What Is Deep Security Cloud One?
Deep Security Cloud One is Trend Micro's integrated cloud‑native security suite that protects virtual machines, containers, serverless functions, and SaaS workloads across the major public clouds. It consolidates anti‑malware, intrusion detection and prevention, web reputation, firewall, integrity monitoring, and vulnerability management into one centrally managed console, eliminating the need for point solutions.
- What Is Deep Security Cloud One?
- Key Modules and Capabilities
- Supported Cloud Environments
- How Deployment Works
- 1. Agent‑Based Protection
- 2. Agent‑less (API‑Only) Scanning
- 3. Hybrid Model
- Pricing and Licensing Overview
- Benefits Over Point Solutions
- Implementation Checklist
- Common Questions
- Is Deep Security Cloud One a replacement for native cloud security tools?
- Can I integrate Cloud One with SIEM platforms?
- What is the latency impact of agents?
More from this site
Keep reading the latest coverage
Key Modules and Capabilities
Cloud One is organized into discrete, API‑driven modules that can be enabled individually or as a full‑stack solution.
- Workload Security – Real‑time anti‑malware, IDS/IPS, and host‑based firewall for VMs, containers, and serverless code.
- Network Security – Cloud‑native micro‑segmentation and virtual firewall to control East‑West traffic.
- Posture Management – Continuous compliance checks against CIS, NIST, and PCI benchmarks.
- Application Security – Web‑application firewall (WAF) and API protection for SaaS and custom apps.
- File Storage Security – Scans and encrypts data in S3, Azure Blob, and Google Cloud Storage.
Supported Cloud Environments
Deep Security Cloud One is built for the three leading public‑cloud providers and integrates with their native services.
| Cloud Provider | Integration Points | Typical Use Cases |
|---|---|---|
| AWS | EC2, EKS, Lambda, S3, GuardDuty API | VM protection, container security, serverless hardening |
| Microsoft Azure | VMs, AKS, Functions, Blob Storage, Azure Security Center API | Hybrid VM workloads, Kubernetes security |
| Google Cloud Platform | Compute Engine, GKE, Cloud Functions, Cloud Storage, Chronicle API | Container hardening, serverless compliance |
How Deployment Works
Customers can choose between three deployment models:
1. Agent‑Based Protection
Lightweight agents are installed on each workload (VM, container, or function). Agents communicate with the Cloud One console via secure TLS, receive policy updates, and report telemetry.
2. Agent‑less (API‑Only) Scanning
For serverless functions and storage buckets, Cloud One invokes the Trend Micro scanning engine through cloud provider APIs, eliminating the need for a persistent agent.
3. Hybrid Model
Enterprises with mixed legacy and cloud‑native assets often run agents on long‑lived VMs while using API‑only scans for transient containers and functions.
Pricing and Licensing Overview
Trend Micro offers subscription‑based pricing per workload unit (per VM, per container, or per function). Discounts are available for multi‑year contracts and large‑scale deployments. Exact rates vary by region and volume, so customers should request a quote from an authorized reseller.
Benefits Over Point Solutions
- Unified Visibility – One console aggregates alerts, compliance reports, and inventory across all clouds.
- Reduced Operational Overhead – Central policy management eliminates duplicate rule sets.
- Scalable Automation – Terraform, CloudFormation, and Azure Resource Manager templates can provision agents and policies as code.
- Continuous Compliance – Built‑in benchmarks auto‑remediate drift.
Implementation Checklist
Before rolling out Deep Security Cloud One, consider the following steps:
Common Questions
Is Deep Security Cloud One a replacement for native cloud security tools?
It complements native services. Cloud One adds deep‑packet inspection, malware detection, and granular compliance that many provider‑built firewalls do not offer.
Can I integrate Cloud One with SIEM platforms?
Yes. Cloud One streams logs to Splunk, QRadar, Azure Sentinel, and other SIEMs via syslog, REST API, or native connectors.
What is the latency impact of agents?
Agents are designed for minimal overhead—typically <1% CPU and <5 ms network latency per scan—though exact impact depends on workload intensity.