Organizations increasingly adopt cloud services for faster deployment, flexibility, and cost advantages, but cloud usage often sits outside established IT access governance. Unlike on-premises systems, cloud services—including personal cloud tools used by employees and partners—may bypass organizational oversight, especially when accessed from mobile devices beyond the corporate perimeter. This lack of integration creates governance challenges for legal and regulatory compliance (notably GDPR requirements for controlling personal data transmission, processing, and storage) and expands cyber-risk, including unauthorized access, data theft or corruption, and malware implantation that can later infect the enterprise.
Because traditional security and governance tools were slow to mature for cloud needs, Cloud Access Security Brokers (CASBs) emerged to fill the gap, and several have been acquired by major security vendors. Recommended CASB capabilities include discovering cloud service usage, controlling access and data movement into approved services using directory-based and service-native controls, protecting regulated/sensitive data via classification plus policy-based controls (encryption, tokenization, pseudonymization) without breaking service functionality, detecting and preventing cyber threats (malware, unauthorized access, leakage), and supporting compliance with “out-of-the-box,” regulation-aligned features backed by certification or proven deployments.
CipherCloud’s CASB+ platform (founded 2010; headquartered in San Jose with global offices) is positioned as a second-generation CASB combining discovery, inline/API controls, DLP, malware detection, UEBA, mobile protection, and an encryption/tokenization gateway. It integrates with Active Directory, SSO, and IDaaS providers, applies real-time anomaly policies (e.g., impossible travel, unmanaged devices), scans new and historical cloud data, and preserves SaaS functionality through patented indexing/search on encrypted data. Key challenges include reliance on undocumented SaaS traffic structures that may change, and tokenization’s requirement for a secured on-premises database. CASB+ still lacks broader access governance functions such as segregation of duties and access attestation.
See All Locations
See All Locations