configuration assessment
Shift-left CI/CD checks catch network policy risks before production; not a general OS or package vulnerability scanner.

Network security and segmentation
Core strength, with L3 to L7 policy, namespace isolation, egress controls, and encryption.

Monitoring and threat detection
Workload IDS/IPS, WAF, DDoS detection, and a dynamic service and threat graph with alerting.

Compliance and reporting
Continuous monitoring and audit-ready reports for major and custom frameworks.

Source: [Tigera](https://docs.tigera.io/assets/images/dashboards-1379b9f25f778cc843aad5e4d93b6e2d.png)

#### 2. Illumio Segmentation

**Best for:** Zero Trust segmentation across hybrid, multi-cloud, and VMs

**Strengths:** Traffic visibility and lateral-movement containment

**Things to consider:** Segmentation and visibility, not workload vulnerability scanning

Illumio Segmentation applies Zero Trust principles to contain lateral movement across hybrid, multi-cloud environments. It combines real-time telemetry with AI to recommend segmentation policies and delivers consistent, automated segmentation for workloads across clouds, endpoints, and data centers.

It maps traffic and dependencies so teams can see how workloads communicate and set least-privilege policies without disrupting operations. Coverage spans data centers, containers, IT/OT, and virtual machines, and breaches can be contained to a single workstation, laptop, or VM.

**Key features include:**

- **Traffic visibility and mapping:** Builds real-time maps of communication and dependencies across data centers, multi-cloud, containers, IT/OT, and virtual machines.

- **Workload and VM segmentation:** Applies consistent, automated segmentation across clouds, endpoints, and data centers to stop lateral movement.

- **AI-assisted policy:** Combines real-time telemetry with AI to recommend segmentation policies and speed decision-making.

- **Endpoint containment:** Contains a breach to a single workstation, laptop, or virtual machine, often before other tools detect it.

- **Cloud segmentation:** Visualizes cloud deployments, resources, and traffic flows and builds dynamic segmentation across hybrid multi-cloud environments and containers.

- **Detection and response add-on:** Illumio Insights provides hybrid cloud detection and response on the same platform.

**How Illumio meets the selection criteria:**

**Criterion**
**How Illumio addresses it**

VM and cloud platform expertise
Provides consistent coverage across clouds, data centers, endpoints, containers, and virtual machines in hybrid multi-cloud environments.

Migration-specific security
Not positioned as a dedicated migration tool, but consistent cross-environment segmentation supports phased moves without disrupting operations.

Discovery and asset inventory
Delivers real-time traffic maps and dependency visibility across workloads and devices.

Vulnerability and configuration assessment
Surfaces risky flows and exposure to inform policy; not a workload vulnerability scanner.

Network security and segmentation
Core strength, with Zero Trust microsegmentation across every environment.

Monitoring and threat detection
Illumio Insights adds hybrid cloud detection and response, and segmentation contains breaches.

Compliance and reporting
Compliance is a named use case, with visibility and enforced segmentation to support audits.

 

Source: [Illumio](https://cdn.prod.website-files.com/63e25fb5e66132e6387676dc/690524b6dc7cda62ef4ce2ac_682b71ce7dc1503ad631a6e1_1200x630%2520Illumio%2520Segmentation%2520Product%2520Brief%2520V02.webp)

#### 3. Akamai Guardicore Segmentation

**Best for:** AI-driven microsegmentation across hybrid cloud, VMs, servers

**Strengths:** Continuous discovery, dependency mapping, policy automation

**Things to consider:** Segmentation-focused, not a full CNAPP or scanner

Akamai Guardicore Segmentation is an AI-powered microsegmentation platform with exposure analysis and response. It provides continuous discovery across IT, cloud, OT, and AI workloads, maps application dependencies, and auto-labels unknown assets for a real-time view of what is communicating.

