Talk to us
by BroadcomTechBag Intel Page

Symantec CloudSOC CASB

Your DLP rules guard laptops and email. The same data shouldn’t slip out through Box, Slack or a personal phone — Symantec CloudSOC CASB finds shadow IT in the logs you already keep, scans sanctioned apps such as Office 365 and Box by API, and controls cloud traffic inline, with Mirror Gateway covering unmanaged devices and Symantec DLP rules reused throughout.

Audit, Securlets and inline GateletsSymantec DLP policies reused as profilesQuote; sold inside DLP Cloud

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Broadcom prints no CloudSOC price; it is usually quoted as part of the DLP Cloud bundle
Quote
Analysts
Broadcom in Gartner’s 2025 Security Service Edge MQ, the market CASB now sits in
Niche Player
Coverage
Broadcom’s own figure for the applications its CASB controls; not independently measured
45,000+ apps
India
No Indian data region is documented for CloudSOC; get the tenant’s region in writing
Ask

Quick answer

Symantec CloudSOC CASB is Broadcom’s cloud access security broker. Audit rates the shadow IT found in your proxy and firewall logs; API Securlets scan sanctioned apps such as Office 365, Google Workspace, Box, Salesforce and Slack; inline Gatelets and Mirror Gateway, for unmanaged devices, act on traffic in flight. It is sold inside the Symantec DLP Cloud bundle on quote only, and Broadcom lists no Indian data region for it. Read more ↓ Show less ↑
Part 01 · Orient

The Broadcom platform family

This page covers Symantec CloudSOC CASB — Audit, Securlets, Gatelets and Mirror Gateway, sold in DLP Cloud. The rest:

Quick facts

30-second orientation
Product
Cloud access security broker: log-based shadow IT Audit, API Securlets and inline Gatelets
Maker
Broadcom Inc., Palo Alto; Enterprise Security Group under Jason Rolleston; CEO Hock Tan
Status
A live product, packaged in Symantec DLP Cloud; no end-of-sale notice has been found
Price
Not published; bought through partners, and no reseller price list was found for it
Licence
Inside DLP Cloud: Audit, CASB for SaaS and IaaS, CloudSOC Gateway and cloud DLP detection
Coverage
Broadcom says its CASB controls over 45,000 applications; five sanctioned SaaS apps named
Data
Classifies PII, PCI and PHI; Symantec DLP policies import as CloudSOC DLP profiles
Analysts
Gartner SSE MQ 2025: Niche Player; KuppingerCole Zero Trust Platforms 2026: Overall Leader (SSE)
India
No Indian CloudSOC data region documented; Broadcom offices in Bangalore, Hyderabad and Pune
In India via
TechBag — app inventory, Securlet pilot, mode plan, quote in INR with GST
Part 02 · Learn

Understand CASB before you buy one

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is a CASB?

A cloud access security broker sits between your people and the cloud apps they use, finding them and controlling the data inside.

Firewall reports and per-app admin consoles vs Symantec CloudSOC CASB — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionFirewall reports and per-app admin consolesSymantec CloudSOC CASB
Knowing which apps staff useA guess from the firewall’s top-sites listAudit’s rated inventory built from those logs
Files already shared outInvisible until someone complainsSecurlets read sharing in sanctioned apps
A risky upload in progressLogged, maybe, after it has goneGatelets stop it inline at the gateway
Personal laptops and phonesEither blocked or simply trustedMirror Gateway applies the same app rules
DLP rules for cloud appsWritten again, app by appSymantec DLP policies imported as profiles
What it is NOT—A web gateway, a published price, or India-hosted

The cheapest test is one Securlet: connect a single Office 365 or Box tenant, block nothing, and read what is already shared outside.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where shadow IT is found

Audit

CloudSOC Audit

Audit takes the proxy and firewall logs you already collect, lists every cloud service staff reach, and gives each one a Business Readiness Rating for risk and compliance.

02
Where stored data is scanned

Securlets

API Securlets

Securlets connect to sanctioned apps such as Office 365, Google Workspace, Box, Salesforce and Slack by API, reading files, shares and user activity already inside them.

03
Where traffic is controlled

Gateway

Gatelets and CloudSOC Gateway

Gatelets inspect requests to cloud apps inline through the CloudSOC Gateway, so a risky upload, download or share can be blocked while the user is still doing it.

04
Where unmanaged devices are covered

Mirror

CloudSOC Mirror Gateway

Mirror Gateway extends CloudSOC’s app controls to BYOD and other unmanaged devices, so a personal laptop signing in to a sanctioned app meets the same policy.

