Sysdig Usage Report Finds Shifting Container Security Left is Not Enough
13.1.2021 15:00:00 EET | Business Wire | Press release
Sysdig, Inc., the secure DevOps leader, today announced findings from its Sysdig 2021 Container Security and Usage Report. While usage reveals organizations are shifting left by scanning images during the build phase, DevOps teams are still leaving their environments open to attack. The report also looks at trends, finding a 310 percent growth in container density since 2017.
The fourth annual report reveals how global Sysdig customers of all sizes and across industries are using and securing container environments. This real-world, real-time data provides insight into usage of the nearly one billion containers Sysdig customers run yearly, including security risks, container utilization, and services used. Read the Sysdig 2021 Container Security and Usage blog.
Among its findings, the report states that while 74 percent of customers are scanning before deployment, still more than half (58 percent) of containers are running as root. There are some containers that should run as root—security and system daemons for example—but this is a small portion of total containers. These risky configurations leave easy access to potentially compromise the system and access sensitive data. This finding stresses the need for security throughout the lifecycle of a container image—fixing vulnerabilities is not enough.
Highlights From the Report
Container density grows 170% since 2018
Over the past three years, the median number of containers-per-host more than doubled from 15 in 2018 to 41 today, indicating a growth in efficiency and a shift in cost savings as containers mature. This reveals a continued focus on optimization.
Prometheus continues to grow, 35% YoY
Open source adoption is broader than just Kubernetes as organizations are shifting toward Prometheus as the standard approach to monitoring container environments. The use of Prometheus metrics among Sysdig customers grew 35 percent year-over-year.
Docker down, containerd and CRI-O up 4X
In 2017, Docker represented 99 percent of containers in use at that time. Today, that number has fallen to 50 percent, down from 79 percent in October 2019. While Docker revolutionized containers, organizations are rapidly switching to newer runtimes like containerd and CRI-O.
21% of containers live less than 10 seconds
The ephemeral nature of containers is a unique efficiency advantage, yet it can be a challenge in managing issues around security, health, and performance. The short life of containers reaffirms the need for container-specific tools for security and monitoring. For example, organizations need metric collection with intervals of less than 10 seconds and a detailed record of what occurred when the container was alive.
“With the high-profile breaches we are seeing and the accelerated adoption of containers in production, the container security risk is now on the radar of CISOs. Across millions of containers that we have studied, it’s clear that organizations are shifting security left, but they are neglecting critical best practices,” said Suresh Vasudevan, chief executive officer of Sysdig. “Container security has to span the entire software development lifecycle. Until organizations fix risky configurations, protect their runtime environments, and invest in container forensics, we will see an increase in container security breaches. I expect we will see several high-impact breaches before we release our next report.”
Other Interesting Findings
- Falco, the open source runtime project for cloud-native environments created by Sysdig and donated to the CNCF, has seen a 300 percent increase in Docker Hub downloads over the last year.
- The use of golang increased to 66 percent, a 470 percent jump since last year.
- 63 percent of container images are replaced within two weeks or less, signifying a more frequent code deployment rate.
Learn More About this Report
- Download the full Sysdig 2021 Container Security and Usage Report.
- Download the infographic.
- Read the usage report blog.
- Join the webinar Real-World Insights: Dig into Sysdig’s Container Security and Usage Report on Jan. 21 at 10am PST to walk through the report with the author.
