CASB

by Amal Joby
A cloud access security broker (CASB) is software that secures user access to cloud apps. Learn how CASBs work, their four pillars, and key benefits.
Amal Joby
AJ

Amal Joby

Amal is a Research Analyst at G2 researching the cybersecurity, blockchain, and machine learning space. He's fascinated by the human mind and hopes to decipher it in its entirety one day. In his free time, you can find him reading books, obsessing over sci-fi movies, or fighting the urge to have a slice of pizza.

Last updated: August 10, 2026

What is a CASB?

A cloud access security broker (CASB) is a software tool or service that sits between users and cloud applications and enforces an organization's security, compliance, and governance policies, letting companies use cloud services safely while protecting sensitive data against threats.

In other words, CASBs help secure the connections between employees (end users) and cloud service providers. They can protect the connected devices and data from malware and cloud-based threats, identify malicious actors based on abnormal behavior, and alert IT administrators. In doing so, a CASB gives organizations both visibility and control over how their cloud environment is actually used.

How does a CASB work?

A CASB works by sitting between users and cloud services, inspecting the traffic and data that flow between them. It enforces policy through one of three deployment modes: a forward proxy, a reverse proxy, or application programming interface (API) scanning.

A forward proxy uses an agent on the user's device to route cloud traffic through the CASB in real time, which suits managed devices, while a reverse proxy routes traffic without an agent and fits unmanaged or bring-your-own devices. API scanning instead connects directly to cloud apps to inspect data at rest and past activity out of band, and many modern CASBs combine these modes in a single deployment. Whichever mode is used, the CASB applies controls like encryption, access rules, and data loss prevention (DLP), and logs activity so teams can investigate risk and prove compliance.

What are the types of CASB?

The types of CASB are API-only, multi-mode first-generation, and multi-mode next-generation, each defined by its architecture.

  • API-only CASB: This type of CASB architecture offers management abilities by remediating data leakage post the occurrences. API-only CASB does not operate in real time and does not offer identity control or zero-day threat protection. Most API-only CASB tools will offer DLP software features, enabling administrators to set policies to detect compliance violations.
  • Multi-mode first-gen CASB: This CASB architecture type offers both administration and security, but doesn’t offer zero-day protection. It requires proxy agents (a network management element acting as a middleman between an unmanaged device and a management system) on every device, which may cause interference with existing infrastructure, for example, secure web gateway proxies.
  • Multi-mode next-gen CASB: This type of CASB architecture offers administration, security, and zero-day protection. It can dynamically adapt to provide protection for both known and unknown malware and data leakage risks on any application. It has integrated identity control and allows both agent-based and agent-less operation modes.

Increasingly, a CASB is delivered not as a standalone product but as a capability within broader security service edge (SSE) and secure access service edge (SASE) platforms, where it works alongside other cloud security services.

What are the four pillars of a CASB?

The four pillars of a CASB are visibility, data security, threat protection, and compliance, which together form the backbone of any CASB solution.

  • Visibility: A CASB can help organizations gain visibility into cloud application account usages, including information about who uses which cloud services, from which devices, and their departments and locations. A CASB may also provide useful financial information, such as reports on cloud spending.
  • Data security: Data security is achieved by incorporating advanced data loss prevention techniques, such as creating digital fingerprints of protected information. When sensitive data is discovered in the cloud or found on its way to the cloud, the CASB should offer the IT department the necessary options to instantly transfer suspected violations to on-premises systems for further analysis.
  • Compliance: When companies transfer data to the cloud, they should ensure they comply with requirements such as HIPAA, PCI, SOX, GDPR, and other regional regulations. CASBs can ensure full compliance with such regulations and help benchmark a company’s security configurations against regulatory requirements such as ISO 27001, CJIS, PCI DSS, and MAS.
  • Threat protection: Employees can be negligent when it comes to spreading malware and other risks through cloud services. A CASB can protect companies from such cloud risks.

What are the benefits of using a CASB?

The benefits of using a CASB are preventing security threats, preventing data leakage, uncovering shadow IT, and detecting risky user behavior. Together, they make cloud services safer to use and make practices like bring your own device (BYOD) more feasible.

  • Prevent security threats: CASB tools can help organizations defend against various threats. In most cases, these solutions help prevent or mitigate threats, including phishing, account takeover, and malware. Most CASB solutions can also help detect new cloud risks.
  • Prevent data leakage: All data stored should be secured, and some data, for example, sensitive data, requires an extra level of protection. CASB products allow businesses to enforce user permission policies, restricting data from unauthorized access. This can control external file sharing. Datasets classified as “sensitive” may receive additional protection.
  • Uncover shadow IT: As mentioned earlier, shadow IT refers to IT systems deployed without the knowledge of the IT department. Although many might argue that shadow IT speeds up innovation, improves business operations, and more, it can lead to numerous cybersecurity and compliance risks. It can also lead to user experience and performance issues. A CASB solution can help uncover shadow IT.
  • Detect risky user behavior: The anomaly detection features of CASB software solutions are useful to monitor user behavior, compare it with benchmark patterns, and flag abnormal activities. Additionally, CASB tools can discover cloud applications and services that employees utilize the most.

