Cybermatch

The Cybermatch taxonomy

Every category we track

16 cybersecurity software categories, each with its own definition, criteria, and shortlist. Pick a category below to compare vendors side by side.

WAF

Web Application Firewall (WAF)

Web Application Firewall tools help security teams protect web applications by inspecting HTTP and HTTPS traffic before it reaches the app. They are used to block or challenge malicious requests, reduce exposure to common web attacks, and apply temporary protection while engineering teams fix the underlying issue. A WAF is not a replacement for secure development, vulnerability management, or application testing. Its value is in adding a control point in front of web applications, especially public-facing apps, legacy systems, commercial software, and high-traffic services where every fix cannot happen immediately. The category varies a lot. Some products are managed rule sets attached to a CDN, cloud load balancer, or ingress controller. Others are part of a broader WAAP platform that also includes DDoS protection, bot management, API protection, rate limiting, and fraud or abuse controls. Cybermatch helps teams compare WAF tools by looking at how they are deployed, what they protect against, how much tuning they need, and how well they fit into the team’s existing application and security workflows.

Explore
AI TRiSM

AI TRiSM

AI TRiSM, or AI Trust, Risk, and Security Management, tools help security, risk, and AI teams govern, test, secure, and monitor AI systems in production. The category has become more important as organizations move beyond isolated AI experiments and start deploying LLM applications, RAG pipelines, copilots, embedded AI features, and autonomous agents. These systems create risks that do not fit neatly into traditional AppSec, cloud security, GRC, or MLOps workflows. A model can leak sensitive data, follow malicious instructions, rely on untrusted retrieved content, behave differently after a model update, or call tools in ways the business did not intend. AI TRiSM tools do not all solve the same problem. Some are closer to governance platforms. Some focus on LLM security testing and runtime protection. Others are built for model monitoring, compliance evidence, or agentic AI control. The right product depends on what the organization needs to manage: regulatory exposure, AI asset sprawl, model supply chain risk, prompt injection, hallucination, agent permissions, or all of the above. CyberMatch helps security teams compare AI TRiSM tools by the capabilities that matter in real deployments: what they discover, what they test, what they block, what evidence they produce, and how much operational effort they require.

Explore
API

API security

API security platforms help teams discover, assess, and protect the APIs that underpin modern applications, services, and integrations. As organizations adopt microservices, agentic AI workflows, and machine-to-machine integrations, APIs have become the primary attack surface. Traditional security tools often fail to cover business logic and contextual authorization, leaving sensitive data exposed. These platforms provide deep visibility into the API inventory, how endpoints are exposed (internal vs. external), and how they are consumed by both humans and autonomous machines. Where traditional web security focuses on front-end vulnerabilities or "known bad" signatures, API security is designed for modern ecosystem realities: Stateful Analysis: Detecting attacks that look like legitimate traffic but exploit the order or logic of API calls. Machine Identities: Validating mTLS and certificate-bound tokens for non-human callers. Schema & Spec Drift: Continuously comparing live traffic against OpenAPI/Swagger specs to identify undocumented changes. Agentic AI Risk: Protecting against prompt injection or data exfiltration via AI-integrated endpoints (e.g., Model Context Protocol).

Explore
APT

Automated Penetration Testing

Automated penetration testing platforms continuously emulate real-world attackers against your assets, so you’re not limited to waiting for an annual red team or manual penetration test to understand your exposure. Instead of static vuln scan results, these tools chain misconfigurations, exploits, and attack paths to show how an attacker could move through your environment – and what to fix first. Where traditional vulnerability scanners focus on breadth of detection, automated pen testing aims to validate exploitability and business impact. The best tools combine attack simulation, safe exploitation, and clear remediation guidance, integrated into your existing pipelines and workflows.

Explore
BP

Brand Protection

Brand Protection tools help security and fraud teams find and remove external abuse of their brand. That usually includes lookalike domains, phishing sites, fake social media accounts, rogue mobile apps, counterfeit listings, and other scams that use the company’s name, brand assets, or executive identities to trick customers, employees, or partners. For most teams, this is not just a brand or marketing problem. Brand abuse is often part of phishing, payment fraud, account takeover, and impersonation campaigns. The job of a Brand Protection platform is to give teams visibility into that activity, enough context to assess what is actually malicious, and a practical way to get it taken down. Cybermatch helps teams compare Brand Protection software more systematically. Buyers can look at how well each product covers the channels they care about, how effectively it separates real threats from background noise, how strong its takedown workflows are, and how much effort it takes to run day to day. That matters because this category is not just about finding suspicious domains. Teams also need to investigate incidents quickly, collect usable evidence, prioritise what matters, and push cases through to remediation.