Its AI evaluates traffic and exposure to generate risk-based policy recommendations with confidence scoring and a phased rollout. The platform applies the same visibility and policy controls to virtual machines, servers, and containers from a single console, and these benefits extend to teams migrating applications from on-premises into the cloud.

**Key features include:**

- **Continuous discovery and mapping:** Uses AI to map application dependencies and auto-label known, unknown, and unmanaged assets across IT, cloud, OT, and AI workloads.

- **AI policy recommendations:** Analyzes traffic and exposure to generate policy recommendations with confidence scoring, evidence, and a recommended phased workflow.

- **Cross-environment segmentation:** Applies the same controls to virtual machines, servers, and containers from one map and policy engine, including on-premises to cloud migrations.

- **Agent-based and agentless enforcement:** Offers agents for maximum visibility and agentless options for in-cloud PaaS, IoT, and OT environments.

- **Exposure analysis and response:** Correlates asset reachability, open admin ports, and risky tool usage to map exploitable paths, with AI-driven threat hunting.

- **Compliance and audit readiness:** Provides continuously enforced segmentation with real-time and historical views mapped to PCI-DSS, HIPAA, and SWIFT.

**How Akamai Guardicore meets the selection criteria:**

**Criterion**
**How Akamai Guardicore addresses it**

VM and cloud platform expertise
Covers hybrid cloud, VMs, servers, containers, OT, and Kubernetes from one console, deployed in the cloud or on-premises.

Migration-specific security
Explicitly extends visibility and segmentation to applications migrating from on-premises into the cloud.

Discovery and asset inventory
Runs continuous discovery with AI dependency mapping and auto-labeling of known, unknown, and unmanaged assets.

Vulnerability and configuration assessment
Exposure analysis maps reachability, open admin ports, and risky tools; not a general vulnerability scanner.

Network security and segmentation
Core strength, with AI-driven microsegmentation and ring-fencing to stop lateral movement.

Monitoring and threat detection
Provides exposure-based threat validation, AI-driven threat hunting, and incident response guidance.

Compliance and reporting
Generates real-time and historical reports mapped to PCI-DSS, HIPAA, SWIFT, and Zero Trust frameworks.

Source: [Akamai](https://www.akamai.com/site/en/images/blog/2022/guardicore-at-rsa-ai-powered-segmentation-cloud-native-security1.jpg)

### Cloud-Native Application Protection Platforms (CNAPP)

#### 4. Wiz

**Best for:** Agentless cloud and AI security across VMs, containers, PaaS

**Strengths:** Attack-path analysis and prioritized risk via Security Graph

**Things to consider:** Agentless-first; runtime depth needs the Wiz Sensor

Wiz is an agentless cloud and AI security platform that connects via API and covers cloud resources across PaaS, virtual machines, containers, serverless functions, repositories, and pipelines. It reaches full coverage in minutes without agents or ongoing maintenance.

Its Security Graph analyzes relationships between the technologies running in a cloud environment to surface the most critical pathways to a breach, and attack-path analysis presents a prioritized list of toxic risk combinations. Runtime protection is available through the Wiz Sensor combined with agentless telemetry.

**Key features include:**

- **Agentless visibility:** Connects via API to cover virtual machines, containers, serverless functions, PaaS, repositories, and pipelines without impacting workload performance.

- **Security Graph:** Analyzes relationships across cloud and AI layers to reveal the most critical pathways to a breach in a single console.

- **Attack path analysis:** Prioritizes toxic combinations of risk with a high probability of exploitation and significant business impact.

- **Runtime protection:** Combines the Wiz Sensor with agentless telemetry for real-time threat detection, including AI-native threats.

- **Code-to-cloud correlation:** Links running cloud resources back to the code, pipeline, and developer, with one-click fixes via pull requests.

- **Workflow orchestration:** Automates detection-to-remediation with out-of-the-box or no-code custom workflows and cloud threat intelligence.

