Skip to content
Notifications
Clear all

Thoughts on the new Cato XDR add-on? Pricing seems steep.

2 Posts
2 Users
0 Reactions
0 Views
(@gracej)
Reputable Member
Joined: 3 weeks ago
Posts: 199
Topic starter   [#23961]

Everyone's rushing to pile XDR onto their SASE platform, and Cato's new add-on is the latest bandwagon. I've spent the last week dissecting the announcement and the preliminary pricing sheets, and the prevailing sentiment seems to be uncritical acceptance. Let's apply some pressure.

The core issue isn't whether XDR is a useful capability—it can be—but whether this specific implementation justifies its cost structure. Cato is essentially asking for a significant premium on top of an already comprehensive SASE subscription. For what? To correlate data they are already ingesting for their SWG, FWaaS, and ZTNA services. The marginal cost to them for this functionality is not zero, but it certainly isn't aligned with the 30-40% uplift I'm hearing about. This is a classic vendor lock-in play: you're already deep in their ecosystem for network security, so the perceived ease of adding their XDR becomes a siren song, obscuring the total cost of ownership over a 3-5 year period.

Consider the practicalities. Their XDR is, by definition, limited to the data sources Cato controls. What about your cloud workloads in Azure or AWS that aren't routed through Cato PoPs? What about your on-premises server security events from a niche system? A robust XDR strategy requires breadth, and a network-centric vendor will always prioritize their own telemetry. You are paying a steep price for a potentially incomplete picture. Furthermore, have you seen the contractual terms for add-ons like this? They often have their own minimum commit periods and renewal escalators, further cementing you into their stack.

I would urge anyone considering this to run a parallel proof-of-concept with a dedicated, best-of-breed XDR platform that can ingest Cato logs as one source among many. Compare the alert quality, the investigation workflows, and the actual, all-in cost. The hidden cost of migration down the line, when you might want to switch SASE providers but find your threat detection logic and historical data siloed inside Cato, could be enormous. This isn't about the technology being bad; it's about the business model being optimized for vendor capture, not for providing you with the most effective and flexible security posture.

Just my two cents


Skeptic by default


   
Quote
(@devops_dad_joke)
Estimable Member
Joined: 5 months ago
Posts: 156
 

You're absolutely right about the data silo. If I'm already shipping logs from my k8s clusters and cloud accounts to a dedicated SIEM, paying extra for a separate XDR that only sees my north-south traffic feels like paying for a car but then renting the steering wheel separately. The integration tax is real.

Where I see it maybe making sense is for a team that's *all in* on Cato for everything and has zero other telemetry pipelines. But even then, that price hike is a tough pill to swallow for a single pane of glass that's missing a few window panes.



   
ReplyQuote