Glossary · simply explained

CASB (Cloud Access Security Broker)

A cloud access security broker (CASB) is the control point between users and cloud services: it reveals which SaaS applications are actually in use, enforces policies for handling data and detects risky configurations in the services themselves.

The trigger is almost always shadow IT: business units use cloud tools the IT department knows nothing about — with company data outside any control. A CASB brings this usage to light and into orderly channels.

How does a CASB work?

Two operating modes complement each other: inline, the CASB sits in the data path — usually integrated with SWG and ZTNA in an SSE platform — and can control actions in real time: block uploads, allow downloads on managed devices, prevent risky shares. Via API it additionally connects directly to the SaaS services and inspects data at rest, shares and configurations there — such as publicly shared documents or dormant admin accounts.

Combined with data loss prevention this creates end-to-end control: who uses which service, with which data, under which conditions.

Typical CASB use cases

  • Shadow IT inventory: which cloud services are really used in the company.
  • Policies per service and device: company tenant allowed, private instance read-only.
  • Detection of risky shares and misconfigurations in SaaS services.
  • GDPR-relevant control over where personal data flows into which services.

Frequently asked questions about CASB (Cloud Access Security Broker)

Why do you need a CASB?

As soon as company data lives in SaaS services, you need visibility and control: which services are used, which data flows there, which shares exist? A CASB answers these questions and enforces policies — from blocking to fine-grained action control.

What is the difference between inline and API mode?

Inline, the CASB sits in the data path and controls actions in real time, such as upload bans. API mode connects directly to the SaaS service and inspects data at rest, shares and settings there. Effective protection combines both views.

How does a CASB detect shadow IT?

From user web traffic: the CASB classifies accessed services, rates their risk and builds a usage inventory. That reveals which tools business units use beyond the approved landscape — the basis for approval, an alternative or a block.

Is a CASB part of SASE?

Yes — CASB is one of the core building blocks of SASE and SSE, alongside SWG, ZTNA and FWaaS. In one platform the services share identities, policies and logs instead of running side by side as separate products.

Does a CASB replace DLP?

No, they interlock: DLP defines which data is worth protecting and recognises it in motion and at rest; the CASB is one of the places where those rules are enforced — on upload, on shares, in the SaaS services themselves.

Open questions about this in your environment? KAEMI advises you in line with your requirements and can also take over ongoing management.