**How Wiz meets the selection criteria:**

**Criterion**
**How Wiz addresses it**

VM and cloud platform expertise
Provides agentless coverage across multi-cloud VMs, containers, serverless functions, and PaaS via API.

Migration-specific security
Not positioned as a migration tool; provides visibility and risk prioritization for workloads once they are in the cloud.

Discovery and asset inventory
Discovers every technology running in code and cloud, including VMs, using multiple detection methods.

Vulnerability and configuration assessment
Surfaces and prioritizes risks and toxic combinations through the Security Graph and attack-path analysis.

Network security and segmentation
Provides exposure and attack-path context rather than in-line segmentation enforcement.

Monitoring and threat detection
Delivers runtime protection through the Wiz Sensor and agentless telemetry, with cloud threat intelligence.

Compliance and reporting
Improves compliance posture through prioritized issues and reporting.

Source: [Wiz](https://www.datocms-assets.com/75231/1671640003-screenshot-2022-12-21-at-15-04-13.png)

#### 5. Orca Security

**Best for:** Agentless multi-cloud CNAPP for VMs, containers, serverless

**Strengths:** SideScanning visibility with prioritized risk and compliance

**Things to consider:** Agentless-first; deep runtime uses the Orca Sensor

Orca Security is an agentless cloud security platform that uses SideScanning to cover cloud workloads across multiple providers. It combines CNAPP capabilities in one platform, including cloud security posture management, workload protection for virtual machines, containers, and serverless functions, entitlement management, vulnerability management, and multi-cloud compliance.

A Unified Data Model correlates risk, and dynamic scoring with attack-path analysis prioritizes the most critical exposures. Coverage spans AWS, Azure, Google Cloud, Oracle Cloud, Alibaba Cloud, and Tencent Cloud.

**Key features include:**

- **Agentless SideScanning:** Scans every cloud workload without agents across all major cloud providers.

- **Workload protection (CWPP):** Protects virtual machines, containers, and serverless functions.

- **Posture management (CSPM):** Identifies and helps remediate misconfigurations across clouds.

- **Vulnerability management:** Delivers agentless vulnerability management that prioritizes the most critical risks.

- **Risk prioritization:** Uses a Unified Data Model plus dynamic scoring and attack-path analysis to focus teams on exploitable risk.

- **Detection and response (CDR):** Provides 24×7 monitoring and response across the cloud attack surface, with the Orca Sensor for runtime.

**How Orca Security meets the selection criteria:**

Criterion
How Orca addresses it

VM and cloud platform expertise
Provides agentless coverage across AWS, Azure, GCP, Oracle, Alibaba, and Tencent, including VMs, containers, and serverless.

Migration-specific security
Not a dedicated migration tool; secures and assesses workloads across multi-cloud once they are deployed.

Discovery and asset inventory
Uses SideScanning to discover workloads and build a unified inventory without agents.

Vulnerability and configuration assessment
Combines agentless vulnerability management and CSPM to detect misconfigurations and prioritize critical risks.

Network security and segmentation
Focuses on posture, workload, and exposure rather than in-line segmentation.

Monitoring and threat detection
Provides CDR for 24×7 monitoring and response, with the Orca Sensor adding runtime coverage.

Compliance and reporting
Supports multi-cloud compliance for industry standards and custom checks.

Source: [Orca Security](https://orca.security/wp-content/uploads/2026/01/orca-AI-security-dashboard-dark-mode-2026.png)

#### 6. Prisma Cloud

**Best for:** Code-to-cloud CNAPP with host, container, serverless security

**Strengths:** Full-lifecycle coverage from IaC to runtime with prioritization

**Things to consider:** Broad platform; some parts now align under Cortex Cloud

Prisma Cloud is a code-to-cloud platform from Palo Alto Networks that secures applications from design through runtime. It spans code security, including infrastructure as code, CI/CD, secrets, and software composition analysis, and infrastructure protection, including cloud security posture management, API visibility, entitlement management, and agentless workload scanning.

