Cloud Access Security Broker (CASB)
What is Cloud Access Security Broker (CASB)?

Cloud access security broker or CASB is a security solution that sits between cloud service consumers and cloud service providers and brokers secure connection to SaaS applications, ensuring sensitive data remains protected, data loss is prevented, and the chances of a cyberattack are reduced.

Time to read: 7 minutes 11 seconds | Updated: July 20, 2026.

Table of Contents

    Key takeaways for Cloud Access Security Broker (CASB)

    • CASB acts as a security control point between users and cloud applications, enforcing enterprise security policies and securing access to SaaS and cloud services. 
    • It protects sensitive data and reduces risk by preventing data loss, limiting unauthorized sharing, and lowering exposure to cyberattacks across cloud environments. 
    • CASB delivers four core capabilities: visibility into cloud usage, data security controls, threat protection, and regulatory compliance enforcement across multiple cloud platforms.
    • It extends security beyond on-premise environments, supporting Zero Trust strategies and securing data across public cloud, SaaS, and hybrid work scenarios. 

    CASB explained

    According to Gartner%3Ca%20href%3D%22https%3A%2F%2Fwww.gartner.com%2Fen%2Finformation-technology%2Fglossary%2Fcloud-access-security-brokers-casbs%23%3A%7E%3Atext%3DCloud%2520access%2520security%2520brokers%2520%28CASBs%29%2520are%2520on%252Dpremises%252C%2Ccloud%252Dbased%2520resources%2520are%2520accessed.%22%20external-link%3D%22true%22%20data-analytics-region-id%3D%22footnote_tip%7Clink_click%22%3EGartner%20IT%20Glossary%2C%20%E2%80%9CCloud%20Access%20Security%20Broker%2C%E2%80%9D%20August%202024.%3C%2Fa%3E, "Cloud access security brokers (CASBs) are on-premises, or cloud-based security policy enforcement points, placed between cloud service consumers and cloud service providers to combine and interject enterprise security policies as the cloud-based resources are accessed."

    In a world where confidential corporate data is distributed across data centers, public clouds (IaaS, PaaS), or SaaS applications, CASB ensures data protection, compliance to regulations, and threat protection and helps security teams extend their Zero Trust network security beyond on-premises data centers and into cloud and SaaS. A CASB solution offers the following four functions:

    • Visibility: Provide visibility into all user traffic and SaaS applications used by employees.
    • Compliance: Enforce compliance with regulations like GDPR, PCI DSS, HIPPA, etc., by limiting access to sensitive data hosted across multiple cloud environments.
    • Data security: Enforce data security policies, prevent unauthorized sharing of data, and monitor and scan data usage to and from SaaS providers.
    • Threat protection: Remediate threats whenever unusual behaviors are detected across cloud application, reducing risks from ransomware, malware, or compromised users.
    Functions of a CASB diagram.
    Functions of a CASB diagram.
    TAP IMAGE TO ZOOM IN

    Where does CASB fit in SASE?

    SASE (Secure Access Service Edge) is a combination of SD-WAN and cloud-delivered security service edge or SSE. SSE is comprised of key security services including Cloud access security broker or CASB that enables businesses to secure sensitive data in public cloud and help deliver part of the security vision of SASE.

    Why should I consider CASB?

    Sensitive corporate data no longer resides behind a firewall in your servers, it is spread across data centers, public cloud or SaaS applications. And with hybrid work, employees access data and apps via unsecured networks—opening critical security challenges for businesses and security teams starting with:

    1. How to restrict employees from sharing (uploading/downloading) sensitive data on managed and unmanaged (by IT) cloud apps.

    2. How to control the use of applications and services that are not explicitly approved by IT (shadow IT).

    3. How to meet various compliance regulations that mandate strict data privacy.

    4. How to secure sensitive data in public cloud and restrict access on BYOD.

    5. How to monitor data in public cloud for malware, ransomware, etc. and safeguard employees from downloading these types of malicious software.