Logs reveal the apps, APIs read what is stored — then an inline gateway and Mirror Gateway act on live traffic.

Part 03 · Evaluate

Nine capabilities. Audit, enforce, respond.

Symantec CloudSOC CASB rates the cloud apps in use, scans the approved ones by API and acts on traffic inline.

Audit
Shadow IT

Unapproved apps, from your logs

Audit parses existing proxy and firewall logs, lists the cloud services in use and rates each with a Business Readiness Rating.

Audit
Securlets

API reach into approved apps

Securlets connect by API to apps like Office 365, Box, Salesforce and Slack, showing who shares what, including files stored long ago.

Audit
IaaS posture

Cloud resources left open

CASB for IaaS adds cloud security posture management, flagging resources whose settings would expose data to the public internet.

Enforce
Gatelets

Stopped while it happens

Gatelets read cloud-app traffic inline through the CloudSOC Gateway, so a share or upload that breaks policy is halted mid-action.

Enforce
Mirror Gateway

Personal devices, same rules

Mirror Gateway gives BYOD and other unmanaged devices the same cloud-app access controls that company-managed laptops receive.

Enforce
App policy

Adopt, block or substitute

Automated policies act on each discovered app: allow it, block it, or point staff to an approved service that does the same job.

Respond
DLP

Symantec DLP rules, reused

Policies built in Symantec DLP import into CloudSOC as DLP profiles, so SaaS files meet the rules already set for endpoints and email.

Respond
ThreatScore

A risk score for every user

UEBA and machine learning raise a user’s ThreatScore with each violation, surfacing hijacked accounts and insiders for adaptive action.

Respond
Malware

Infected files in shared folders

Cloud-borne malware is detected so staff do not bring in, or pass along, infected files through the apps and folders they share.

See it, don’t just read it

Watch Symantec CloudSOC CASB in action

Four 2023 walkthroughs from Symantec’s official channel: inline Gatelets, the year’s feature round-up, and two demos of using Symantec DLP policies as CloudSOC profiles.

Symantec by Broadcom (official)·Demo, April 2023

Getting Started with CloudSOC CASB - Gatelets (Inline Inspection)

A 2023 walkthrough of turning on Gatelets, CloudSOC’s inline inspection of cloud-app traffic.

Symantec by Broadcom (official)·Update, April 2023

What’s New in CloudSOC CASB

The 2023 round-up of CloudSOC feature changes; check with Broadcom what has shipped since.

Symantec by Broadcom (official)·How-to, October 2023

Adding a DLP profile to a CloudSOC protect policy

A 2023 demo of attaching a DLP profile to a protect policy so files in cloud apps are checked.

Symantec by Broadcom (official)·How-to, October 2023

How to import a DLP Policy into CloudSOC as a DLP profile

A 2023 demo of bringing an existing Symantec DLP policy into CloudSOC instead of rebuilding it.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Symantec CloudSOC CASB

Your data now lives in apps you don’t run. CloudSOC carries your DLP rules in there with it.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Shadow IT counted from logs you already have

Audit needs no new agent to start: it reads the proxy and firewall logs your network already produces, lists the cloud services people actually reach, and scores each with a Business Readiness Rating. That turns a guess about unapproved apps into a ranked list you can allow, block or replace.

02

One DLP policy, carried into the cloud

For an estate that runs Symantec DLP, the draw is reuse. Existing DLP policies import into CloudSOC as DLP profiles, and Broadcom describes one policy engine across cloud apps, email and the web. PII, PCI and PHI are classified automatically, so SaaS files meet the rules already written.

03

Three routes in, including unmanaged devices

Securlets scan sanctioned apps by API for data already stored; Gatelets act inline through the CloudSOC Gateway on what is moving now; Mirror Gateway covers BYOD and unmanaged devices. Each user’s ThreatScore, built by UEBA, then lets policy tighten for the accounts that behave oddly.

04

Where it stops

There is no public price, and CloudSOC normally arrives inside the DLP Cloud bundle rather than alone. Broadcom documents no Indian data region for it. The newest official demos are from 2023, and Broadcom was a Niche Player, not a Leader, in Gartner’s 2025 SSE Magic Quadrant.