Runtime defense adds threat detection, serverless security, host security, and web application and API security. AI-powered risk prioritization analyzes the blast radius from at-risk assets, and a Copilot supports guided investigation and response.

**Key features include:**

- **Cloud security posture management:** Hardens the cloud estate and protects application infrastructure across the stack.

- **Agentless workload scanning:** Scans workloads across the infrastructure without deploying agents.

- **Host and container security:** Protects hosts and blocks untrusted images before deployment.

- **Runtime threat detection:** Blocks advanced attacks in real time with in-line protection and defense in depth.

- **Code security:** Provides IaC security, CI/CD security, secrets detection, and software composition analysis to fix risks before runtime.

- **AI-powered prioritization:** Analyzes the blast radius from at-risk assets, with a Copilot for guided investigation and response.

**How Prisma Cloud meets the selection criteria:**

**Criterion**
**How Prisma Cloud addresses it**

VM and cloud platform expertise
Provides multi-cloud coverage from code to runtime, including host, container, and serverless workloads.

Migration-specific security
Not a dedicated migration tool; secures application infrastructure and hosts once workloads are in the cloud.

Discovery and asset inventory
Inventories cloud assets and infrastructure through agentless scanning and posture management.

Vulnerability and configuration assessment
Combines CSPM, IaC, software composition analysis, and workload scanning to detect misconfigurations and vulnerabilities before and after deployment.

Network security and segmentation
Provides web application and API security and runtime protection; segmentation is not the primary focus.

Monitoring and threat detection
Blocks attacks in real time and analyzes large-scale event data with Precision AI.

Compliance and reporting
Uses posture management to support compliance across the cloud estate.

Source: [Palo Alto Networks](https://www.paloaltonetworks.com/blog/wp-content/uploads/2019/11/Twistlock.jpg)

#### 7. Microsoft Defender for Cloud

**Best for:** CNAPP for hybrid and multicloud with strong Azure integration

**Strengths:** Posture management, workload protection, and DevOps security

**Things to consider:** Deepest fit for Azure-centric, Microsoft-heavy estates

Microsoft Defender for Cloud is a cloud-native application protection platform for hybrid and multicloud environments, providing unified security across the application lifecycle from code to runtime. It combines cloud security posture management, workload protection, and DevOps security.

It gives end-to-end visibility with contextual risk prioritization so teams can remediate at scale, and threat detection and response are integrated into the Microsoft Defender portal. Attack-path analysis helps mitigate attacks across infrastructure, AI workloads, APIs, and data stores.

**Key features include:**

- **Cloud security posture management:** Strengthens posture across hybrid and multicloud with contextual risk insights and at-scale remediation.

- **Workload protection:** Delivers multicloud protection across infrastructure, apps, and sensitive data with cloud-native threat detection.

- **DevOps security:** Unifies security across multicloud and multi-pipeline environments to prevent vulnerabilities, misconfigurations, and secrets from reaching production.

- **Attack path analysis:** Proactively mitigates attacks across cloud infrastructure, AI workloads, agents, APIs, and data stores.

- **Secure infrastructure as code:** Guards against risky misconfigurations reaching production with secure IaC templates and container images.

- **Integrations:** Works with Microsoft Sentinel, Defender XDR, Security Exposure Management, and Security Copilot.

**How Microsoft Defender for Cloud meets the selection criteria:**

Criterion
How Defender for Cloud addresses it

VM and cloud platform expertise
Covers hybrid and multicloud environments with deep Azure integration, protecting infrastructure, apps, and data.

Migration-specific security
Not a dedicated migration tool, but hybrid coverage suits securing workloads moving into Azure.

Discovery and asset inventory
Provides end-to-end visibility across hybrid and multicloud environments.

Vulnerability and configuration assessment
Uses CSPM and DevOps security to detect misconfigurations, vulnerabilities, and secrets from code to runtime.

Network security and segmentation
Provides attack-path analysis and posture management rather than in-line segmentation.

