Denise Dubie
Senior Editor

Cato Networks launches agentic threat prevention

News
Aug 3, 20265 mins

The new AI-powered SASE capability predicts attack paths using network and security telemetry and automatically deploys protections against AI-assisted cyberattacks.

Agentic AI
Credit: Rob Schultz / Shutterstock

Cato Networks has expanded the AI capabilities of its cloud-based secure access service edge (SASE) platform with Agentic Threat Prevention. This new service uses AI agents to predict how attackers are likely to move through an enterprise environment and automatically deploy protections before an attack can progress.

The capability combines network and security telemetry from across the Cato platform to build customer-specific attack models, correlate unrelated events, and enforce preventive controls globally through the company’s SASE platform.

Unlike traditional attack path analysis and exposure management tools that focus on identifying vulnerabilities or prioritizing risk, Cato said Agentic Threat Prevention goes beyond analysis by anticipating likely attack progression and automatically adapting protections.

“Cato Agentic Threat Prevention starts from the premise that preventing AI-assisted attacks requires more than isolated alerts,” said Brian Anderson, global field CTO at Cato Networks, in an interview with Network World. “It uses Cato’s unified network and security context to build an understanding of each customer environment, including users and identities, devices, applications, assets, traffic patterns, security events, vulnerabilities, data activity, and threat intelligence.”

The platform correlates those data points to identify activity that might appear harmless on its own but could signal the early stages of a larger attack, according to Anderson. For example, downloading an administrative tool may not be suspicious in isolation, but when combined with factors such as the user’s role, the time of day, the download source, and other environmental exposures, the platform can predict likely next steps, including tool execution or lateral movement, and automatically apply preventive controls.

Cato SASE Cloud Platform runs on a private global backbone of more than 85 points of presence (PoP) connected via multiple SLA-backed network providers. The PoPs software continuously monitors the providers for latency, packet loss, and jitter to determine in real-time the best route for every packet. Cato applies optimization and acceleration to all traffic going through the backbone to enhance application performance and the user experience. To ensure all locations benefit, Cato optimizes traffic from all the edges and toward all destinations, on-premises and in the cloud.

According to Anderson, Agentic Threat Prevention is designed primarily to stop sophisticated, multi-stage attacks where context and prediction matter, including AI-assisted exploitation, lateral movement, identity-driven attack paths, and ransomware precursors. It is not intended to replace Cato’s existing inline protections for short-lived malware or rapid “smash-and-grab” attacks, which are handled by the company’s IPS, anti-malware, DNS protection, firewall, and Dynamic Prevention engines.

“AI-assisted attacks are exposing the limits of static security controls and manual response. An entire attack can require less time than is required to investigate an alert,” said Frank Dickson, group vice president at IDC, in a statement. “As attackers adapt faster and tailor campaigns to each environment, enterprises will need prevention approaches that use shared context, automation, and cloud-scale enforcement to reduce exposure before compromise occurs.”

This capability is designed to address AI-assisted attacks that can move faster than traditional detection and response processes. According to Anderson, what differentiates the technology is its ability to reason rather than simply execute predefined workflows.

“What makes the approach agentic is the ability to reason across multiple signals, anticipate likely next steps, and adapt protections automatically within the platform, rather than simply triggering a prebuilt workflow after a known condition based on known attack patterns,” Anderson said.

Depending on the predicted attack path, the platform can block access to suspicious tools, prevent additional tool downloads, apply threat prevention controls, or tighten access policies based on the customer’s specific environment rather than generic security rules. The system also periodically reevaluates automated restrictions and removes them if behavior returns to normal to help reduce false positives, according to Cato.

Cato also shared early production and testing metrics to support the technology’s effectiveness. According to the company, the engine processes an average of 4.5 million traffic signals per customer account each week, generating more than 345,000 condition matches and enforcing more than 71,000 targeted restrictions without analyst intervention. Cato also said its internal agentic red team lab has run more than 500 autonomous attack simulations since mid-May, during which the platform consistently blocked attackers before they reached their objectives by applying an average of 15 targeted controls per affected host and mitigating 12 distinct threat vectors per attack.

Agentic Threat Prevention complements Cato’s recently introduced Agentic CVE Mitigation capability, which automatically assesses newly disclosed vulnerabilities and applies protections in as little as 45 minutes. The two capabilities are intended to reduce both the vulnerability exposure window and the time attackers have to move laterally through an environment. Anderson said the new capability reflects a broader evolution in enterprise security from reactive detection to predictive defense.

“The meaningful shift is from reactive detection to predictive prevention,” Anderson said. “In our current AI era, prediction is the new prevention. Defenders need systems that can anticipate attacker movement and act at machine speed to keep pace with AI-assisted attacks.”

Cato’s Agentic Threat Prevention is generally available now.

Denise Dubie

Denise Dubie is a senior editor at Network World with nearly 30 years of experience writing about the tech industry. Her coverage areas include AIOps, cybersecurity, networking careers, network management, observability, SASE, SD-WAN, and how AI transforms enterprise IT. A seasoned journalist and content creator, Denise writes breaking news and in-depth features, and she delivers practical advice for IT professionals while making complex technology accessible to all. Before returning to journalism, she held senior content marketing roles at CA Technologies, Berkshire Grey, and Cisco. Denise is a trusted voice in the world of enterprise IT and networking.

More from this author