On G2, CASB reviewers most consistently highlight the same wins: visibility into cloud and SaaS usage, discovery of shadow IT and unsanctioned AI apps, and DLP controls, with Netskope One Platform, Microsoft Defender for Cloud Apps, and Trend Micro Cloud App Security among the most-reviewed tools in the category.

What is the difference between a secure web gateway and a CASB?

The difference between a secure web gateway (SWG) and a CASB lies in their focus: an SWG secures and filters users' web traffic, while a CASB secures users' access to cloud and SaaS applications and the data within them. Both are a step up from firewalls and offer data and threat protection, but they operate at different layers.

Secure web gateway (SWG) CASB
Protects users from malware and malicious websites by scanning and filtering web content, spam, viruses, and dangerous URLs. Controls how users reach cloud and SaaS apps and protects the sensitive data inside them.
Enforces policy for safe, compliant web browsing across the organization. Provides visibility, DLP, and threat protection specific to cloud app usage.
Best for promoting safe general internet usage. With native API integration, offers more granular protection for cloud-based data.

What is the difference between a CASB and SASE?

A CASB deals specifically with cloud and SaaS usage, while SASE is a broader architecture that combines networking and security and includes CASB capabilities. SASE typically converges SD-WAN, SWGs, zero-trust network access, and a CASB into a single cloud-delivered platform, an approach also known as cloud edge security.

CASB SASE
A focused tool or service for overseeing and protecting cloud and SaaS usage. A broader cloud architecture that converges networking and security into one platform delivered from the edge.
Delivers visibility, DLP, threat protection, and compliance for cloud app usage. Bundles SD-WAN, SWGs, zero trust network access, firewall as a service, and a CASB.
Acts as one building block within a larger security stack. Delivers a CASB as one of its components, alongside networking and other security services.
Best for organizations that need to govern SaaS and cloud app usage specifically. Best for organizations unifying network and security across a distributed workforce.

Frequently asked questions about CASB

Here are the most commonly asked questions about CASBs.

Q1. What is the difference between a CASB and DLP?

A CASB governs how users access cloud and SaaS applications and applies security across that usage, while DLP focuses specifically on stopping sensitive data from leaving the organization. Most CASBs include DLP as one of their capabilities, so the two often work together rather than as either-or choices.

Q2. What types of companies need a CASB?

Companies that rely heavily on cloud and SaaS applications, allow remote or BYOD access, or operate under regulations like HIPAA, PCI DSS, or GDPR benefit most from a CASB. It is especially valuable for mid-sized and enterprise organizations that need visibility and control across many cloud services at once.

Q3. How does a CASB help uncover shadow IT?

A CASB uncovers shadow IT by analyzing network logs and traffic to reveal which cloud applications employees actually use, including unsanctioned tools that the IT department never approved. It then lets administrators assess the risk of those apps and apply or block access with policy controls.

Q4. What criteria should you use to evaluate a CASB solution?

Key criteria for evaluating a CASB include its deployment modes (forward proxy, reverse proxy, and API), the depth of its DLP and threat protection, coverage of the cloud apps your organization uses, compliance reporting, and how well it integrates with existing security tools. Ease of setup and quality of support matter too, since comprehensive CASBs can take time to configure.

Q5. What is the difference between a CASB and a firewall?

A traditional firewall guards the network perimeter and controls traffic based on ports, protocols, and IP addresses, while a CASB works at the application layer, watching cloud and SaaS usage beyond that perimeter, with visibility, DLP, and policy control at the application and data level. Firewalls generally cannot see inside sanctioned cloud app usage the way a CASB can.

To go deeper on keeping tabs on your cloud environment, explore cloud monitoring and how it complements the visibility a CASB provides.

CASB Software

This list shows the top software that mention casb most on G2.

Netskope is a Cloud Access Security Broker (CASB)

Symantec CASB is a cloud security solution.

Microsoft Defender for Cloud Apps is an enterprise-grade security for cloud apps.

Discover, Monitor and Protect your sensitive data wherever it lives and goes: cloud, endpoints, storage or network.

Proofpoint Cloud App Security Broker (PCASB) helps you secure applications such as Microsoft Office 365, Googles G Suite, Box, and more.

