A cloud access security broker is software that sits between your company's devices and the cloud services you use, watching what data moves in and out
When your company uses cloud services — Salesforce, Microsoft 365, Slack, Google Workspace, or dozens of others — those services live on someone else's servers. A cloud access security broker, or CASB, is a tool that monitors and controls the traffic flowing between your company's network and those cloud services. Think of it as a security checkpoint: it can see what files are being uploaded, who is accessing what, and whether that activity looks suspicious or violates company policy.
The core reason companies deploy a CASB is that cloud services are outside their direct control. Your IT department can lock down the computers in your office, but they cannot physically control Salesforce's servers. A CASB gives them visibility and some control over what happens when employees use cloud apps, even though those apps run elsewhere.
Key Takeaways
- A CASB monitors data moving between your company's network and cloud services, acting as a security checkpoint for cloud traffic.
- CASBs can block risky actions like uploading sensitive files to personal cloud storage or downloading data from an unsecured device.
- Common CASB products include Netskope, Zscaler, Cisco Umbrella, and Palo Alto Networks Cloud Identity Engine, though many companies use their cloud provider's built-in tools instead.
- A CASB cannot prevent a determined insider from stealing data, but it can detect unusual patterns and alert security teams to investigate.
How a CASB actually watches cloud traffic
A CASB works by intercepting the connection between your device and a cloud service. This can happen in a few ways. Some CASBs are installed as software on your company computer. Others work by routing your internet traffic through a company server first, which inspects it before sending it to the cloud. A third approach uses an API connection directly to the cloud service — for example, connecting to Salesforce's own API to see what is happening inside your Salesforce account.
Once the CASB is in place, it can see what you are doing. If you try to upload a spreadsheet containing customer credit card numbers to a personal Dropbox account, the CASB can detect that the file contains sensitive data and block the upload. If someone logs into your company's Slack account from a device that does not have the required security software installed, the CASB can deny access or flag it for a security team member to review.
The CASB also keeps a log of activity. Security teams can later search these logs to answer questions like "Did anyone download files from our Google Drive yesterday?" or "Which employees accessed our cloud storage from outside the office?"
What a CASB can and cannot do
A CASB is good at detecting patterns and enforcing rules. It can block a file upload, require multi-factor authentication before allowing access, or prevent a user from sharing a document outside the company. It can also detect when an account is being used in an unusual way — for example, logging in from a new country at an impossible speed, or downloading 10 times the normal amount of data in an hour.
What a CASB cannot do is prevent someone who has legitimate access from misusing that access. If you have permission to read customer data in Salesforce, a CASB cannot stop you from copying that data and emailing it to a competitor. It can log that you did it, and a security team can investigate after the fact, but prevention requires other controls — like limiting who has access to sensitive data in the first place.
A CASB also cannot protect you from threats that happen entirely within a cloud service. If a hacker breaks into your Salesforce account by guessing your password, a CASB might detect the unusual login, but the real problem is the weak password. The CASB is a layer of defense, not a complete solution.
Why companies deploy a CASB instead of relying on the cloud provider
Cloud providers like Microsoft, Google, and Salesforce do offer their own security features. Microsoft 365 has built-in data loss prevention. Salesforce has login controls. So why add another tool?
The main reason is that a CASB can see across multiple cloud services at once. If your company uses Salesforce, Slack, Dropbox, and Google Workspace, each one has its own security settings and logs. A CASB sits above all of them and can enforce a single set of rules across all four. It can also enforce rules that the cloud provider does not offer — for example, blocking uploads to any personal cloud storage service, even ones the cloud provider has never heard of.
A CASB also gives a company's security team a single place to look for suspicious activity, rather than logging into four different admin dashboards. For large companies with strict compliance requirements — like healthcare companies that must follow HIPAA or financial firms that must follow SEC rules — this centralized view is often required by law.
Common CASB products and how they differ
Netskope and Zscaler are the two largest independent CASB vendors. Both offer similar core features: they intercept cloud traffic, log activity, and enforce policies. Netskope is often chosen by companies that want very detailed control over what data can be uploaded and downloaded. Zscaler is often chosen by companies that want to route all internet traffic through a security service, not just cloud traffic.
Cisco Umbrella and Palo Alto Networks Cloud Identity Engine are CASBs built by larger security companies that also sell firewalls and other network tools. Companies that already use Cisco or Palo Alto for network security sometimes choose their CASB to keep everything in one place.
Many companies do not buy a separate CASB at all. Instead, they use the security features built into their cloud provider. Microsoft 365 includes data loss prevention and conditional access rules. Google Workspace includes similar features. For small companies or companies that use only one or two cloud services, these built-in tools are often enough.
What a CASB logs and who can see it
A CASB typically logs: who accessed what, when they accessed it, what device they used, where they were located, what they downloaded or uploaded, and whether the action was allowed or blocked. This log is stored on the CASB's servers or on your company's own servers, depending on how the CASB is set up.
In most companies, only the security team and IT department can see these logs. However, if your company is subject to a legal investigation or a regulatory audit, the logs may be turned over to lawyers or government agencies. Some companies also use CASB logs to investigate employee misconduct — for example, if someone is suspected of stealing data.
If you work for a company that uses a CASB, you should assume that your cloud activity is being logged. This does not mean your company is spying on you — it means they have a record of what you do with cloud services, similar to how they have a record of what you do on the company network.
The difference between a CASB and a VPN
A CASB and a VPN are sometimes confused because both can route your traffic through a company server. The difference is in what they do with that traffic. A VPN encrypts your traffic and hides your location, mainly to protect your privacy on public WiFi. A CASB inspects your traffic and enforces security policies, mainly to prevent data loss and detect threats.
Many companies use both. You might use a VPN to encrypt your connection when working from a coffee shop, and the CASB would inspect your cloud traffic even after the VPN encrypts it. The VPN protects the connection. The CASB protects the data.
Frequently Asked Questions
Can a CASB see my passwords?
A CASB can see the traffic flowing to and from cloud services, but it does not need to see your password. It typically intercepts traffic after you have already logged in, or it connects using an API key that the cloud provider issues. If a CASB were designed to capture passwords, it would be a security risk, not a security tool.
Does a CASB slow down my internet?
A CASB adds a small amount of latency because your traffic has to be inspected before it reaches the cloud service. For most users, this is not noticeable — a few milliseconds. If your company has deployed a CASB and you notice your cloud services are slow, the CASB is usually not the cause, but your IT department can investigate.
Can I bypass a CASB if my company has one?
If the CASB is deployed correctly, bypassing it is difficult. If it is installed on your company computer, you cannot uninstall it without IT permission. If it is routing your traffic through a company server, you cannot change that without changing your network settings, which are usually locked down. Some employees try to use personal devices or personal internet connections to avoid the CASB, but most companies have policies against this.
What happens if a CASB blocks something I need to do?
If a CASB blocks an action you need to perform for your job, contact your IT department or security team. They can review the block, understand why the policy was in place, and either adjust the policy or grant you an exception. This usually takes a few hours to a few days.
Is a CASB the same as a data loss prevention tool?
A CASB and a data loss prevention tool, or DLP, overlap but are not the same. A DLP tool specifically looks for sensitive data — like credit card numbers or social security numbers — and blocks it from leaving the company. A CASB does this, but also does other things, like enforcing login rules and detecting account compromise. Many CASBs include DLP features, but not all DLP tools are CASBs.