Select a tab
What's New
- 2026-08-03 | Agentic Threat Prevention launched - Cato introduced a new security service using AI agents to identify and block emerging agentic attack behavior, alongside expanded AI Security controls for users and local agents.
- 2026-07-31 | Leader in Gartner Magic Quadrant for SASE Platforms - Cato announced it was named a Leader for the third consecutive year, reinforcing the platform story WWT sellers can use in SASE modernization conversations.
- 2026-07-23 | CrowdStrike integration expanded - Cato and CrowdStrike announced integrations that combine network and endpoint telemetry to streamline investigation, strengthen detection fidelity, and accelerate response.
Cato Networks delivers a cloud-native Secure Access Service Edge (SASE) platform that converges networking, security and access into a single global service. The platform connects sites, cloud environments, remote users, and applications while applying a common policy and shared security context. Core capabilities include SD-WAN, Firewall-as-a-Service, Secure Web Gateway, IPS and malware prevention, DNS security, CASB, DLP, Zero Trust Network Access, digital experience monitoring, XDR/XOps, and AI Security.
The core differentiation is architectural convergence rather than a portfolio of separately built point products. Cato uses a purpose-built private global backbone and a single cloud-native security engine to inspect traffic and enforce policy consistently. The 2026 modular adoption model also allows customers to start with AI Security, SD-WAN, SSE, or Universal ZTNA and expand on the same underlying platform, as needs arise. This gives WWT sellers multiple landing motions while preserving a broader consolidation and upsell path.
For WWT, the partnership aligns naturally to cyber, networking, cloud, AI Security, and AI-Native Engineering (AINE) motions. WWT can add value through architecture consulting, AI security Shadow AI assessments, migration planning, deployment, managed services, proof-of-value design, and ATC/AI Proving Ground validation. The recent $3M ACV S&P Global deal, which Cato Networks fed to WWT, demonstrates how executive alignment, persona-based discovery, and WWT customer relationships can turn an AI Security initiative into a platform opportunity.
AI model / capability types: Machine learning is used across Cato security analytics and threat detection; generative AI/LLM and agentic AI are central to Cato AI Security use cases for governing employee AI use, protecting homegrown AI applications, controlling autonomous agents, and defending against AI-enabled attacks. Cato also uses AI agents in Agentic Threat Prevention. Cato Neural Edge adds GPU-powered infrastructure for real-time AI-driven inspection and enforcement. Deep-learning specifics should be described only where a Cato product source explicitly identifies them.
Cato AI Security: https://www.catonetworks.com/solutions/ai-security/
Cato Platform: https://www.catonetworks.com/platform/
WWT AI Security: https://www.wwt.com/topic/ai-security/overview
Message Overview
In the Summer of CY2026, Cato spent a full day with WWT cybersecurity, SASE, SSE and AI Sec leadership to align around a go-to-market execution plan. It includes national WWT security-seller enablement, executive alignment, and a multi-session SASE deep-dive motion.
One of our first joint wins was a $2.9M ACV AI Security opportunity at a WWT financial services customer. This company has approximately 45,000 employees across 70 offices in 35 countries and gave WWT a great springboard for discussing the value of Cato Networks with additional prospects.
Cato Networks values protection of partner margins. Opportunities you bring us typically result in a 30 to 40 percent partner discount (on top of any non-standard pricing requests), with most partners retaining 20-25% gross margin. Cato sells exclusively through the channel – there is a partner on every single deal we do, whether that is a referral partner, reselling partner, systems integrator, or managed service provider. We offer deal registration protection, incumbency protection, transparent discounting and significant recurring revenue opportunities. Registered opportunities should be submitted early, so WWT has clear protection, visibility, and the best chance to capture applicable strategic partner incentives and attach WWT-led services.
