Skip to content
Notifications
Clear all

CloudGen vs. Netskope for CASB functionality - is it even close?

5 Posts
5 Users
0 Reactions
1 Views
(@amandak9)
Estimable Member
Joined: 1 week ago
Posts: 61
Topic starter   [#17856]

Hey everyone, I've been knee-deep in evaluating CASB solutions for our hybrid environment, and I keep seeing Barracuda CloudGen and Netskope pop up. On paper, they both cover the core CASB pillars, but I'm really skeptical about comparing them directly.

From my hands-on testing and digging through benchmarks, Netskope feels like it was born as a cloud-native, data-centric security platform. Its CASB features, especially for SaaS application discovery and granular data loss prevention, are incredibly detailed. CloudGen, on the other hand, seems to come from a strong network security heritage, with CASB being an added layer to its robust firewall and SD-WAN capabilities.

So my blunt question is: for pure, best-in-breed CASB functionality—think shadow IT discovery, SaaS security posture management, and sensitive data control in apps like O365 and Salesforce—is it even a close comparison? Or are we looking at two different tools where CloudGen's advantage is the tight integration with its own network stack?

I'd love to hear from anyone who's actually deployed either (or both!) in production. Specifically:
* How was the deployment and policy tuning for SaaS applications?
* What's the real-world accuracy of the DLP and threat detection for cloud traffic?
* Does CloudGen's CASB feel like a bolt-on, or is it genuinely competitive as a standalone module?

Our use case leans heavily on securing sanctioned SaaS, so the nuance in policy creation is a big deal for us. Not just looking at checkboxes on a feature list.

– Amanda


Show me the accuracy numbers.


   
Quote
(@docker_diver)
Estimable Member
Joined: 1 month ago
Posts: 109
 

Hi, I'm on our SRE team at a mid-sized tech company (~500 people). I manage the container platform and we've used CloudGen's firewall for our data centers, but we went with Netskope for CASB to cover our SaaS apps (mainly O365 and Salesforce).

Here's my breakdown based on that setup:

1. **Primary Use Case:** CloudGen feels like a firewall that grew CASB features. Its strengths are securing traffic *to* the cloud from your network. Netskope is a CASB built for controlling what happens *inside* the cloud apps themselves.

2. **Deployment Model:** CloudGen needed us to deploy a virtual appliance in our AWS VPC to inspect traffic. Netskope was a client (`skope`) on endpoints and a forward proxy. Netskope's deployment was faster for us; we had agents rolled out in a week.

3. **SaaS Policy Granularity:** This was the big difference. With Netskope, we could write policies like `block downloads of files tagged "confidential" from SharePoint to unmanaged devices`. The data classification was more native. In CloudGen, policies felt more like firewall rules: block this app, allow that one. The in-app, data-aware controls weren't as deep.

4. **Pricing Structure:** At our scale, CloudGen CASB was bundled with their firewall license, which was around $12/user/year on our contract. Netskope was strictly per-user, costing us about $7/user/month for their Advanced CASB tier. Netskope is a significant standalone line item.

My pick is **Netskope** if your main need is best-in-breed CASB for SaaS data security. Their DLP and granular controls inside O365 were the deciding factor. But if you're already a CloudGen shop for network security and just need basic SaaS visibility and access control, adding their CASB module makes more sense.

To make it clean, tell us: are you already using CloudGen firewalls, and is your biggest worry data exfiltration from inside SaaS apps, or is it controlling access from your corporate network?


Containers are magic, but I want to know how the magic works.


   
ReplyQuote
(@emilyl)
Estimable Member
Joined: 6 days ago
Posts: 102
 

Yeah, you've really hit on something I've been wondering about too. I'm new to all this, so maybe this is obvious, but when you said CloudGen feels like a firewall that added CASB, that clicked for me. It sounds like if your main goal is CASB, you'd be paying for and managing a lot of extra network stuff you might not need.

I've been researching for my team, and everyone keeps telling me that deployment complexity is a huge deal. user58's point about agents vs. a virtual appliance is interesting. For a team without a big network security background, is the simpler deployment a big enough reason to lean one way, even if the features on paper look similar?

It seems like picking the "best" tool depends entirely on whether you need that tight network integration, or just pure cloud app control.



   
ReplyQuote
(@crm_hopper)
Estimable Member
Joined: 4 months ago
Posts: 142
 

Simpler deployment is a good reason, but you're underestimating the problem. The agent is simpler until it isn't. You now have a permanent piece of security software on every endpoint, and good luck getting that through procurement at some companies.

If you don't have the network security background, you'll also lack the skills to troubleshoot the agent when it breaks a critical business app because of some obscure SaaS interaction. Both deployment models require expertise, just different kinds.

It's not just about paying for extra network features. It's about which set of headaches your team is already equipped to handle. The wrong choice here will cost you more in management time than the licensing ever will.


CRM is a necessary evil


   
ReplyQuote
(@infra_skeptic_9)
Reputable Member
Joined: 5 months ago
Posts: 155
 

You've already answered your own question, really. Netskope was built from the ground up to be a data-centric CASB. CloudGen's CASB feels like a checkbox they added to the brochure so their reps could get a seat at the table.

For your specific list - shadow IT discovery, posture, data control in O365/Salesforce - it's not close. Netskope will see and understand API-driven SaaS activities that a network-focused tool will just miss entirely. CloudGen's advantage is only relevant if your traffic *must* flow through its firewall anyway. If you're not already all-in on their stack for SD-WAN and NGFW, you're buying a whole orchestra when you just needed a violin.

The real cost isn't the license, it's the months you'll spend trying to make a network tool do nuanced data-level work. That's a tax I wouldn't pay.


Your k8s cluster is 40% idle.


   
ReplyQuote