We rolled out Cato SASE across 20 sites last year. The connectivity piece is rock solid. Zero issues with the global backbone, SD-WAN performance is exactly as advertised, and the PoP handoff is reliable.
But if you're buying this for advanced threat detection, look elsewhere. The IPS and threat intel are basic. Missed several command-and-control callbacks that other tools flagged. Their "deep packet inspection" seems to just be pattern matching. For a secure network core, it's fine. For active threat hunting, it's not enough.
show me the logs
So you paid for an all-in-one SASE platform but still needed separate tools for actual threat detection. That's a pretty expensive global router.
Did you ever get a breakdown of what portion of your annual spend was for the threat intel module versus the backbone connectivity? I've seen cases where just buying the SD-WAN and using a best-of-breed cloud sandbox ends up cheaper, with better results.
Show me the bill
That's a critical question, and one we did analyze before renewal. The threat intel module wasn't a separate SKU in our bundle; it was part of a consolidated "security service" tier. The real cost issue is the bundled pricing model itself.
In our case, we couldn't remove the threat module to pay less, it was all or nothing. Your point about combining their SD-WAN with a specialized cloud sandbox is valid, but introduces integration and management overhead they count on you wanting to avoid. The platform's value is in operational simplicity, not component depth. You're paying a premium for the unified console, even if parts of what it unifies are mediocre.
Check the SLA.
Thanks for sharing this, it's really helpful. We're looking at SASE platforms now and I've been worried about overselling on the security side.
When you say "deep packet inspection" seems like pattern matching, does that mean it can't catch zero-day stuff at all? Or just that it's slower to update? Trying to gauge if we'd need another tool right away, or if it's okay for a bit.
Your experience with the threat intel module is consistent with the bundled analysis I've seen from other SASE platforms. The pattern matching you describe is typically signature-based, which creates a significant gap in detection efficacy.
This is why we've benchmarked the total cost of ownership of bundled SASE security against a disaggregated model. For many organizations, paying for the all-in-one console and then layering a specialized, behavior-based EDR or NDR tool on top is actually cheaper than trying to force the native module to do a job it wasn't built for. The integration overhead is real, but the financial and detection math often works out.
Have you calculated what your effective cost per security alert was, given the misses you observed? That metric often clarifies whether the bundled premium is justifiable.
every dollar counts
Exactly. That's the real math they don't show you on the datasheet.
You're paying a tax for the single pane, but the glass is dirty. I ran that cost-per-alert calc last year on a different platform. The "effective" cost for a *validated* alert from the native tool was insane because the signal-to-noise was so bad and it missed the real stuff.
Integration overhead for a proper EDR is a weekend with their API, not a deal-breaker. The bundled model bets you're too lazy to do it.