FortiCASB is Fortinet's cloud-native Cloud Access Security Broker service, designed to provide comprehensive visibility, compliance, data security, and threat protection for cloud-based services. By leveraging direct API access, FortiCASB enables deep inspection and policy management for data stored in various cloud application platforms. It offers detailed user analytics and management tools to ensure that organizational policies are enforced, safeguarding sensitive data across multiple SaaS applications. Key Features and Functionality: - Visibility: FortiCASB utilizes data scans and analytics to monitor who accessed information, what was accessed, when, and from where, providing comprehensive insights into cloud application usage. - Compliance: The service offers file content monitoring to identify and report on regulated data within the cloud, aiding organizations in meeting compliance requirements such as SOX, GDPR, PCI, HIPAA, NIST, and ISO27001. - Data Security: FortiCASB conducts scans to detect sensitive data, such as social security or credit card numbers, classifies this data based on sensitivity levels, and issues alerts accordingly. - Threat Protection: Employing User Entity Behavior Analytics, FortiCASB monitors for suspicious or irregular user behavior and sends alerts for potential malicious activities. - API-Based Integration: The service integrates directly with major SaaS applications, including Office 365, Dropbox, AWS S3, Google Workspace, and more, ensuring seamless security management across platforms. - Shadow IT Discovery: FortiCASB provides consolidated reporting to detect unsanctioned on-network SaaS usage, helping organizations identify and manage unauthorized applications. Primary Value and Problem Solved: FortiCASB addresses the critical need for organizations to maintain visibility and control over their cloud-based services. As businesses increasingly adopt SaaS applications, they often face challenges in monitoring application usage, securing sensitive data, and ensuring compliance with regulatory standards. FortiCASB mitigates these challenges by offering a centralized solution that provides real-time insights, enforces data security policies, and protects against threats, thereby enabling organizations to confidently leverage cloud technologies without compromising security.

Lookout is a mobile app that fights cybercriminals by predicting and stopping mobile attacks before they do harm.

Forcepoint Data Security Cloud is a unified cloud security platform that enables Zero Trust access to the web, SaaS and private applications with best-in-class data security and malware protection while delivering a great user experience. Gain the full visibility and control over web and application usage to mitigate digital risks and give your organization more freedom and flexibility. Key product capabilities include: • Visibility into web, SaaS and private application use • Distributed enforcement – endpoint enforcement, cloud enforcement via in-line proxy & API, and on-prem enforcement • Industry-leading data and threat protection capabilities to secure data everywhere, for people working anywhere • Seamless user experience from any location and any device "

Monitors your cloud applications for data leaks, cyber-threats and regulatory violations that put your business at risk.

ManagedMethods helps companies gain visibility gain visibility into how users store, access and share files in the cloud.

Secure access service edge (SASE) for branch offices, retail locations and mobile users

Oracle CASB Cloud is an API-based cloud access security broker for applications and workloads.

Symantec Web Security is a cloud based software that helps protect organization from compromised websites and malicious downloads and allows user to control, monitor and enforce Acceptable Use Policies for organizations users, whether on-premises or away from the office.

Wiz is a CNAPP that consolidates CSPM, KSPM, CWPP, vulnerability management, IaC scanning, CIEM, DSPM, and container and Kubernetes security into a single platform.

Axis Security enables any organization to quickly deliver tightly managed global access to employees, partners and other stakeholders through a purpose-built zero-trust cloud security platform.

Acronis Cyber Protect Cloud unites backup and next-generation, AI-based anti-malware, antivirus, and endpoint protection management in one solution. Integration and automation provide unmatched ease for service providers — reducing complexity while increasing productivity and decreasing operating costs. Acronis Cyber Protect Cloud is the single service provider solution that combines backup, anti-malware (including anti-virus, anti-ransomware, and anti-cryptojacking) and security and management capabilities such as vulnerability assessments, patch management, URL filtering and more. Now, service providers can eliminate complexity and make security a centerpiece of their offerings while increasing SLAs, decreasing churn, and generating more recurring revenue. Get upgraded security with integrated AI-based defenses that protect clients from modern threats, make smarter use of resources so your team can focus on clients, and earn new recurring revenue and higher margins that strengthen your business. Enriched with next-gen, full-stack anti-malware protection and comprehensive yet simple management tools, built on top of our industry-leading backup and data recovery solution, Acronis Cyber Protect Cloud simplifies onboarding, daily operations, and reporting, and combats advanced attacks with new use cases enabled by integration. Acronis Cyber Protect Cloud makes it easy to deliver the modern cyber protection your clients seek.

Productiv provides application engagement analytics for IT leaders who are rethinking SaaS management. Using more than 50 engagement dimensions, Productiv continuously rationalizes application portfolios and answers questions about investments and effectiveness with insights about actual use. Companies like Fox and Equinix use Productiv to maximize application value for their people, their budget, and their business

Check Point Harmony Email & Office, protects enterprise data by preventing targeted attacks on SaaS applications and cloud-based email.

Box is the leader in Intelligent Content Management, helping teams securely manage, collaborate, and automate their work with AI-powered tools. It provides one secure platform for the entire content lifecycle, from storing and sharing to signing, automating, and activating content with AI. With Box AI, teams can query documents, summarize reports, and streamline processes across departments.Box enforces advanced security and compliance with HIPAA, GDPR, FINRA, and FedRAMP certifications, plus AI guardrails that protect data in motion and at rest. Trusted by AstraZeneca, Morgan Stanley, and the U.S. Air Force, Box powers mission-critical collaboration across regulated industries and global businesses. With over 1,500 integrations, including Microsoft 365, Google Workspace, Salesforce, Slack, and DocuSign, Box connects seamlessly with your everyday tools.APIs and SDKs enable customization so Box adapts to your workflows.