Explore
CIG

Cloud Identity Governance (CIG)

Cloud Identity Governance platforms provide security and identity teams with a unified, continuous view of who has access to what across cloud providers, SaaS applications, and identity stores, and whether that access is appropriate. Instead of spreadsheet-driven access reviews and one-off IAM audits, CIG tools continuously ingest entitlements, groups, and roles to surface toxic combinations, privilege creep, and access that no longer matches a user’s role. Traditional IGA was built around on-prem directories and a small set of core apps. Cloud Identity Governance extends that model to multi-cloud and SaaS environments where access is spread across IAM roles, SaaS tenants, and ephemeral resources. Legacy IGA platforms remain strong at workflow (joiner/mover/leaver, approvals, attestations) but often struggle with cloud entitlements such as thousands of granular permissions, Kubernetes roles, and SaaS-specific privilege models. CIG platforms specialise in discovering and normalising these entitlements, analysing risk, and feeding decisions back into IGA or ITSM for approvals and lifecycle.

Explore
CNAPP

CNAPP (Cloud Native Application Protection Platform)

Cloud-native application protection platforms bring together multiple cloud security capabilities in one place. They typically include CSPM, CWPP, CIEM, and sometimes DSPM. The goal is to provide security and platform teams with a connected view of risk across cloud accounts, workloads, and the software delivery lifecycle, rather than juggling separate tools for misconfigurations, vulnerabilities, and excessive entitlements. Standalone CSPM focuses on configuration drift in cloud services. CWPP protects workloads at runtime. CNAPP sits above both. It correlates findings across build, deploy, and run so you can see how issues in IaC templates, container images, Kubernetes manifests, live workloads, identities, and data stores combine into practical attack paths rather than isolated alerts. Modern CNAPP platforms also add “shift-left” controls by integrating with source control and CI systems. This lets teams fail builds or block deployments when critical policies are violated, and reserve runtime controls for catching what slips through. For leadership, that means a clearer story: which cloud risks matter most, where they sit in the lifecycle, and who owns the fix.

Explore
ES

Endpoint Security

Endpoint Security software helps security and IT teams protect laptops, desktops, servers, and other managed endpoints from malware, ransomware, exploitation, credential theft, and hands-on-keyboard attacker activity. For most organizations, endpoints are still where many attacks become real. Users open files, run browsers, authenticate into SaaS tools, connect from unmanaged networks, and move between office, remote, and cloud environments. That makes endpoint security a core control point for preventing compromise, detecting suspicious behavior, and responding quickly when something gets through. Modern Endpoint Security platforms usually combine prevention, detection, investigation, and response. At the prevention layer, they may include next-generation antivirus, exploit protection, host firewall controls, device control, and ransomware protection. At the detection and response layer, they often include EDR-style telemetry, behavioral detections, process timelines, endpoint isolation, remote remediation, and integrations with SIEM, SOAR, identity, and XDR workflows. CyberMatch helps teams compare Endpoint Security software more systematically. Buyers can assess how well each product protects the operating systems and workloads they actually run, how useful its detection and investigation workflows are, how much noise it creates, and how practical it is to operate at scale. That matters because endpoint security is not just about blocking malware. Teams also need visibility into attacker behavior, fast containment options, manageable policies, clean reporting, and a deployment model that does not create friction for IT or end users.

Explore
EASM

External Attack Surface Management (EASM)

External Attack Surface Management platforms continuously map and monitor your organisation’s internet-facing footprint from an attacker’s point of view. Instead of relying on internal CMDBs and manually maintained asset lists, EASM tools discover domains, subdomains, IP ranges, services, certificates, and common SaaS usage to reveal unknown or unmanaged assets—common initial breach points. Traditional vulnerability scanning assumes you already know what to scan and where it lives. EASM starts earlier. It focuses on discovery and attribution: finding assets that appear to belong to your organisation and tying them back to owners, environments, and business units. Modern platforms then layer exposure analysis, risk scoring, and alerting on top so security teams can drive remediation by the teams that actually control those assets. For leadership, EASM provides a way to talk about external risk in concrete terms: how many internet-facing assets you have, which ones are most exposed, and how that picture is changing over time.

