Cato Agentic Threat Prevention launches with automated dynamic controls
Cato’s new security service analyzes behavior every four hours and can apply tailored controls, but the company did not disclose pricing.
By Dominic Okoye · Staff Writer
· 3 min read
Cato Networks launched Cato Agentic Threat Prevention on Aug. 3, positioning the security service as a way to identify and disrupt AI-assisted attacks before they progress. The company disclosed no price, and its documentation sets out separate license terms for existing and new customers.
The feature operates on Cato’s security and network telemetry. Cato says its agents establish normal behavioral patterns for an environment, find deviations across activity and security signals, predict a possible next attacker action, then apply temporary controls specific to that customer’s environment. If malicious activity occurs, the system is designed to block it in real time; controls can later be changed or allowed to expire as the assessed risk shifts.
How does Cato Agentic Threat Prevention work?
According to Cato’s product documentation, the agents are powered by the Opus 4.6 large language model. They analyze network-wide traffic and security signals every four hours, reviewing the preceding 24 hours of activity across users, hosts, sites, applications and other entities.
Cato says the software compares events with account-specific behavioral context and correlates signals from security engines, including malware protection, intrusion prevention and firewall services. A download that is ordinary for an administrator, for example, may be treated differently for a user with no history of that action. Where the system judges activity to carry elevated risk, it can restrict access to exposed services, actions or paths.
Administrators can use an Agentic Threats page to review suspicious behavior, the reasoning and context behind detections, controls that remain active or were adjusted, and threats the system says it mitigated, according to Cato. The practical trade-off is familiar to security operators: the service automates enforcement, while teams still need to evaluate the visibility and control settings behind those interventions.
Cato frames the launch as a response to attackers using frontier AI models to automate and adapt multistage campaigns. Claims that such attacks can scan millions of environments, produce exploits within hours and operate at scale are the company’s stated rationale for the product; the materials supplied do not independently establish the prevalence of those attacks or the service’s effectiveness, false-positive rate or comparative performance.
Who can use Cato Agentic Threat Prevention?
Customers that held an active Advanced Threat Protection license as of August 2026 have Agentic Threat Prevention included, Cato says. Other customers need an Agentic Threat Prevention license in addition to either a Threat Prevention or Advanced Threat Prevention license. Cato directs prospective buyers to contact a representative and has not published pricing.
The launch is separate from Cato AI Security for Agents, another offering aimed at governing AI agents deployed by enterprises, including their prompts, tool calls and access. Agentic Threat Prevention instead targets attackers that Cato says use AI to accelerate attacks.
It also complements Cato’s Agentic CVE Mitigation service, which the company says assesses newly disclosed vulnerabilities and can apply protections in as fast as 45 minutes. That service addresses known new exposures, while the new product is intended to anticipate activity within a customer environment.
This story draws on original reporting from SiliconANGLE.