🚀 CloudSEK featured in the 2026 Frost Radar™!
Read more
A Cloud Access Security Broker (CASB) is a service or software tool that operates between enterprise users and cloud service providers to enforce security policies, data protection, and compliance.
Policy scope covers the activity that starts after authentication succeeds: which files move, who shares them, which apps connect, and which sessions look wrong.
Gartner named the category in 2012, when enterprise data began living in services nobody owned. Identity tools decide who signs in and network tools decide which destinations are reachable, while a CASB is the layer that watches what happens once a user is already inside Microsoft 365, Salesforce, or Google Workspace.
Deployment mode decides everything else about a CASB, because each mode observes a different slice of cloud activity and enforces policy at a different moment.

API mode connects directly to a cloud provider's management APIs and inspects activity after it happens.
Sanctioned applications get thorough coverage: files at rest, sharing permissions, configuration changes, and connected third-party apps, with no traffic redirection and no effect on user experience.
Detection in API mode lags the event by minutes. An API-mode CASB finds an overshared file after the share completes, which suits data governance and posture work.
Blocking an action mid-session falls outside what this mode does.
Forward proxy mode routes outbound traffic from managed devices through the CASB before it reaches any cloud service. Inline placement enables real-time blocking, inspection of uploads, and coverage of unsanctioned applications the organization never approved.
Coverage stops at the managed device boundary. Agents, proxy configuration, or PAC files are required on every endpoint, so personal laptops and phones escape the control entirely.
Reverse proxy mode integrates with the identity provider and routes sessions through the CASB after sign-in, with nothing installed on the endpoint. This is the standard answer for contractors and BYOD access to sanctioned applications.
Brittleness comes built into reverse proxy mechanics. Microsoft's documentation on Conditional Access app control describes the mechanics: the proxy rewrites URLs, scripts, and cookies inside the session.
Applications that break under rewriting fall outside enforcement, and so do native desktop and mobile clients that bypass the browser.
Most enterprise deployments combine modes: API for sanctioned application governance, forward proxy for managed devices and shadow IT discovery, reverse proxy for unmanaged access.
Vendor consoles present the result as one policy set, while the underlying coverage gaps stay specific to each mode.
CASBs operate across four critical pillars of cloud security:
A CASB applies policy through a repeatable evaluation sequence, regardless of which mode carries the traffic.
Buyers confuse these categories because their marketing overlaps, though each acts at a different point in the access path.
Overlap between these categories is the practical reality for buyers. A single vendor platform delivers CASB, SWG, and ZTNA functions from the same console, which makes the labels a way to check coverage instead of a shopping list.
Honest evaluation starts with the paths a CASB misses, and generative AI exposed most of them at once.
A LayerX Enterprise GenAI Security Report 2025 finds that 70% of connections to generative AI tools run through personal accounts, with 56% of corporate-account connections bypassing single sign-on, meaning organizations can’t enforce security measures on them.
Traffic outside the corporate identity path escapes reverse proxy control and produces no tenant API records.
Desktop and mobile applications that authenticate outside the browser skip reverse proxy sessions, and browser extensions interact with cloud services in ways proxies parse poorly. Both routes handle real corporate data while generating no CASB events.
Discovery starts from knowing that an application exists at all. New AI services appear faster than catalogs update, and local models run entirely on the endpoint.
Embedded AI features inside approved SaaS raise no new domain, so shadow AI defeats discovery built for a slower software cycle.
Service-to-service calls and machine identities move data without a user session to inspect. Exposed tokens and leaked API keys give attackers a route into cloud data that no CASB policy evaluates, since the traffic never resembles a person signing in.
Infostealer logs and breach dumps supply valid session cookies and passwords for SaaS accounts. Attackers signing in with legitimate credentials from a plausible location look like employees until behavior analytics catch a pattern.
Leaked credential monitoring therefore works as a partner control to anything enforced at the session layer.
Detection value from a CASB shows up as a specific set of events that other tools miss.
Each signal reaches the SOC through log export, where correlation with endpoint and identity telemetry turns a single cloud event into an investigation with context around it.
Standalone CASB buying has largely ended across the enterprise market. Gartner now evaluates the capability inside security service edge, a market it describes as mature and consolidated.
SWG, CASB, zero trust network access, and firewall-as-a-service arrive there as one cloud-delivered platform.
Two consequences follow for anyone buying today. Most organizations acquire CASB features through a platform contract instead of a dedicated product.
Evaluation shifts accordingly, from comparing CASB vendors to checking whether a platform's cloud controls match the depth a dedicated tool once provided.
Architecture labels change nothing about enforcement itself. A zero trust program still needs a control that inspects in-app actions, and SSE provides the delivery model rather than the capability itself.
Who coined the term CASB?
Gartner introduced the term cloud access security broker in 2012 to describe products that enforce enterprise security policy between users and cloud service providers.
Does a CASB decrypt traffic?
Yes, in proxy modes. Inline inspection requires TLS termination, while API-mode deployments read data through provider APIs without decrypting sessions.
Does a CASB work with mobile apps?
Partially. Managed mobile devices route through forward proxy profiles, while native apps on unmanaged devices bypass session controls.
Can a CASB block ChatGPT and other AI tools?
Yes, for corporate-account access on managed paths. Personal-account use on unmanaged devices and local models running offline stay outside its reach.
Does a CASB replace DLP?
No. A CASB applies DLP policy to cloud traffic, while endpoint and email DLP cover data paths that never touch a cloud application.
Do small organizations need a CASB?
Cloud data sensitivity matters more than headcount. Small teams handling regulated data get CASB features bundled inside most productivity and SSE licenses.
