Cato is architected to deliver on the promise of SASE: secure and optimized access for everyone, everywhere, at any scale, and to any application. Cato is focused on offloading day-to-day work from the customers‘ IT and minimizing the dependency on scarce skills and resources.
The Cato architecture is comprised of multiple cloud-native, scalable, and extensible components that enable a consistent SASE experience even as customers’ footprint, requirements and use cases expand.
The Single Pass Cloud Engine (SPACE) is the core security engine of Cato. It converges multiple network security functions for flow control and segmentation (NGFW), threat prevention (SWG, IPS, NGAM, RBI), and application and data protection (CASB, DLP, ZTNA) into a cloud-native software stack. The SPACE consistently enforces security policies for both inline traffic and out-of-band access. With complete real-time traffic visibility, the SPACE captures rich context and event data for each inspected flow including network, device, application, and data attributes and feeds it to Cato’s open data lake for incident detection and response. All future network security capabilities will be built into the SPACE to benefit from the same single pass efficiency, cloud distribution readiness, and common data and policy management framework.
Cato created the first purpose-built SASE Cloud service backbone. Numerous Points of Presence (PoPs) worldwide run bare metal compute nodes within top-tier physical hosting providers to deliver real-time scalable and efficient security protection and network optimization. Thousands of SPACEs are orchestrated to deliver a resilient, low-latency inspection within short proximity to every user or location. The Cato PoPs are interconnected with multiple tier-1 global and regional carriers to form a cloud network optimizing Internet access to both Web and SaaS destinations as well as WAN access to on-premises and cloud datacenters and applications. Cato control and ownership of the physical cloud architecture enables footprint extensibility to anywhere in the world without dependency on hyperscalers footprint expansion and cost structures.
The Cato SASE Cloud Platform is built on an open data lake that ingests both Cato-generated feeds and third-party feeds from threat intelligence services to support real-time threat prevention. Network and security events are generated through SPACE processing and include rich context of the device, user, network, applications, and data associated with each flow. Endpoint events are created by the Cato Client ZTNA and EPP/EDR engines or via 3rd party endpoint solutions such as Microsoft Defender and Crowdstrike. The complete data set is used by Cato’s AI/ML-based threat hunting and network degradation detection and underpins Cato’s AI-assisted incident investigation and response tools. The data lake can be accessed by customers using the Cato API to extract granular data for processing by external solutions such as SIEM.
The Cato SASE Cloud Platform was architected to consistently and equally support all edges: devices, users, branch locations, physical and cloud datacenters, and the applications used by the business. Cato’s holistic visibility to all traffic enables the replacement of multiple point solutions such as firewalls and cloud proxies to mitigate risks such as web-based attacks, malware propagation across locations, and continuous protection of business applications as they migrate to the cloud.
Cato autonomously sustain the cloud platform resiliency, scalability, performance, and global reach. It takes away complex planning, design, deployment, and testing work from IT and enables agile response to new business needs.
The Cato SASE Cloud Platform automatically ingests hundreds of security feeds, developed by Cato and by third parties, and distributes them to all SPACEs globally in near real-time. Cato Security Research uses an AI/ML-based system to continuously validate the quality of each feed recommendation against the universe of feeds used by Cato to reduce the likelihood of false positives. Cato further mitigates emerging threats by developing and simulating the impact of new prevention rules on real customer traffic, and only then deploying these rules into production with 24-48 hours without any involvement of IT or impact to the end users.
Feed quality management and the automated mitigation of threats maximizes the stopping power of Cato and offloads complex and resource intensive processes from IT security.
Cato enables customers to easily migrate to the Cato SASE Cloud. Cato instantly connects physical locations to the Cato Cloud using zero-touch provisioning of Cato edge SD-WAN devices. Cato Clients are easily deployed through a self-service portal or enterprise endpoint mangement (MDM) platforms.
Cato is often used to fully migrate an organization to SASE. However, the Cato platform is modular, and can co-exist with current IT networking and security infrastructure including routers, firewalls, and cloud-based security services. Organizations can deploy Cato selectively and gradually, by use case, geography, or organizational unit, to address business and technical constraints until such a time they are ready to achieve full convergence.
The Cato SASE Cloud Platform was architected to deliver current and future network security capabilities through a single cloud service. All capabilities are managed through a single pane of glass that follows the same approach to configuring, troubleshooting, and analyzing all aspects of the service. Customers and partners use the Cato Management Application to define policies that are seamlessly distributed to all PoPs, SPACEs, and Cato Clients for consistent enforcement. Similarly, a single universal API is available to access all platform data to automate integrations with other business processes and 3rd party applications.
Von Grund auf als echte Cloud-native SASE-Plattform konzipiert, nutzen alle Sicherheitsfunktionen von Cato heute und in Zukunft die globale Verteilung, massive Skalierbarkeit, fortschrittliche Ausfallsicherheit, ein autonomes Life Cycle Management und das einheitliche Verwaltungsmodell der Cato-Plattform.
Cato erweitert alle Sicherheitsfunktionen global, um eine konsistente Durchsetzung von Richtlinien überall und für jeden zu gewährleisten, von den größten Datenzentren bis hin zu einem einzelnen Benutzergerät.