    The availability of cloud services in a click offers easy and unchecked access to employees. Things get complicated when employees use certain applications like GitHub, Dropbox, etc., for both professional and personal work, or create accounts on unmanaged apps for data analysis or managing project workflows. Actions like these open unseen challenges for security teams and put the corporate data at huge security risk.

    CASBs help security teams extend their control to cloud by providing visibility into all cloud services used by the employees, monitoring or scanning SaaS applications for potential threats, securing data against threats, meeting compliance regulations, and restricting sensitive data sharing. 

    How CASB works diagram.
    How CASB works diagram.
    TAP IMAGE TO ZOOM IN

    How does CASB work?

    A CASB solution is delivered via on premises hardware or software or as a cloud service, CASB uses proxy and API methods to enforce strong security checks: 

    • Proxy workflow: for real time data inspection.

    1. User attempts to access a SaaS app or IaaS platform. Traffic is intercepted by CASB and SSL inspection is performed.

    2. CASB validates identity and applies policy via in-line CASB and data protection controls to restrict upload, download, and share activities. Compliances are checked, and access is automatically adapted based on real-time context changes.

    3. With restricted actions in place, secure SaaS access is extended to the user while restricting unauthorized behaviors to prevent data loss and enforce compliance.

    4. Admins gain visibility into all user activity while accessing the SaaS app. If security posture changes or the user attempts unauthorized activity, access is reassessed, and admins alerted.

    • API workflow: for scanning data at rest.

    CASB leverages out-of-band application programming interface (API) security for monitoring data stored in cloud services like Microsoft Office 365, Salesforce, Workday, SharePoint, etc. CASB integrates with the APIs of these cloud services and scans for malware, ransomware, malicious software, and other types of cyber threats. 

    Features of CASB

    • In-line CASB: Enforce security policies in real time as data moves to and from the cloud. This can include authentication, encryption, and other security controls.
    • SSL inspection for CASB control: Inspect encrypted SSL/TLS traffic to stop potential threats or data leakage before it happens. By decrypting the traffic, the CASB can apply security policies to protect sensitive data.
    • Visibility into apps and shadow IT: Shadow IT refers to the use of applications and services without IT's explicit approval. With CASB businesses gain visibility into SaaS apps and shadow IT to better understand and manage the risks associated with sanctioned and unsanctioned app usage.
    • Granular control of restricted actions: Admins can set granular policies that restrict certain actions like uploading, downloading, sharing data, etc., from any SaaS application. This is an important requirement to protect against data loss and ensure compliance with various regulations.
    • DLP for SaaS based apps: DLP (Data Loss Prevention) helps protect sensitive data within SaaS applications by monitoring, detecting, and blocking potential data breaches or unauthorized access. DLP can use regular expressions (regex) and dictionary matching or use OCR (Optical Character Recognition) to identify and protect sensitive data.
    • Compliance with predefined and custom dictionaries: Predefined and custom dictionaries can be created to ensure compliance with specific regulations like HIPAA, PCI DSS, GDPR, and NIST. These dictionaries contain terms and patterns that are unique to each regulation, helping organizations meet their compliance obligations.

    HPE and CASB

    HPE Aruba Networking CASB is a modern Cloud Access Security Broker (CASB) solution designed to enhance cloud security and secure access to SaaS applications for organizations. Our CASB serves as the security mediator between users and SaaS applications, providing inline CASB protection for data in motion, effectively regulating data flows, uncovering shadow IT, and preventing data loss.

    HPE Aruba Networking CASB provides end‑to‑end visibility, allowing centralized management of user access, downloads, and sharing permissions. Our CASB's operation is straightforward: it proxies traffic to avoid risky pass-through connections, validates identities, applies policies, and securely connects users to resources while inspecting traffic and monitoring user experience.

    Emphasizing ease of use and scalability, HPE Aruba Networking CASB delivers secure access to modern cloud services and applications. In our cloud‑centric world, CASB as part of the broader HPE Aruba Networking SSE platform aims to deliver value with increased visibility, compliance, and data security from the outset.