Explore
SSPM

SaaS security posture management (SSPM)

SaaS security posture management (SSPM) platforms help security teams continuously assess and improve the security configuration of business-critical SaaS applications. As organisations adopt more SaaS tools across collaboration, CRM, HR, ITSM, development, and storage, security settings, admin roles, integrations, and data-sharing controls can drift away from policy over time. SSPM provides visibility into that posture and highlights misconfigurations, excessive access, risky third-party connections, and policy violations. Traditional security tools often have limited insight into the configuration layer of SaaS applications. They may detect identity issues, endpoint compromise, or network activity, but they do not always show whether MFA is enforced for admins, external sharing is overly permissive, audit logging is disabled, or OAuth apps have been granted unnecessary privileges. SSPM is designed to close that gap by continuously checking SaaS environments against security best practices and internal standards. For leadership, SSPM offers a way to reduce SaaS-related risk without relying on manual reviews of every application. It gives teams a clearer picture of configuration hygiene across the SaaS estate, helps prioritise high-impact issues, and supports more consistent governance as SaaS adoption grows.

Explore
SM

Secret Management

Secret Management platforms help organizations securely store, control, and monitor access to sensitive machine credentials such as API keys, database passwords, tokens, certificates, and encryption keys. Rather than letting secrets sit across code repositories, CI/CD pipelines, configuration files, collaboration tools, or manually managed vaults, these platforms provide a central system for storing, issuing, rotating, and auditing the credentials used by applications, infrastructure, and automation. Traditional privileged access tools were built mainly for human administrators and long-lived credentials. Secret Management addresses a different challenge: protecting non-human identities and the secrets they rely on across cloud, containerized, and DevOps environments. Modern platforms are designed to reduce secret sprawl, enforce least-privilege access, automate rotation, and make sure credentials are only available to the workloads and systems that genuinely need them. Many also support dynamic secrets, short-lived credentials, and policy-based access controls to limit the impact of credential theft or reuse after compromise. For leadership teams, Secret Management offers a clearer view of credential risk. It helps answer practical questions such as where sensitive secrets are stored, which teams and systems depend on them, whether access is governed consistently, and how quickly exposed or overprivileged credentials can be rotated, revoked, or replaced.

Explore
SASE

Secure Access Service Edge (SASE)

Secure Access Service Edge (SASE) platforms combine networking and security functions into a cloud-delivered service that connects users, devices, branch offices, and applications through identity- and policy-based controls. In practice, SASE brings together capabilities such as SD-WAN, secure web gateway (SWG), cloud access security broker (CASB), firewall as a service (FWaaS), and zero trust network access (ZTNA), delivered through a distributed cloud architecture rather than a stack of separate on-premise appliances. Traditional network security models were built around the corporate data center, backhauling traffic through centralized firewalls and VPN concentrators before users could reach applications. SASE addresses a different operating model: users are distributed, applications are increasingly cloud-hosted, and access decisions need to follow identity, device posture, location, and business policy rather than network location alone. Modern SASE platforms are designed to reduce reliance on legacy VPNs, improve visibility across hybrid environments, and apply security controls consistently across branch, remote, and cloud access. For leadership teams, SASE provides a practical way to evaluate how securely and efficiently the organization connects people and sites to business resources. It helps answer questions such as whether remote and branch access are governed consistently, how internet and SaaS traffic is protected, whether performance is acceptable for global users, and how well the organization can enforce policy without adding more fragmented point products.

Explore
TPRM

Third-Party Risk Management

Third-Party Risk Management (TPRM) is essentially the process of ensuring your partners’ security gaps don’t become your own. Since modern businesses outsource everything from cloud hosting and payment processing to basic HR functions, the traditional security perimeter has effectively disappeared. If a key vendor goes down or gets breached, your business stops. That makes TPRM a core governance problem rather than just a procurement hurdle. It is about moving from a "check-the-box" onboarding task to a continuous cycle of oversight.

