Palo Alto Networks Achieves Highest Overall CASB Protection Rate in SecureIQLab Validation

Oct 08, 2026
3 minutes

As SaaS applications become central to how organizations create, share and store information, security teams need more than visibility into application usage. They need consistent control over user activity, sensitive data and application risk.

The 2026 SecureIQLab SSE Independent Cyberrisk Validation Comparative Report, commissioned by Palo Alto Networks, evaluated five SSE solutions across 643 CASB test cases. Palo Alto Networks achieved the highest total protection rate at 91.7%, compared with a 62.3% group average.

The results highlight three areas security leaders should consider when evaluating SaaS security.

Strengthening Control Across SaaS Applications

Sanctioning an application is only the beginning. Organizations also need granular control over what users do inside SaaS applications, from sharing and downloading files to messaging and collaboration.

Palo Alto Networks achieved a 90.7% Activity Control protection rate, compared with a 60.9% group average, across testing that included communication, collaboration, file sharing, cloud storage, code repositories and other application categories.

But controlling user activity is only one part of the equation. Organizations also need to protect the data involved in those interactions.

Protecting Sensitive Data as It Moves

Sensitive data moves across file sharing, collaboration, cloud storage, code repositories and emerging AI workflows. Protecting one channel while leaving another exposed can create gaps as data moves across the enterprise.

Data Control was a challenging area across the evaluation, with a 65.5% group average. Palo Alto Networks achieved the highest overall result at 82.0%, across testing spanning multiple enterprise and GenAI scenarios.

Effective SaaS security requires data protection that follows sensitive information across the different ways people work.

Mitigating Exposure Across the SaaS Environment

Protection cannot stop with data in motion. Organizations also need visibility into data already residing in SaaS and the application-level risks that can expose it.

Palo Alto Networks achieved a 90.9% Out-of-Band CASB protection rate, compared with a 54.3% group average. SecureIQLab noted that lower results for several evaluated vendors were primarily driven by limited API-based application coverage. Palo Alto Networks also achieved a 95.1% SSPM protection rate across the tested scenarios, compared with a 30.7% group average.

Together, these capabilities extend protection from individual user interactions to the broader SaaS environment where sensitive data resides.

Key Outcomes from the SecureIQLab Validation

The evaluation highlights four considerations for organizations modernizing SaaS security:

  • Granular SaaS Control: Govern what users can do within sanctioned applications.
  • Consistent Data Protection: Protect sensitive data across applications, channels and workflows.
  • Data-at-Rest Protection: Extend visibility and protection to data already residing in SaaS.
  • SaaS Posture: Identify application-level risks and misconfigurations that can expose sensitive data.

The findings reinforce a simple point: SaaS security should be measured by the protection it delivers, not simply by the capabilities on a checklist. The SecureIQLab validation demonstrates the breadth of protection needed across today’s SaaS environments. For a detailed look at the methodology and results, read the full report here.


Subscribe to Sase Blogs!

Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more.