Cato and CrowdStrike link SASE and endpoint security tools
The companies made integrations generally available through CrowdStrike Marketplace; deal terms and customer adoption figures were not disclosed.
By Wei-Lin Zhao · AI Correspondent
· 3 min read
Cato Networks and CrowdStrike have made new integrations generally available that connect Cato’s SASE Platform with CrowdStrike’s Falcon platform, with no financial terms disclosed. For security teams, the pitch is operational: put network telemetry and endpoint signals in the same workflow so investigations require fewer manual handoffs.
The companies said the partnership is meant to reduce the gap between tools that often sit in separate parts of the security stack. Endpoint alerts can show suspicious activity on a device, while network systems can show traffic patterns around that device. Cato and CrowdStrike said joining those views should help analysts add context to detections and respond faster, although they did not disclose customer adoption, pricing or performance metrics for the integration.
What is being integrated
The work spans three product connections. Cato XOps will integrate with CrowdStrike Falcon Discover to match endpoint detections with Cato network telemetry. The companies said that combination is intended to improve threat visibility and speed investigations.
Cato Asset Security will also connect with Falcon Discover. That integration combines Cato’s device intelligence with endpoint context from CrowdStrike, giving customers a more complete asset view across managed devices, according to the companies.
The third component sends telemetry from the Cato SASE Platform into Falcon Next-Gen SIEM. CrowdStrike customers can use that data for threat hunting and detection engineering inside the SIEM environment, the companies said.
Channel angle
The integrations are available globally through the CrowdStrike Marketplace. TD SYNNEX is also part of the distribution story. Francisco Criado, senior vice president of security, cloud and AI at TD SYNNEX, said the collaboration gives channel partners an integrated security approach that can be deployed and scaled more easily.
Karl Soderlund, Cato’s global channel chief, framed the deal around richer security data and AI-era threats, saying security outcomes improve when teams have connected data. That is a common claim in the security market, where vendors are adding AI language to most product announcements. The companies did not provide benchmarks showing reduced investigation time or response time.
Chris Stewart, CrowdStrike’s vice president of global cloud and technology alliance partners, said the integration lets customers correlate network and endpoint telemetry and streamline investigations. The statement keeps CrowdStrike’s role familiar: Falcon remains the endpoint and SIEM control point, while Cato contributes network and SASE telemetry.
Why Cato is pushing the connection
Cato is a venture-backed security and networking company competing in the secure access service edge market. Its most recent disclosed financing was a $359 million round in June 2025, which valued the company at more than $4.8 billion.
The CrowdStrike partnership gives Cato another route into security operations teams that already use Falcon. For CrowdStrike, the integration adds network context from a SASE vendor without requiring it to own that layer directly. The announcement is product-level, not a merger or financing event, but it reflects the continued pull toward combined telemetry across endpoint, network, asset and SIEM systems.
This story draws on original reporting from SiliconANGLE.