top of page

Your CASB Has Been Lying to You for Five Years

Look at your CASB dashboard. It's green. Mostly green. A couple of yellow indicators if you scroll. Pretty charts. Confident metrics. The vendor's quarterly business review looks great.

Now ask yourself: when was the last time the CASB caught something you didn't already know about?

If you can't remember, you're not alone. The CASB was a great idea in 2015. It saw network traffic from corporate devices, identified the apps that traffic was going to, and flagged the ones nobody had approved. That was useful when the company laptop was the primary access device, the corporate VPN was the primary route, and the apps in question were full-fat web apps making chatty backend calls.

None of those assumptions are reliably true anymore.

Where modern SaaS adoption actually happens

Today an employee finds an AI tool on their phone during their commute. They sign in with their work Google account, click "Allow" on the OAuth consent screen, and now have a persistent token authorized to read their Drive and inbox. The CASB never saw it. The phone was on a cellular network. The OAuth handshake routed directly from Google to the vendor. No corporate egress, no Surface in the SWG logs, nothing.

An hour later, that same employee is on the corporate network. They open the AI tool in a browser. The CASB sees an HTTPS connection to "ai-tool.com." Maybe it categorizes the domain as "Productivity." Maybe it doesn't have a category at all. Either way, the action that mattered — the OAuth grant — happened off-network and is invisible to the CASB forever.

The pretty dashboard is doing exactly what it was built to do

This isn't the CASB's fault. The CASB is doing exactly what it was designed to do. It's watching the network. The problem is that the network stopped being where the interesting stuff happens. Most of the consequential SaaS and AI adoption in 2026 is happening through OAuth federation, mobile devices, BYOD, and SaaS-to-SaaS integrations — none of which the CASB has any meaningful visibility into.

The vendors know this. Every CASB pitch deck in the last two years has quietly pivoted to talking about "API-based discovery" or "identity-aware" features. That's the polite way of admitting the original product premise has aged badly. The dashboards still look great because the underlying scope shrank, not because the threats did.

The proof is in your own data

Try this. Pull the list of apps your CASB reports for last quarter. Now pull the OAuth grant list from your Google Workspace or Microsoft 365 tenant. Compare them. The OAuth list will be much longer. It will contain apps the CASB doesn't know exist. It will contain integrations that authorize broad access to your data using tokens that don't expire. That gap is the lie. Not malicious — but a lie all the same.

The Cloud Security Alliance has been saying this for two years: SaaS governance starts with discovery, and discovery has to be identity-based, not network-based. The CISA SCuBA baselines back it up. The NIST Cybersecurity Framework 2.0 assumes you have an asset inventory worth governing. None of those assumptions match what the CASB was built to do.

What to do instead

Don't rip out the CASB. It still catches some things, and the contract has a year left anyway. But stop pretending it's giving you a complete picture. Start running OAuth discovery against your workspaces. Look at the apps holding data that nobody sanctioned. Map the identity perimeter that's been the real perimeter for a while now. Once you've seen the gap, you can't unsee it.

That's what Waldo Security's Shadow IT solution exists to do. It's not a replacement CASB. It's the thing the CASB was supposed to be once everything moved off the network.

Want to see the gap your CASB has been hiding? Book 30 minutes. We'll show you yours.

Comments


bottom of page