Cato Networks added a data loss prevention (DLP) engine to its security services edge (SSE) 360 service aimed at protecting data across Enterprise applications without the complexities of a traditional DLP.
DLP has been an effective tool for protecting data assets, but according to Boaz Avigad, director of product marketing at Cato, it has in the past been inaccurate, with policy difficult to implement.
“It's about making things easy, simple, and quick,” Avigad told SDxCentral.
Avigad explained the Cato DLP works in three steps – profiling of sensitive data, setting policy, and policy enforcement. The Cato system has 350 data types, including social security numbers, credit card information, and bank accounts, which are split into categories of compliance and location. Once data profiles are built, those responsible for enforcing policy within an Enterprise are able to set rules defining the accessibility of each data type.
The system comes with predefined data types, but Avigad noted Cato will soon introduce the ability to add custom types, which he said will be helpful in cases such as an Enterprise having its own SKU numbers to protect. Additionally, the engine applies machine learning (ML), using anomaly detection algorithms to identify when DLP rules exceed predefined baselines, and notifies the Cato security content team to refine and improve “out-of-the-box” data types.
“We want even customers who don't have experience with DLP or training for the first time just to be able to get into this and have it be usable and effective for them,” Avigad said.
Industrywide DLP, Cloud Access Security Broker RenovationsAvigad said because CASB and DLP are often offered either in tandem or as one unified tool, they are easily confused. However, he clarified that the two are different, with CASB focused on user protection while DLP puts an emphasis on securing the data itself.
Cato is not the only provider revamp tools like DLP and CASB to support the industry migration to a full secure access service edge (SASE) transformation. Juniper Networks last month added CASB and DLP capabilities to its security service edge (SSE) portfolio, taking the service one step closer to a full SASE architecture.
Dell’Oro Group last year in its Network Security Market report named VMware, Cato, and Versa Networks as vendors offering a truly “unified SASE” platform.
“There's a growing need for not just security but holistic security,” said Dave Greenfield, Cato's director of technology evangelism. “One solution that's going to pull together the all the various security products an organization has been running.” The big question, he added, is whether the convergence of tools like DLP, secure web gateway, CASB, and ZTNA – or an SSE solution – is good enough.
“At the end of the day, everyone agrees that SASE is the goal,” Greenfield said. “The question is how do you get there. SSE is seen as an interim step.”
Comments