Monitoring and threat detection
Delivers cloud-native threat detection and response integrated into the Microsoft Defender portal.

Compliance and reporting
Uses posture management to support compliance across hybrid and multicloud environments.

Source: [Microsoft](https://learn.microsoft.com/en-us/azure/defender-for-cloud/media/overview-page/overview-07-2023.png)

#### 8. CrowdStrike Falcon Cloud Security

**Best for:** Unified agent and agentless CNAPP with cloud detection response

**Strengths:** Adversary-intel-led detection, CSPM, CWPP, vulnerability mgmt

**Things to consider:** Full runtime value pairs agentless with Falcon sensor

CrowdStrike Falcon Cloud Security is a cloud-native application protection platform that unifies agentless visibility with the Falcon sensor to protect workloads from code to runtime. It combines posture management, workload protection, vulnerability management, container and Kubernetes security, and cloud detection and response in one platform.

It enriches detections with adversary intelligence that tracks hundreds of global adversaries, and agentless posture management adds graph-based context to prioritize exploitable exposures. Coverage spans AWS, Azure, Google Cloud, and Oracle Cloud Infrastructure.

**Key features include:**

- **Unified agent and agentless protection:** Combines agentless visibility with the Falcon sensor for real-time detection and automated response.

- **Cloud detection and response (CDR):** Provides real-time detection across multi-cloud control planes, correlated with endpoint and identity signals.

- **Posture management (CSPM):** Offers agentless posture management enriched with adversary intelligence and graph-based context.

- **Workload protection (CWPP):** Defends cloud workloads across AWS, Azure, GCP, and OCI with threat detection and response.

- **Vulnerability management:** Uses runtime application code analysis to prioritize reachable, exploitable vulnerabilities.

- **Adversary intelligence:** Maps detections to known adversaries and TTPs using more than 281 tracked adversaries and real-time indicators.

**How CrowdStrike Falcon Cloud Security meets the selection criteria:**

Criterion
How Falcon Cloud Security addresses it

VM and cloud platform expertise
Secures AWS, Azure, GCP, and OCI with unified agent and agentless coverage across workloads and containers.

Migration-specific security
Not a dedicated migration tool, but positions to secure any cloud you migrate to, build on, and run.

Discovery and asset inventory
Provides agentless visibility across what you build and run, with graph-based context.

Vulnerability and configuration assessment
Combines agentless CSPM with runtime code analysis to prioritize reachable vulnerabilities and misconfigurations.

Network security and segmentation
Focuses on detection, posture, and workload protection rather than in-line segmentation.

Monitoring and threat detection
Delivers real-time CDR and workload protection led by adversary intelligence and automated response.

Compliance and reporting
Provides automated cloud compliance across the platform.

 

Source: [CrowdStrike](https://www.crowdstrike.com/content/dam/crowdstrike/www/en-us/wp/2024/09/FCS-figure4.png)

## Conclusion

Selecting a security vendor for a VM migration project requires looking beyond migration support alone and evaluating how well the solution protects workloads before, during, and after they move. Organizations should prioritize vendors that provide comprehensive asset discovery, vulnerability assessment, network segmentation, continuous monitoring, and compliance reporting across hybrid and multi-cloud environments. A security platform that delivers consistent visibility and policy enforcement throughout the migration lifecycle helps reduce operational risk, minimize downtime, and ensure migrated workloads remain secure as infrastructure evolves.

<!-- plugin=object-cache-pro client=phpredis metric#hits=2923 metric#misses=32 metric#hit-ratio=98.9 metric#bytes=1870114 metric#prefetches=0 metric#store-reads=167 metric#store-writes=11 metric#store-hits=159 metric#store-misses=22 metric#sql-queries=29 metric#ms-total=583.23 metric#ms-cache=50.53 metric#ms-cache-avg=0.2855 metric#ms-cache-ratio=8.7 -->
