Cato-CrowdStrike Partnership Is ‘Massive’ Win For Reducing Security Complexity, Improving Efficacy: Solution Provider CTO

Cato Networks’ recently expanded partnership with CrowdStrike brings together two of the industry’s most highly effective cybersecurity platforms with huge promise for reducing complexity for customers, Defensive Networks CTO Ben Ferguson tells CRN.

Cato Networks’ recently expanded partnership with CrowdStrike brings together two of the industry’s most highly effective cybersecurity platforms with huge promise for reducing complexity for customers, a top partner of the two vendors told CRN.

For Defensive Networks, the integration represents a major advancement through combining Cato’s differentiated network security capabilities with CrowdStrike’s esteemed offerings in endpoint security and security operations, according to Ben Ferguson, executive vice president and CTO at the El Segundo, Calif.-based solution provider.

[Related: Cato Networks Expands Into AI Security With First-Ever Startup Acquisition]

The partnership delivers “massive architectural simplification” and ultimately accelerates the critical work of security teams, he said.

Defensive Networks has spent many years testing security products to determine whether their efficacy matches the claims of vendors, Ferguson noted. That testing led Defensive Networks to view Cato as not just an SD-WAN vendor with a few security capabilities, but as “a very serious, premier cybersecurity company on the network security side,” he said.

In the world of SASE (Secure Access Service Edge), Cato clearly stands out by delivering “a lot of really cool, really efficient tools for managing large networks and reducing complexity,” Ferguson said.

Cato then brings in additional “higher functions through a forward proxy—where you’re running it in the cloud, so you can democratize a lot more things that would be otherwise extremely expensive to deploy out at the edge,” he said.

CrowdStrike, meanwhile, is a longtime strategic vendor partner for Defensive Networks, and Ferguson is a founding member of the cybersecurity giant’s technical advisory board, Ferguson said.

Defensive Networks is also “one of the top implementation partners in the world” for the cybersecurity vendor, he said. “They’re just the efficacy leader in that space, in system security.”

Ideal For Hybrid

In particular, the tight integration of Cato and CrowdStrike technologies is especially well-suited to businesses that still operate their own data centers and offices even as they adopt cloud, SaaS and AI through a hybrid architecture, Ferguson said.

“I think that is a sweet spot, where Cato has probably the best story in hybrid architecture—because they’re the hybrid SASE company, definitively,” he said. “It should resonate with the sharp decision-makers.”

The expanded Cato-CrowdStrike partnership, unveiled in July, includes three integrations between the Cato SASE Platform and CrowdStrike’s Falcon platform.

One integration connects Cato XOps with CrowdStrike Falcon Discover to correlate network telemetry with endpoint detections, with the aim of giving enhanced context for faster security investigations. A second integration combines Cato Asset Security with Falcon Discover to boost device intelligence and provide broader visibility across managed assets, according to the companies.

The third integration enables customers to stream network telemetry from Cato’s SASE platform into CrowdStrike Falcon Next-Gen SIEM platform, expanding the data available to analysts for activities such as threat hunting and investigations.

The integration addresses a longstanding challenge in security operations by unifying network and endpoint visibility, according to Cato Global Channel Chief Karl Soderlund.

The combination of Cato XOps with CrowdStrike Falcon Discover, for instance, provides “a complete view of all the assets” that an organization has, Soderlund said. “That’s half the battle in a lot of cases. And then, how do we strengthen the posture that we have together, and what do we do?”

That’s where the integration of Cato Asset Security and Falcon Discover comes into play, he said.

The combination involves “enriching device intelligence and endpoint posture together, having that access and giving kind of that complete view of what those managed assets are—and how we can actually make the changes necessary to improve,” Soderlund said.

Then with the third integration, Cato is taking its SASE platform and “wrapping it into [CrowdStrike’s] Next-Gen SIEM to help analysts hunt the threats, build out detections, investigate the activity and solve the problem,” he said. “So it’s really a nice, complete, end-to-end story.”

Ultimately, “I think the biggest thing we’re doing is removing silos,” Soderlund said. “So all the different infrastructure silos that are out there, the technology debt that’s hanging out there, the lack of resources and skills—that’s what the customers are struggling with.”

Architectural Simplification

For Defensive Networks, one of the most significant benefits is the ability to send Cato network data into CrowdStrike Next-Gen SIEM through a single API, Ferguson said.

With many competing network security tools, partners are forced to deploy log collectors at each customer site or build tunnels to more-centralized collectors, he noted. That approach can be time-consuming, as well as “virtually impossible” to make resilient, he said.

By contrast, Ferguson said he was able to connect the Cato data sources to CrowdStrike in his lab just minutes after learning that the integration was available.

“I implemented all these data sources in 15 minutes,” he said, adding that he could do the same for a global company with numerous locations in that short time window.

For “virtually every other architecture,” this process might require “one hour, two hours, three hours per site,” Ferguson said.

Ultimately, “the simplification of that shouldn’t be undervalued,” he said. “It’s the first out there that has so much data and context through a single API key swap. I think that is a big deal.”

Complementary Market Expansion

Notably, the Cato-CrowdStrike partnership also brings together two vendors whose current market expansion efforts are highly complementary, according to Soderlund.

Cato has been “aggressively” moving upmarket into Global 2000 and Fortune 500 accounts—where CrowdStrike already has a well-known and major presence—while CrowdStrike has been pushing further into the midmarket and mid-enterprise segments where Cato is strong, he said.

Thus, beyond the technical enhancements through integrating the Cato and CrowdStrike platforms, “there is this cool go-to-market partnership, too,” Soderlund said.

All in all, solution and service provider partners are quickly recognizing how they can position the combined Cato-CrowdStrike offerings for customers, which are increasingly seeking help with key areas such as cybersecurity and AI governance, he said.

Partners can now provide “this differentiated story that’s really comprehensive and really simplistic to bring to [customers],” Soderlund said. “It’s accelerating faster than I anticipated.”