Skip to content
Notifications
Clear all

Hot take: Cato's network is good, but their CASB module is half-baked.

3 Posts
3 Users
0 Reactions
1 Views
(@infra_auditor_nina)
Reputable Member
Joined: 4 months ago
Posts: 159
Topic starter   [#18807]

Alright, let's get this out there before the fanboys pile on. I've been running Cato SASE for about 18 months now. The core network overlay? Solid. Latency is predictable, their PoP redundancy is decent, and the firewall-as-a-service logic works as advertised. It's the network part.

But then there's the CASB module. We pushed for it to get that "single pane" SASE dream. Big mistake, or at least a premature one.

Here's the rub: it feels bolted on as a checkbox feature. The API-based discovery is shallow compared to dedicated CASB players. We found major gaps in context for sanctioned apps, and the unsanctioned app shadow IT report? Basically just a list of domains. You get things like:

* `slack-enterprise.s3.amazonaws.com` flagged as "unsanctioned" because it's an AWS domain, with zero correlation that this is actually our legitimate Slack data.
* Custom OAuth scopes for in-house apps? Good luck. The policy engine falls apart.

Their response in the ticket was essentially, "The network sees the domain, and the domain is not on the pre-approved list." That's not CASB, that's a glorified DNS filter.

And don't get me started on the remediation workflows. It's either "block" or "allow." No nuanced steps like "quarantine" or "require re-authentication" for sensitive actions. The logging for CASB-specific events is buried in the general activity log, so good luck building a clear audit trail for compliance (looking at you, SOC 2).

I'll admit, the *convergence* is tempting—having the network path and the CASB signal come from the same vendor. But right now, you're paying a premium for a feature set that's about 40% baked.

So, question for the room:
* Is anyone actually using their CASB in production for more than just basic shadow IT reporting?
* Have they improved the O365/AWS integrations beyond the surface level in the last quarter?
* Am I being too harsh, or is this just the reality of SASE vendors trying to do everything at once?

- Nina


- Nina


   
Quote
(@cloud_ops_learner)
Reputable Member
Joined: 2 months ago
Posts: 143
 

I'm fairly new to the cloud ops scene and we're actually evaluating Cato right now. The network part sounds great but your CASB experience gives me pause. We're a small shop with a few custom OAuth apps and I don't want to end up in a situation where the "single pane" turns into a single pain. Did you end up keeping Cato for the network and running a separate CASB, or are you looking at a different SASE stack altogether?


Still learning


   
ReplyQuote
(@jacksonr)
Estimable Member
Joined: 1 week ago
Posts: 66
 

Yep, the network/security split in these single-vendor platforms is real. That 'glorified DNS filter' line nails it. We tried the CASB module about a year ago and had the same issue with sanctioned SaaS apps.

Our fix was to keep Cato for the network overlay and pair it with a lightweight, API-only CASB for the actual app context and OAuth governance. It added maybe 15% to our overall cost, but the visibility jump was massive. You lose the "single pane" dream, but you gain actual control.


Right-size everything


   
ReplyQuote