Cloud Access Security Broker (CASB) is a security technology that helps businesses monitor and control how users interact with cloud applications and services. It provides visibility into cloud usage and can enforce policies around access, data protection, compliance, and threats. NIST describes CASB as an important component of the modern enterprise security landscape as organizations increasingly rely on multiple cloud services.
For a mid-sized or enterprise business, CASB becomes particularly useful when employees are working from home, using personal devices, or accessing cloud applications from locations outside the traditional corporate network. An employee might use Microsoft 365, Salesforce, Google Workspace, Dropbox, or another SaaS application without that traffic ever passing through the company's traditional network perimeter. CASB provides a way to apply security controls to those cloud interactions regardless of where the employee is working.
Keep Every Business Location Secure
From headquarters to remote workers at home or on the go, keep your business network secure with Fusion Connect SASE.
A CASB can work through several different mechanisms depending on the platform and architecture. It can monitor cloud applications, identify unauthorized or "shadow IT" services, enforce access policies, inspect activity and data, and apply controls such as Data Loss Prevention (DLP). In a modern SSE or SASE architecture, CASB capabilities may be integrated with other security functions such as Secure Web Gateway (SWG) and Zero Trust Network Access (ZTNA), creating a more unified approach to securing users and cloud applications.
A simple example
An employee uploads a confidential company document to a personal cloud-storage account.
A CASB could potentially:
- Identify the cloud service being used.
- Determine who is accessing it.
- Identify the type or sensitivity of the data.
- Apply the company's security policy.
- Allow, block, or restrict the activity.
- Generate an alert for IT or security teams.
The important concept is that CASB gives the business visibility and control over cloud activity that might otherwise happen outside its traditional network perimeter.
History of CASB
CASB emerged as businesses began rapidly adopting cloud applications and discovered that traditional network security tools weren't designed for a world where applications and data increasingly lived outside the corporate data center. The term Cloud Access Security Broker is generally credited to Gartner, which introduced the category to describe a security policy enforcement point between cloud service users and cloud providers. Gartner's definition describes CASB as a point that combines and enforces enterprise security policies as cloud resources are accessed.
The CASB market began taking shape in the early 2010s. Gartner formally established the CASB category in 2012, when analysts Neil MacDonald and Peter Firstbrook published research on the growing importance of cloud access security brokers. The category gained additional visibility as organizations began discovering just how many cloud applications employees were using outside of IT's direct control.
Early CASB products concentrated heavily on cloud discovery and visibility—helping businesses find out which cloud applications employees were actually using. As the technology matured, CASB capabilities expanded to include security policy enforcement, data protection, threat detection, compliance, and more detailed activity monitoring. NIST describes this evolution from first-generation discovery capabilities toward broader cloud-security functionality.
Today, CASB increasingly exists as part of a larger cloud-delivered security architecture rather than as an isolated appliance or product. CASB capabilities are commonly incorporated into Security Service Edge (SSE) and SASE platforms alongside technologies such as SWG and ZTNA. Gartner's current architecture guidance identifies CASB as one of the capabilities that can be delivered through SASE, while its 2026 research describes SSE as a way to consolidate cloud-delivered access security functions.
Three Interesting CASB Facts
- "Shadow IT" helped create the market.
One of CASB's original jobs was essentially answering a question many IT departments couldn't answer: "What cloud applications are our employees actually using?" Businesses were discovering that employees could adopt cloud services without IT knowing about them. - CASB is older than SASE.
CASB became an established security category in the early 2010s. Gartner didn't introduce the SASE architecture concept until 2019. Today, CASB is commonly considered one of the security capabilities that can be delivered as part of SASE. - The "broker" isn't necessarily a person—or even a physical device.
Despite the name, a CASB is typically software or a cloud-delivered security capability that sits logically between users and cloud services to enforce security policies. Modern CASB functionality can be integrated directly into broader SSE/SASE platforms.
Why CASB Is Important to Your Business
For a business owner, CASB addresses a fundamental problem with modern work: your employees can access company data from cloud applications almost anywhere. They may be working from the office, home, a hotel, or another location—and the applications they use may be operated by third-party cloud providers. Traditional network security alone may not provide enough visibility into what users are doing inside those applications.
CASB gives IT and security teams greater control over cloud usage without necessarily blocking cloud applications altogether. Businesses can establish policies around which applications are approved, what users can do with company data, and which activities should generate alerts or be blocked. This is particularly relevant for organizations combining remote work, SaaS applications, BYOD (bring your own device), SD-WAN, and cloud-based infrastructure.
Frequently Asked Questions
What does CASB protect?
CASB helps protect cloud applications, users, and data by providing visibility and enforcing security policies. Depending on the solution, capabilities can include cloud discovery, access control, threat protection, data protection, DLP, and compliance monitoring.
Is CASB the same thing as a firewall?
No. A firewall primarily controls network traffic based on defined rules. CASB focuses specifically on cloud application usage and activity, providing visibility and policy enforcement around users, cloud services, and data.
In an SSE/SASE architecture, CASB and firewall capabilities can work together as complementary security controls.
Does CASB work for employees working from home?
Yes. CASB is particularly relevant when employees access cloud applications outside the traditional corporate network. Because the controls can be applied to cloud activity rather than relying exclusively on an employee's physical network location, CASB can help provide consistent security policies for remote users.
What is shadow IT, and how does CASB help?
Shadow IT refers to applications, cloud services, or technology being used by employees without formal approval or visibility from IT. CASB can help identify these services and provide information about how they are being used, allowing an organization to evaluate their security and decide whether to allow, restrict, or block them.
Is CASB part of SASE?
Yes. CASB is commonly included among the security capabilities associated with SASE. A SASE architecture can combine networking capabilities such as SD-WAN with security functions including CASB, SWG, ZTNA, and firewall capabilities.
Does CASB replace other security tools?
Not necessarily. CASB is one component of a broader security strategy. Modern SSE/SASE platforms increasingly combine CASB with other capabilities, allowing organizations to manage multiple security functions through a more unified architecture rather than maintaining completely separate security products.