The Market Compass analyzes the Cloud Access Security Broker (CASB) market, focusing on how organizations can secure and govern cloud service usage in hybrid IT environments spanning SaaS, on-premises, and hosted services. As cloud adoption expands, key risks emerge from poor integration of cloud usage into existing security and access governance processes, uncontrolled “shadow IT” driven by employees and business units, regulatory pressures (notably GDPR), and increased cyber threats such as data theft, corruption, and malware propagation through cloud services.
CASBs address these issues by providing discovery of cloud usage, access control, cloud data protection, and compliance enforcement/reporting—capabilities that have increasingly expanded into Cloud Security Posture Management (CSPM). Architecturally, CASBs evolved from log-based discovery to control points using proxies (inline enforcement with potential performance and compatibility downsides) and API-based approaches (granular controls but with detection-to-enforcement delays). Most mature products now use hybrid architectures combining proxy and API methods, and they integrate with adjacent controls such as rights management, DLP, secure web gateways, access governance, malware protection, and posture management.
The report argues that standalone CASBs are declining as buyers prefer broader cloud security solutions that unify CASB, CSPM, data and user protection, and Zero Trust Network Access, with future expansion toward edge computing and 5G-driven challenges. It defines essential and recommended capabilities across discovery, access control, data security, compliance, posture management, auditability, deployability, scalability, and integration with identity sources (e.g., AD, Azure AD, LDAP, IDaaS).
Vendors are compared via ratings and highlighted strengths. Featured differentiators include Bitglass’ agentless AJAX-VM reverse proxy and on-device secure web gateway, Forcepoint’s human-centric approach with access/security governance elements, Censornet’s context-sharing Autonomous Security Engine, CipherCloud’s integrated data-centric protection and AnyApp, and McAfee’s extension of CASB controls to custom applications on IaaS/PaaS.
See All Locations
See All Locations