Cato lässt sich skalieren, um Multi-Gig-Datenströme mit vollständiger TLS-Entschlüsselung und über alle Sicherheitsfunktionen hinweg zu prüfen und kann sich nach Ausfällen von Dienstkomponenten automatisch wiederherstellen, um einen kontinuierlichen Sicherheitsschutz zu gewährleisten.
Cato stellt sicher, dass die SASE-Cloud-Plattform eine optimale Sicherheitslage, eine Serviceverfügbarkeit von 99,999 % und eine Sicherheitsverarbeitung mit geringer Latenz für alle Nutzer und Standorte aufrechterhält, ohne dass der Kunde eingreifen muss.
Cato bietet eine einzige Oberfläche für die konsistente Verwaltung aller Sicherheits- und Netzwerkfunktionen, einschließlich Konfiguration, Analyse, Fehlerbehebung sowie Erkennung von Vorfällen und Reaktion auf diese. Ein einheitliches Verwaltungsmodell erleichtert die Übernahme neuer Funktionen durch die IT und das Unternehmen.
Kunden nutzen Cato, um komplexe Legacy-Architekturen mit mehreren Sicherheits-Point-Solutions und kostspieligen Netzwerkdiensten zu eliminieren.
Die einzigartige SASE-Plattform von Cato bietet überall und für jeden einen sicheren und optimierten Anwendungszugang.
With Cato we have a good, solid sedan with the speed of a Porsche that got us exactly where we needed to go fast.”
Rodney Masney
Chief Information Officer
With Cato we have a very flexible supplier that understands our requirements and is there when we need help.”
Jan Jørgensen
IT Project Leader
Cato allowed us the flexibility to incorporate our WAN, Internet and remote access solutions into one neat package that could be managed with a small team of people.”
Joel Jacobson
Global WAN Manager
Cato’s management interface was so easy to use compared to those of the traditional SD-WAN players we looked at.“
Thomas Chejfec
Group CIO
I see Cato SASE as a tool for digital transformation promotion. We can use it to reorganize our entire security portfolio, reduce costs, and bring out the best in our students, professors, and administrators. Being able to work productively and securely anywhere gives a great boost to all our digital transformation initiatives.”
Hitoshi Kusunoki
Information Planning Department
Cato’s biggest benefit from my point of view is that our network operators no longer need any specialized knowledge.”
Takashi Nakajima
Head of the Digital Transformation (DX) Promotion Division and Chief of Business Operations
When we chose it over a year ago nobody was talking about SASE. Now, everybody is moving towards SASE and you can see it discussed in all the IT media.”
James Bonnaventure
CTO
Now with Cato we just fire a support ticket and Cato is on it. Within 30 minutes to an hour it’s resolved. And we can monitor every single step with Cato’s QOS metrics. We have goggles and eyes we never had before.“
Kevin Juma
Technology Operations Manager
With the Cato SASE Cloud from Cato Networks, we were able to connect locations and employees securely, easily and quickly. We now have the IT solution in-house and can adapt the infrastructure to our needs at any time with the desired flexibility.“
Ralf Luchsinger
Chief IT, Service and Provider Management
Thanks to Cato, I can stand by my promises and feel comfortable we can deliver on the company’s business needs quickly, efficiently, and securely.”
Jesper Hjørland
Service Manager for Network and Connectivity
I would recommend the Cato SASE solution to any healthcare organization that needs simple yet very secure connectivity among regional and local sites, remote users, and the cloud.”
Alvin Lim
Group Technology and Information Security Director
I know that my company is secure, that all my sites and users can connect with the same solution, and that every time I need something from Cato, they’ll listen carefully and come through. Thanks to Cato I can sleep at night.”
Shira Baum
CIO
We have improved the performance of every application on the network by rolling out Cato, We don’t hear about network slowness; we don’t hear complaints.“
Nick Hidalgo
VP, Information Technology
There are not many times as a CIO that you can check the box in all these areas – faster, more secure, happy users, and a happy team – all for less cost and more business value. That’s the Cato SASE Cloud Platform.”
Dustin Collins
Global CIO
The Cato team was interested in helping us succeed. After meeting their customer success manager and voicing our feedback on the product, Cato went out and changed the product. That’s what I call partnership.״
John Lim Ji Xiong
Chief Digital Officer
Cato Networks wurde im Gartner® Magic Quadrant™ for Single-Vendor SASE 2024 als Leader ausgezeichnet.
WAN-Transformation mit SD-WAN: Schaffung einer ausgereiften Grundlage für den SASE-Erfolg
„Wir haben einen Einbruchs- und Angriffssimulator auf Cato laufen lassen, die Infektionsraten und die laterale Bewegung sind einfach gesunken, während die Erkennungsraten gestiegen sind. Dies waren Schlüsselfaktoren für das Vertrauen in die Sicherheit von Cato.“
Die Lösung, auf die IT-Teams gewartet haben
Lassen Sie sich überraschen!
Mit Cato kann jedes Unternehmen die Vorteile der digitalen Transformation voll ausschöpfen, mit der Geschwindigkeit des Geschäfts vorankommen und für die nächsten Herausforderungen gerüstet sein.