| Name | Title / Role | Phone | |
| Karl Soderlund | Global Channel Chief, Cato Networks | Karl.soderlund@catonetworks.com | +1-617-595-8741 |
| Addie Finch | Vice President, Americas Channel | Addie.finch@catonetworks.com | +1-716-239-8734 |
| Tristan Elder | Vice President, EMEA Channel | Tristan.elder@catonetworks.com | +447469192388 |
| Chris Hendey | Channel Manager, WWT Lead | Chris.Hendey@catonetworks.com | 408-910-5999 |
| All US Channel Managers | Regional Channel Manager Email Alias | rcam@catonetworks.com |
Executive Relationship Map:
Karl Soderlund <-> Chris Konrad
Addie Finch <-> Chris Konrad
Karl Soderlund <-> Ashish Upadhyay
Typical margins expected for a registered deal
- 30% off at Starter Level (current)
- 40% off at Advanced Level
GM% historical average
- Most partners retain 20-25% or higher
How to register a deal (step-by-step process)
- Go to www.catonetworks.com
- Hover over the Partners tab at top of page
- Click on Partner Portal under Quick Links
- Either sign in, or if this is your first visit, click the Sign Up button
- Once you've clicked Sign Up, send an email to rcam@catonetworks.com and ask that someone approve your submission
- Login and click to register a deal
How to access the partner portal (URL + login instructions)
https://partners.catonetworks.com/#/page/login
- Either sign in, or if this is your first visit, click the Sign Up button
- Once you've clicked Sign Up, send an email to rcam@catonetworks.com and ask that someone approve your submission.
Registration types:
- Resale / MSP / Referral / Incumbent Reseller, MSP, Referral
- Incumbent protection is automatic and deal reg is not required on renewals
Deal registration approval SLA
- We aim to either approve or reach out to discuss deal registrations within 48 hours.
- If you have a question or need to check status, feel free to email chris.hendey@catonetworks.com or rcam@catonetworks.com to reach the channel management team who can assist.
Incumbent protection policy
- We honor incumbency based on the last partner to sell new business to the customer in each product category.
AI Security Solutions:
There are hundreds of solutions on the market but oftentimes they address one piece of the AISecurity puzzle. Cato wins when customers want to avoid assembling separate tools for AI usage, AI applications, and autonomous agents, or when vendor longevity and consolidation risk make them uncomfortable placing a multi-year security bet on a fast-moving field of narrowly focused, early-stage vendors.
Cato's differentiator is the platform approach: one AI-native solution, one policy framework, and one control point for all three AI use cases - the AI employees use, the AI applications teams build, and the agents operating across the environment - with AI activity connected to the broader network and security context.
SASE:
Zscaler - Cato wins against Zscaler when customers want one operating model for networking and security rather than separate service domains, predictable application performance, or a mature path from SSE to full SASE. The differentiators that matter are Cato's single policy model, single data lake, single operations plane, private backbone, and integrated SD-WAN;
Netskope - Cato wins against Netskope when customers need to expand beyond SSE and DLP into branch networking, private applications, east-west traffic, and full SASE without re-architecting later. Cato's private backbone, mature SD-WAN, consistent enforcement across all traffic paths, and one architecture that can expand use case by use case without integration debt are the key differentiators.
Palo Alto Networks - Cato wins against Palo Alto when the buying priority is operational simplification, faster rollout, and avoiding a growing portfolio of modules, consoles, policy domains, and integration work. Customers that value one cloud-native architecture, one policy model, one data lake, and one operation plane often see Cato as the cleaner path to network, security, ZTNA, and AI convergence.
Fortinet - Cato wins against Fortinet when customers want to reduce appliance refresh, capacity planning, and emergency patch cycles, or when rapid branch rollout and cloud-delivered operations matter more than preserving a firewall-centric architecture. Cato differentiates with cloud-native enforcement, no customer-managed appliance lifecycle for core SASE, and unified policy, telemetry, and operations.
Cisco - Cato wins against Cisco when customers want faster SASE deployment, simpler day-to-day management, predictable global performance, and less licensing and hardware complexity. Cato's unified management, private backbone, zero-touch provisioning, and converged security stack are especially strong when customers are replacing MPLS/VPNs or multiple point products; internal Cisco win examples cite eliminating backhauling, consolidating point products, and easier management as win drivers.
Cloudflare - Cato wins against Cloudflare when customers want enterprise SASE with managed SD-WAN and last-mile optimization, built-in advanced security, and an operating model that does not require customer engineering to extend or maintain security controls. Cato differentiates with integrated edge SD-WAN, a converged security stack, and a managed platform where Cato - rather than the customer's developers - owns enforcement, updates, and platform accountability.
- For a full list of Cato Networks Integration partners, please visit: https://www.catonetworks.com/integrations/
- Cato Networks and Crowdstrike also benefit from a mutual GTM partnership with each side's sellers being compensated for bringing the other vendor into an opportunity.