About Sysdig
Sysdig is driving the secure DevOps movement, empowering organizations to confidently secure containers, Kubernetes, and cloud services. With the Sysdig Secure DevOps Platform, cloud teams secure the build pipeline, detect and respond to runtime threats, continuously validate compliance, and monitor and troubleshoot cloud infrastructure and services. Sysdig is a SaaS platform, built on an open source stack that includes Falco and sysdig OSS, the open standards for runtime threat detection and response. Hundreds of companies rely on Sysdig for container and Kubernetes security and visibility. Learn more at www.sysdig.com.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20210113005319/en/
Contact information
Amanda McKinney Smith
(703) 473-4051
amanda.smith@sysdig.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
H2SITE Secures New Strategic Investment to Accelerate Industrial Deployment of Hydrogen Production and Separation Solutions25.6.2026 07:00:00 EEST | Press release
H2SITE, a leading industrial company in hydrogen production and separation solutions, has completed a second closing of its Series B round. The transaction brings in EIC Fund with a private investor who will support the company’s next phase of growth and increases H2SITE’s total funding raised in this round to more than €42 million. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260624444396/en/ H2SITE These new partners, join BEV, Suma Capital, Hy24, Crane, Enagás Emprende, Calderion and CRPV who participated in the first closing, further validating the confidence of the European innovation ecosystem in H2SITE’s ability to industrialize and deploy key hydrogen solutions at commercial scale. Over the past years, H2SITE has successfully demonstrated the maturity and scalability of its technology, achieving more than 50,000 operating hours with its membrane reactors and separators, establishing advanced manufacturing capabilit
FPT Expands Strategic Collaboration with Microsoft to Advance AI Frontier Innovation Across Asia25.6.2026 05:00:00 EEST | Press release
FPT Corporation today announced an expanded strategic collaboration with Microsoft aimed at accelerating enterprise AI adoption and co‑innovation across Asia, with a strong focus on ASEAN, Japan, and South Korea. The collaboration brings together Microsoft’s global AI platforms with FPT’s large‑scale delivery and regional market capabilities to support organizations as they move from AI experimentation to real‑world, scalable impact, with measurable business outcomes. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260624200416/en/ Representatives of FPT and Microsoft at the signing ceremony, formalizing an expanded strategic collaboration to advance AI Frontier innovation across Asia The collaboration aligns with FPT’s AI‑First strategy and Microsoft’s vision for human‑agent collaboration, with the goal of enabling enterprises to redesign how work is done across engineering, operations, and business functions. Positioning FP
Murata Expands Product Information Management API Service to Cover All 73 Product Categories25.6.2026 05:00:00 EEST | Press release
Murata Manufacturing Co., Ltd. (TOKYO: 6981) (ISIN: JP3914400001) now covers all 73 product categories in its Product Information Management (PIM) API Service. By using this API service, engineers, developers, and procurement specialists can retrieve up-to-date product information, enabling prompt responses to product status changes and reducing the risk of component obsolescence. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260624146819/en/ [Murata Manufacturing Co., Ltd.] Murata expands Product Information Management API Service to cover all 73 product categories As digital transformation accelerates in the manufacturing industry, a wide variety of systems and platforms are being used across the entire workflow - from design and component selection through to procurement. Previously, Murata’s PIM API Service covered only surface-mount and leaded ceramic capacitors and inductors. This narrow service coverage required user
Swedish Court Further Reschedules Delivery of Judgment in PriceRunner Vs Google Antitrust Case24.6.2026 21:55:00 EEST | Press release
Klarna Group plc (NYSE: KLAR) wishes to update investors that the Patent and Market Court in Stockholm, Sweden (Patent- och marknadsdomstolen) has again postponed publication of its judgment in the antitrust damages proceedings brought by PriceRunner, a Klarna subsidiary, against Google. The Court has rescheduled publication of its judgment from June 26, 2026 to July 1, 2026 at 13:00 CET. As with the Court's two previous notifications, the rescheduling is a procedural decision by the Court and relates solely to the timing of the judgment delivery. In its notification, the Court cited high workload as the reason for needing additional time to finalize the judgment. No inference about the outcome should be drawn from it. Important Notice The outcome of the proceedings is inherently uncertain. No assurance can be given that PriceRunner will succeed on liability or quantum. Any award would be subject to appeal by Google, to sharing arrangements with former PriceRunner shareholders and Klar
Vertex Energy Announces 6,000 bpd Group III Base Oil Expansion Project24.6.2026 17:00:00 EEST | Press release
Vertex Energy, Inc. (“Vertex” or the “Company”) today announced it is advancing a project at its Mobile, Alabama refinery to produce crude-derived conventional Group III base oils through the Company’s existing hydrocracker and related processing infrastructure, providing lubricant manufacturers and blenders with an additional domestic source of high-quality Group III supply. The project is designed to add an incremental 6,000 barrels per day of conventional Group III production capacity and support production of 4 cSt, 6 cSt, and 8 cSt Group III base oils using an existing crude-derived hydrocracked vacuum gas oil stream produced at the Company’s Mobile, Alabama refinery. Combined with the Company’s existing re-refined Group III base oil production, this additional capacity is expected to make Vertex the leading Group III producer in North America. Vertex has completed preliminary design work and has procured a high-pressure lubricants hydrotreating unit. The Company plans to start pr
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
