Join our Newsletter — 33% off our NHI Course

CASB in remote work: what governance gaps are teams missing?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: CASBs struggle to keep up with remote work because proxy-based deployment, manual policy handling, incomplete SaaS visibility, and weak offboarding support leave operational gaps that cloud-first teams still have to close, according to Zluri. The underlying issue is that legacy inspection models were built for network boundaries, not for SaaS sprawl and identity-driven access.

Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “Drawbacks of CASBs (Cloud Access Security Brokers) in the Remote World”.

By the numbers:

  • According to a Gartner report cited by Zluri, CASB solutions cost between $15/user/year and $85/user/year.
  • The article says almost 360k new malware is found every day.

Key questions

Q: What breaks when CASB only covers live SaaS sessions?

A: You miss the exposures that persist after the session ends, including public file links, dormant users, missing MFA, and over-privileged accounts.

Q: Why does remote work make CASB less effective for SaaS governance?

A: Remote work widens the gap between where traffic is inspected and where identity decisions are actually made.

Q: What are the signs that CASB visibility is not enough?

A: Warning signs include unknown or unsanctioned apps that remain outside coverage, policy decisions that require manual check-box work, and users who still retain meaningful access after the broker layer has done its inspection.

Practitioner guidance

  • Define the SaaS governance boundary Document where CASB visibility ends and where entitlement, offboarding, and privileged access controls must take over for each critical SaaS application.
  • Replace manual policy handling Remove any CASB workflow that still depends on repeated manual classification, connector setup, or check-box policy tuning before enforcement can occur.
  • Tie remote access to lifecycle controls Align remote endpoint access with joiner-mover-leaver processes so SaaS permissions are granted, reviewed, and removed through the same governance path.

Bottom line: CASB remains useful for inspection, but remote work exposes that inspection alone does not govern SaaS access end to end.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

CASB is being asked to solve a governance problem it was not built to own: the control model assumes that network mediation plus policy inspection can keep pace with SaaS sprawl, but remote work breaks that assumption. Zluri’s critique points to a deeper issue than deployment friction: modern identity governance needs lifecycle execution, not only traffic observation. The practitioner conclusion is that visibility without operational enforcement leaves the programme looking controlled while remaining materially incomplete.

A question worth separating out:

Q: Should organisations treat CASB visibility as a substitute for SaaS governance?

A: No. CASB visibility helps discover activity and flag risk, but governance still requires ownership, entitlement review, and lifecycle handling. Without those controls, the organisation may know an app is present and risky while still lacking a defensible way to approve, reduce, or remove access.

👉 Read our full editorial: CASB drawbacks in remote work expose SaaS governance gaps


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.