Cato Networks is in the early stages of moving into the ATC. We continue to work with the SASE/SSE team to determine which use cases the ATC environment will be built around. Stay tuned!
| Focus Area | How Cato Aligns |
|---|---|
| Customer Experience | Improves application availability and performance through global connectivity, SD-WAN, traffic optimization, and consistent security; relevant to retail, branch, contact-center, and digital-experience use cases. |
| Workforce Experience | Universal ZTNA, secure web access, Enterprise Browser, browser extension, and remote-user connectivity support secure work from managed and unmanaged endpoints. |
| Connected Workforce | Connects branches, campuses, remote users, and cloud resources through one SASE platform and global backbone, reducing dependence on fragmented WAN/VPN architectures. |
| Cloud Platforms | Supports AWS, Azure, GCP, vSockets, cloud datacenter integration, identity integrations, and event/data integrations for hybrid and multi-cloud environments. |
| Data Strategy | CASB, DLP, AI governance, prompt/data controls, and shared security context help protect sensitive information as data moves through SaaS, cloud, and AI workflows. |
| Automate Everything | Zero-touch deployment, APIs, XOps, AI/ML-driven detection, automated policy capabilities, and Agentic Threat Prevention support operations at machine speed. |
| Cyber Security | Converges FWaaS, SWG, IPS, malware prevention, DNS security, CASB, DLP, ZTNA, XDR/XOps, AI Security, and agentic threat defense in one cloud-native platform. |
- S&P Global - $2.9M ACV - Cato AI Security / AI Firewall for approximately 45,000 employees across 70 offices in 35 countries. The customer needed unified AI visibility, governance, and control across AI usage spanning AWS, Azure, and GCP. WWT relationships, executive alignment, persona-based discovery, and a strong proof of value helped Cato win; the solution displaced Zscaler and beat Noma/other AI-security startups. Outcome: centralized AI governance, stronger security posture, and a safer path for future AI initiatives.
Gartner – 2026 Magic Quadrant™ for SASE Platforms
Cato Networks was named a Leader in the 2026 Gartner® Magic Quadrant™ for SASE Platforms, marking the third consecutive year Cato has been positioned in the Leaders Quadrant.
GigaOm – 2026 Radar for Secure Access Service Edge (SASE)
Cato Networks was named a Leader and Outperformer in the 2026 GigaOm Radar for SASE, marking the third consecutive year Cato has earned both distinctions. Cato was positioned closest to the center of the Radar among all evaluated vendors and ranked highest on Emerging Features and Business Criteria.
GigaOm – 2026 Radar for Security Service Edge (SSE)
Cato Networks was named a Leader and Outperformer in the 2026 GigaOm Radar for Security Service Edge (SSE). The assessment highlighted Cato's strengths across areas including agentless secure access, multivector threat protection, and next-generation deep packet inspection.
GigaOm – 2026 Radar for SD-WAN
Cato Networks was named a Leader and Outperformer in the GigaOm Radar for SD-WAN, giving Cato Leader and Outperformer recognition across all three core GigaOm categories: SASE, SSE, and SD-WAN.
Forrester Consulting – 2026 Total Economic Impact™ of Cato SASE Platform
A Forrester Consulting Total Economic Impact™ study commissioned by Cato Networks found that a composite organization modeled from Cato customers could achieve 235% ROI, $18.9 million in total benefits, $13.2 million in net present value, and payback in less than six months with the Cato SASE Platform.
- Financial Services - Strong fit for globally distributed institutions that need consistent policy, zero-trust access, AI governance, and cloud security. The WWT + Cato S&P Global win is the anchor proof point for AI Security in a complex financial/data-services environment.
- Healthcare & Life Sciences - Use Cato to consolidate network and security controls across clinics, remote workers, SaaS/cloud applications, and third parties while improving visibility and protecting sensitive data. Cato customer references include multi-location healthcare organizations and AI Security use cases involving patient data.
- Manufacturing - Cato is well suited to multi-site manufacturers modernizing MPLS, connecting plants and clouds, improving IoT/OT visibility, and reducing security appliance sprawl. Cato performs especially well in challenging China environments with multiple Points of Presence inside mainland China and a Hong Kong gateway for any traffic that does need to leave China.
- Retail / Distributed Enterprise - Retailers and other branch-heavy organizations can use Cato to improve site connectivity, cloud/SaaS performance, secure internet access, and operational consistency across hundreds of locations.
- Public Sector / SLED / Federal - Zero Trust, network modernization, secure remote access, and cloud connectivity are relevant to public-sector customers. Cato's FedRAMP High authorization process is underway and expected in 2027.
- Cato Readiness & Migration Assessment - Inventory sites, circuits, remote users, cloud connectivity, security policies, and operational dependencies; produce migration waves, risk controls, and success criteria.