The idea
Audit by logs, Securlets by API, Gatelets inline
The reuse
Symantec DLP policies as CloudSOC profiles
The price
Quote; normally inside the DLP Cloud bundle
Proof, not promises

The numbers behind the platform

45000+ apps
the applications Broadcom says its CASB controls, per its network-protection page
— Vendor
7 components
in the DLP Cloud bundle that carries CloudSOC, from Audit to DLP for Gmail
— Vendor
5 apps named
for API and inline coverage: Office 365, Google Workspace, Box, Salesforce, Slack
— Vendor
3 data classes
classified automatically as regulated: PII, PCI and PHI
— Vendor
2026
KuppingerCole Zero Trust Platforms Overall Leader, for Symantec SSE, which includes CASB
— Analyst
3 Indian cities
with Broadcom offices: Bangalore, Hyderabad and Pune
— Vendor

What your Symantec CloudSOC CASB rollout looks like

Week 1Model

Feed Audit your existing logs

Upload proxy and firewall logs to CloudSOC Audit and rank the cloud services found by Business Readiness Rating.

Week 2Decide

Pick the apps that matter

Choose the sanctioned apps to govern first, often Office 365 or Google Workspace, and ask Broadcom where tenant data sits.

Week 3Pilot

Connect one Securlet

Link one tenant by API, block nothing, and read what is already shared outside the company before writing policy.

Month 2Prove

Bring DLP and go inline

Import your Symantec DLP policies as profiles, then switch on Gatelets for a pilot group and watch the false positives.

Month 3Commit

Widen to BYOD and users

Add Mirror Gateway for unmanaged devices, tune ThreatScore-driven actions, and roll the policy out to every user.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

3.9
38+ reviews*
76% would recommend
Shadow IT discovery4.2
DLP integration4.3
API app coverage3.8
Ease of setup3.4
Value for money3.6
5★
36%
4★
40%
3★
16%
2★
6%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“We fed six months of proxy logs into Audit and found 300-odd file-sharing services nobody had approved. The rating sorted them in a day.”
Information Security Manager
BFSI
Insurance
“Importing our Symantec DLP policies as profiles saved weeks. The same PAN-card rule now fires on OneDrive and on the laptop.”
DLP Lead
Insurance
Pharma
“The Box Securlet showed links shared publicly years ago. Cleaning those up was the first real win of the pilot.”
Cloud Security Engineer
Pharma
IT Services
“Mirror Gateway let contractors on their own laptops use Salesforce without us handing out managed devices.”
IT Head
IT Services
Telecom
“ThreatScore flagged an account downloading far more than usual at night; it turned out to be stolen credentials.”
SOC Analyst
Telecom
Manufacturing
“Capable, but the console is busy and we had to ask three times which region our tenant data sits in.”
Head of Infrastructure
Manufacturing
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the cloud access security broker market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag CASB Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Symantec CloudSOC CASBThis page

Quoted inside Symantec DLP Cloud through partners.

Grid 02 · The architecture

Reach × Data Depth

The grid nobody publishes — how many routes a CASB has into cloud apps, unmanaged devices included, vs how much it does with the data once there.

Deep data, fewer routesBroad and deep brokersLight SaaS add-onsMany routes, lighter data
Symantec CloudSOC CASBThis page

API, inline gateway, Mirror Gateway; Symantec DLP profiles.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Symantec CloudSOC CASB vs the CASB field

Against Netskope CASB, Skyhigh CASB, Microsoft Defender for Cloud Apps, Forcepoint CASB and Zscaler CASB — on modes, unmanaged devices, app coverage, price, DLP and India.

DimensionSymantec CloudSOC CASBNetskope CASBSkyhigh CASBMicrosoft Defender for Cloud AppsForcepoint CASBZscaler CASB
What it isSymantec-branded CASBNetskope One moduleStandalone or in SSEDefender XDR’s CASBCASB on Forcepoint DLPPart of Zscaler SSE
Deployment modesAPI + inline gatewayAPI, forward, reverseAPI, forward, reverseAPI + reverse proxyAPI, reverse, forwardInline + API
Unmanaged devicesMirror GatewayReverse proxy listedReverse proxyEntra-gated proxyReverse proxyIsolation, not proxy
App risk catalogue45,000+ apps (claim)80,000+ apps40,000+ services33,000+ apps800,000+ (claim)Score, no total
API connectorsFive apps namedNo total given40 apps27 connectorsSuites, no countNo total given
Pricing modelInside DLP CloudPer user, bundledPer user, two SKUsPer user, in a suitePer user, quotedPer user, by edition
Published entry priceQuote only~$15+ bundledNot published$12/user/month (suite)Not published~$6–12 reported
Included vs add-onBundle carries DLPBundle decidesEDM/IDM, OCR extraPurview labels built inAll modes in oneEdition decides
Data protectionSymantec DLP profilesAI/ML DLP, coachingEDM, IDM, OCRPurview-driven1,700+ classifiersEDM, IDM, OCR
Threats and UEBAThreatScore UEBAUEBA, sandboxingUEBA, sandbox, ATT&CKUEBA in Defender XDRRemediation onlySandbox, at-rest scans
Posture managementCSPM for IaaSSSPM, GenAI riskSSPM, 1,900+ AI appsSSPM + app governanceCompliance mappingSSPM included
India data regionNot documented8 Indian data centresMumbai PoPs, India logsUS or nearest regionMumbai + 5 edge cities4 Indian node cities
Lock-in and exitTied to Symantec DLPPlatform pullData gone in ~30 daysMicrosoft-centredDLP couplingTied to the ZIA path
Best fitSymantec DLP estatesDeep multimode CASBSkyhigh web estatesMicrosoft 365 estatesForcepoint DLP usersZscaler ZIA estates
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Symantec CloudSOC CASB if…