Explore
vCISO

VCISO Platform

vCISO Platforms help organizations and service providers operationalize cybersecurity leadership through software. Rather than relying on scattered spreadsheets, slide decks, ticket queues, and point tools to manage assessments, risks, policies, compliance work, and executive reporting, these platforms provide a central system for structuring and tracking the work typically led by a virtual CISO or security advisory function. Common capabilities include risk registers, security assessments, compliance mapping, policy management, remediation planning, continuous monitoring, and customer- or leadership-facing reporting. Traditional security leadership has often depended on manual consulting workflows and disconnected GRC processes. vCISO Platforms address a different challenge: how to deliver repeatable, scalable cybersecurity governance and program management across one organization or many clients without losing visibility, consistency, or strategic alignment. Modern platforms are designed to standardize assessments, prioritize remediation, map work to frameworks, and turn security findings into structured plans that both technical teams and business stakeholders can follow. Many also support continuous evidence collection, recurring reviews, third-party risk workflows, and board-ready reporting so security leadership is not rebuilt from scratch each quarter. For leadership teams, a vCISO Platform provides a clearer view of security program maturity and decision-making. It helps answer practical questions such as what the biggest risks are, which remediation actions matter most, how compliance efforts map to real security work, whether security activities are progressing on schedule, and how to communicate program status to executives, boards, customers, or auditors.

Explore
XDR

XDR (Extended Detection and Response)

Extended Detection and Response (XDR) software helps security teams detect, investigate, and respond to attacks that move across more than one part of the environment. Where endpoint tools see a process and email tools see a message, XDR platforms correlate telemetry from endpoint, identity, email, network, cloud, and SaaS into a single incident, so an analyst sees one attack rather than six disconnected alerts. That correlation is the point: modern intrusions rarely stay on the surface where they started, and the gaps between tools are where attackers operate with the least friction. A typical XDR platform combines telemetry ingestion and normalization, cross-domain detection logic, automated correlation into prioritized incidents, guided investigation with attack timelines, and response actions that reach back into the connected tools — isolating a host, disabling an account, quarantining a message, or triggering a SOAR playbook. Most map detections to MITRE ATT&CK, and many now bundle AI-assisted triage to reduce the manual work of sorting alerts. Products in this market differ sharply on one axis in particular: whether they are open (ingesting third-party telemetry from tools you already run) or native (delivering their strongest results when paired with the same vendor's endpoint, email, and firewall products). The market is also converging with SIEM, and several vendors here now position a single platform that covers both real-time detection and long-term log retention. CyberMatch helps teams compare XDR platforms on what actually matters in operation: which data sources they genuinely correlate, how much of the triage is automated versus assumed, what response actions are available without leaving the console, and how well the platform fits the security stack already in place.

Explore
DAM

DAM (Database Activity Monitoring)

Database Activity Monitoring (DAM) software watches how users, applications, and administrators interact with a database in real time — every query, every login, every schema change — independent of the logs a database engine keeps for itself. That independence matters: native logs are easy for a privileged account to disable or tamper with, while a DAM tool captures activity at the network layer, through an agent, or via API integration with the database or cloud provider, then flags anomalous access, blocks dangerous statements, and alerts a security team before data leaves the building. Because databases hold the structured records regulators care about most — cardholder data, health records, financial statements, personal information — DAM sits at the center of compliance programs for PCI-DSS, SOX, GDPR, and HIPAA, producing the audit trails auditors ask for and the detail needed to investigate a breach. It is often a defense against people already inside the perimeter: database administrators and other privileged accounts routinely have broad access that application-layer controls never see, and DAM is built to notice when that access turns into abuse, whether through carelessness, credential theft, or insider intent. The market is splitting between legacy, agent-heavy platforms built for on-premises estates and newer, agentless, cloud-native tools that cover thousands of managed and unmanaged databases with near-zero overhead, and many vendors now bundle DAM with data discovery, classification, and posture management rather than sell it standalone. CyberMatch helps teams compare DAM vendors on what actually differs in practice — deployment model, database and cloud coverage, how alerts get enforced, and how the platform fits the rest of a data security stack.

Explore