- SSE / SASE Market Scan and Architecture Workshop - Assess current-state network/security architecture, business drivers, incumbent stack, and target operating model; map where Cato is the best fit and define a phased adoption plan.
- Implementation & Migration Services - Design and deploy Cato sites, users, cloud connectivity, routing, policies, integrations, and cutover plans while minimizing business disruption.
- Security Policy / Zero Trust Optimization - Rationalize firewall, SWG, CASB/DLP, ZTNA, and segmentation policies; reduce policy sprawl and align controls to business risk.
- Shadow AI Assessments – Leverage Cato Network's AI Security solution to demonstrate to clients where Shadow AI exists and why a project to defend against such instances is necessary
- AI Security Governance & Proof-of-Value - Define approved AI-use policy, protect homegrown AI applications/agents, and validate controls through a structured POV and future ATC/AI Proving Ground lab.
- Managed SASE / Operational Services - Provide ongoing monitoring, policy operations, lifecycle management, incident coordination, and optimization around the Cato environment where WWT has the appropriate service capability.
Our sweet spot for a wholistic SASE project tends to be upper mid-market and lower enterprise customers, where lean teams cannot keep up with the complexity of dozens of disparate point solutions.
Our AISecurity solution scales from mid-market to enterprise, as well, but the best fits tend to be mature AI-oriented companies who are developing their own applications or connecting agents to corporate resources and applications.
Cato Neworks Majors Sellers tend to focus on accounts 25,000 seats and greater and lead with AI Security discussions whereas enterprise and regional sales directors focus on eliminating complexity in accounts 1,000 to 10,000 seats, in size, via SASE initiatives.
The important thing to note is that there are many doors into a Cato Networks opportunity and each of these can be sold as a stand-alone starting point: AI Security, SD-WAN/MPLS Replacement, SSE and/or ZTNA.
Once customers purchase one element of the platform, they tend to very quicky look to spin down their existing infrastructure and collapse more features/functionality onto the Cato platform.
Industries / Verticals:
- Financial services and data-intensive enterprises
- Healthcare and life sciences
- Manufacturing and industrial organizations
- Retail / distributed branch enterprises
Business Characteristics
- Multiple point products for SD-WAN, firewalls, SSE, VPN/ZTNA, CASB/DLP, or remote access with high operational overhead.
- MPLS or legacy WAN renewal approaching, or pressure to improve global application performance and resiliency.
- Rapid cloud/SaaS adoption across AWS, Azure, and/or GCP with inconsistent network and security policy.
- Shadow AI, GenAI adoption, AI application development, or agentic-AI initiatives that lack unified governance and runtime controls.
- Need to secure contractors/unmanaged devices while modernizing remote access and Zero Trust.
- M&A, geographic expansion, branch growth, or divestiture activity requiring faster connectivity and policy standardization.
1. "How many separate products or teams are involved today in WAN, internet security, remote access, CASB/DLP, and threat response?"
Reveals toolchain fragmentation, operational cost, and platform-consolidation potential.
2. "When your MPLS, SD-WAN, firewall, SSE, or VPN contracts renew, which parts of the architecture are you willing to change?"
Identifies timing, incumbent lock-in, and the best Cato landing motion.
3. "How are you governing employee use of ChatGPT, Claude, Copilot, Gemini, and other generative AI tools today?"
Surfaces Shadow AI, data leakage, policy, and AI-governance needs.
4. "Are your development teams building AI applications or agents that need runtime protection against prompt injection, data leakage, or unsafe tool use?"
Qualifies Cato AI Security for applications/agents and an AINE-aligned motion.
5. "How consistently can you apply security policy across branches, remote users, cloud workloads, and unmanaged devices?"
Tests for gaps created by separate network, security, and access stacks.
6. "Where do users experience latency, outages, or inconsistent performance when accessing cloud and SaaS applications globally?"
Reveals network-modernization and global-backbone value.
7. "What compliance or data-sovereignty requirements constrain how traffic, prompts, logs, or sensitive data are inspected and stored?"
Identifies regulatory fit, data-residency requirements, and architecture constraints early.
8. "If we could reduce the number of consoles and vendors, which operating costs or staffing bottlenecks would you most want to eliminate?"
Connects technology consolidation to measurable business and services outcomes.
- Cato AI Security overview - Current AI Security positioning, user/application/agent governance and protection.
- Cato SASE Platform - Platform architecture and converged network/security capabilities.
- Partner Sales Toolkit – (Requires Partner Portal Login, which can be requested at this link, as well) Customer Presentation Deck, Vertical-specific use case decks, competitive resources and more