  • ✓You already run Symantec DLP and want its policies applied to Office 365, Box, Salesforce and Slack without rewriting them
  • ✓You want shadow IT measured from the proxy and firewall logs you already keep before you change any traffic routing
  • ✓Contractors and staff use personal devices for sanctioned apps, and Mirror Gateway’s unmanaged-device controls fit that

Compare alternatives if…

  • ✓You need data stored in India on record — Netskope, Skyhigh, Forcepoint and Zscaler document Indian facilities
  • ✓You want a price before a sales call — Microsoft lists the Defender Suite at $12 per user a month
  • ✓You want SaaS posture checks named on the product page — Netskope, Skyhigh, Microsoft and Zscaler list SSPM

Do not expect…

  • ✓A CloudSOC price list, or a way to buy it outside a partner quote
  • ✓A documented Indian data region for CloudSOC tenants
  • ✓A top-quadrant Gartner placement — Broadcom sat with the Niche Players in the 2025 SSE MQ

Symantec CloudSOC CASB is one of 44 secure web & DNS products TechBag carries. The Secure Web & DNS guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does unwatched cloud-app use cost you?

Drag the sliders (staff using sanctioned cloud apps; security analyst-hour cost). Estimates model analyst time per user each year spent tracing unapproved apps, checking files shared outside the company and writing cloud-app DLP rules, at an assumed 1.5 hours per user a year, with 70% of it removed by log-based Audit, API scanning and reused DLP policy. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual cloud-app review cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Broadcom publishes no CloudSOC price, and its product pages point to a partner or a contact form. CloudSOC is normally bought inside Symantec DLP Cloud, which bundles CloudSOC Audit, CASB for SaaS, CASB for IaaS, the CloudSOC Gateway, the DLP Cloud Detection Service, DLP Cloud Detection for WSS and DLP for Office 365 email and Gmail. The licence unit is not published. Westcon-Comstor distributes Symantec in India. TechBag maps your apps first, then quotes in INR with GST.

Symantec DLP Cloud (with CloudSOC)

Best for governing data in SaaS and IaaS

  • CloudSOC Audit, CASB for SaaS and IaaS
  • CloudSOC Gateway for inline control
  • Quote only, through partners

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Symantec SSE with CASB add-on

Best for estates already on Cloud SWG

  • Cloud SWG includes app visibility and control
  • Granular CASB controls are an add-on
  • Quote only; no public list price

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
App inventory

Which proxy and firewall logs can feed Audit, and how many months of them do you still keep?

2
Sanctioned apps

Is each app you must govern — Office 365, Google Workspace, Box, Salesforce, Slack — covered by a Securlet?

3
Inline route

How will traffic reach the CloudSOC Gateway for Gatelets, and does Cloud SWG already carry your web traffic?

4
Unmanaged devices

Do contractors or staff use personal devices for sanctioned apps? If so, scope Mirror Gateway in the pilot.

5
DLP reuse

Do you run Symantec DLP today? Its policies import as CloudSOC profiles; without it, budget time to write them.

6
Data region

Which region will hold your tenant’s logs and incidents? No Indian region is documented, so get it in writing.

7
Bundle scope

Which DLP Cloud parts does the quote include: Audit, CASB for SaaS, CASB for IaaS, Gateway, cloud detection?

8
Licence

What is the licence unit and term? Ask for the quote itemised in INR with GST, with renewal terms stated.

FAQ

Questions buyers ask

It is Broadcom’s cloud access security broker under the Symantec brand. Audit finds shadow IT in proxy and firewall logs, Securlets scan sanctioned apps by API, Gatelets control cloud traffic inline through the CloudSOC Gateway, and Mirror Gateway extends those controls to unmanaged devices.

Ready to evaluate Symantec CloudSOC CASB?

Run your existing proxy logs through an app inventory first, or let a TechBag advisor scope the DLP Cloud parts you need, press Broadcom on the tenant data region and get the quote itemised in INR.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.