    Benefits of HPE Aruba Networking CASB

    HPE Aruba Networking CASB enables businesses to embrace cloud and extend the same level of data security as they have for on premise services. Our CASB solution offers the following benefits:

    • Enhanced data security: Provides real-time scanning and monitoring of data usage and flow to and from the SaaS provider. This includes DLP capabilities that protect sensitive data by preventing unauthorized sharing and ensuring that data security policies are enforced. 
    • Visibility and control: Offers detailed visibility and control over cloud environments. Teams can see all user traffic, identify which cloud applications people are using, and apply granular controls to manage how data is accessed and used. 
    • Compliance: Supports compliance with data privacy regulations by enforcing corporate cybersecurity policies across multiple cloud environments. Risk assessments and scores for users and applications aid in the management of compliance requirements. 
    • Threat mitigation: Protects against both known and unknown threats, including anti-malware and anti-virus. Detects unusual behavior across cloud applications, identifying risks like ransomware, compromised users, and rogue applications, and can automatically remediate threats to limit organizational risk.
    • Operational efficiency: Consolidates multiple types of security policy enforcement into a single point, for streamlined security operations, and simplified management of security policies and securing multiple cloud services.

    CASB FAQs

    What are the core pillars of Cloud Access Security Broker (CASB)?

    CASB solutions are typically built on four core pillars: visibility, compliance, data security, and threat protection. They help organizations discover cloud application usage, enforce security policies, protect sensitive data, detect risky behavior, and support regulatory requirements across SaaS and cloud environments. 

    Where are CASBs used?

    CASBs are used to secure access to cloud services such as SaaS, IaaS, and PaaS applications. They are commonly deployed to protect users accessing cloud resources from corporate offices, branch locations, and remote environments, while maintaining visibility and policy enforcement. 

    How CASBs are deployed?

    CASBs can be deployed inline, where they inspect traffic in real time between users and cloud applications. This approach enables immediate enforcement of security policies, access controls, threat prevention, and data protection measures. Some CASBs also support API-based integrations to extend visibility and monitor data already stored within cloud services, but inline deployment provides the most comprehensive and proactive protection. 

    What are the differences between CASB vs. SWG vs. DLP?

    CASB focuses on securing cloud application usage and data within cloud services. Secure Web Gateways (SWG) protect users from web-based threats and enforce internet access policies. Data Loss Prevention (DLP) identifies and prevents sensitive data exposure across multiple channels. Many modern platforms combine all three capabilities. 

    What are the use cases for CASB?

    Common CASB use cases include discovering shadow IT, protecting sensitive data in cloud applications, controlling the upload and download of sensitive information to SaaS applications, preventing unauthorized data sharing, enforcing compliance requirements, monitoring user activity, detecting account compromise, and securing access to sanctioned and unsanctioned cloud services. 

    How do you choose a CASB?

    When selecting a CASB, evaluate visibility into cloud usage, data protection capabilities, threat detection, policy flexibility, deployment options, and integration with existing security tools. Organizations should also look for a single policy engine for SSE services including Zero Trust Network Access (ZTNA), Secure Web Gateway (SWG), CASB and DLP, which simplifies administration, reduces policy inconsistencies, improves operational efficiency, and enables consistent security enforcement across cloud applications, users, and data. 

    How does a CASB integrate with existing security infrastructure?

    CASBs commonly integrate with identity providers, security information and event management (SIEM) platforms, endpoint security tools, DLP systems, Zero Trust Network Access (ZTNA), Secure Web Gateways (SWG), firewall platforms, and SD-WAN. These integrations help organizations apply consistent policies, share security intelligence, automate responses, improve visibility, and enforce security controls across users, devices, applications, and networks. 

    Related products, solutions or services

    HPE Aruba Networking SSE

    Enable seamless and secure access for every user, device, and application from anywhere with Security Service Edge (SSE).

    HPE Networking EdgeConnect

    Enable data access wherever it lives with a secure SD-WAN SASE solution that produces both the connectivity and security necessary for hybrid cloud.