The KuppingerCole Leadership Compass on Cloud Access Security Brokers (CASBs) examines how organizations can regain security, compliance, and governance control in hybrid IT environments where multiple SaaS, IaaS, on-premises, and hosted services coexist. CASBs emerged because traditional security and access governance tools were slow to extend into cloud usage, creating gaps such as unmanaged “shadow IT,” inconsistent policy enforcement, and heightened exposure to data theft, corruption, and malware insertion. CASB capabilities cluster around discovering which cloud services are used (and by whom), controlling access and transactions across users/devices/locations, and protecting sensitive data in cloud services via detection, blocking, quarantining, encryption, or tokenization. Modern “CASB 2.0/CASB+” solutions increasingly combine functions traditionally associated with DLP, rights management, and secure web gateways, delivered through network-based proxy controls, API-based integration with cloud services, or a hybrid of both.
The evaluation framework emphasizes discovery depth (identity attribution, risk profiling, traffic analysis), granular access control (policy standards support, adaptive authentication, integration with directories/IDaaS and cloud-native controls), cloud data security (classification, DLP/RMS integration, encryption and key management), compliance (regulatory templates, certifications, reporting), and cyber security (malware controls, anomaly detection, integration with security intelligence systems). The Compass cautions that vendor selection requires deeper analysis and proof-of-concept validation beyond chart positions.
Overall Leaders are CipherCloud, McAfee, Microsoft, Oracle, Palo Alto Networks, and Symantec, with Microsoft and Symantec highlighted for integrated CASB 2.0 platforms after acquisitions. Product and Innovation Leadership particularly favor CipherCloud, Microsoft, Netskope, Oracle, and Symantec, while Market Leadership reflects global reach, elevating large vendors such as Microsoft, Symantec, Cisco, and others. Correlated matrices show weak alignment between market share and product strength, identifying vendors that “overperform” on capability relative to market presence and vice versa.
See All Locations
See All Locations