2 min Security

Cato integrates SASE platform with CrowdStrike Falcon

Cato integrates SASE platform with CrowdStrike Falcon

Cato Networks and CrowdStrike have announced a technical partnership to integrate the Cato SASE Platform with CrowdStrike’s Falcon platform. The integration enables organizations to leverage network and endpoint data within a single security workflow.

Companies often have separate solutions for network security and endpoint detection. As a result, security analysts must investigate incidents using data from different consoles. The new integrations are designed to combine that information, reducing the amount of manual work required for investigations.

The partnership is part of a broader trend in which security platform vendors are increasingly connecting their products via APIs and standard integrations, explains SiliconANGLE. Instead of a single, all-encompassing security platform, many organizations are opting for specialized solutions that exchange data with one another. By bringing together network, endpoint, and other security data, vendors are striving to simplify the work of security operations centers (SOCs) and provide faster incident insight.

A more comprehensive view of endpoints

One of the integrations links endpoint detections from CrowdStrike Falcon Discover to network telemetry from Cato XOps. In addition, information about managed devices is exchanged between Cato Asset Security and Falcon Discover. This creates a more comprehensive overview of endpoints.

CrowdStrike Falcon Next-Gen SIEM also gains access to network telemetry from the Cato SASE Platform. This allows analysts to use network and endpoint data together for threat hunting, detection rules, and incident investigation.

According to Karl Soderlund, Global Channel Chief at Cato Networks, an effective security strategy increasingly depends on combining diverse data sources. He states that the integration provides organizations with more context and better prepares security teams for AI-related threats.

Chris Stewart, vice president of global cloud and technology alliance partners at CrowdStrike, says the integration is designed to help customers correlate network and endpoint telemetry, streamline investigations, and respond more quickly to threats. The integrations are available worldwide immediately through the CrowdStrike Marketplace.