Customer story · Technology & Software
Managed IT Provider Eliminates Appliance Sprawl, Improves Security Capabilities with Cato Networks
WorldwideIT, a managed IT provider serving businesses, nonprofits and government, adopted Cato Cloud Firewall as a Service to give its customers SSL inspection and cloud-based security without upgrading on-premises firewall appliances.
Published by Cato Networks
About WorldwideIT (WWIT)
WorldwideIT (WWIT) has delivered managed IT solutions to businesses, nonprofits and government for more than 14 years. The provider builds customized solutions to meet the unique needs of each customer and proactively manages the changing demands of modern IT. Its security architecture relied on deploying and managing a firewall at each customer premises, which WWIT monitored to ensure the necessary performance and security capabilities. Most of its customers operate multiple offices.
The challenge
WWIT's security model placed a managed firewall appliance at every customer site. That worked until customers began asking for advanced security services such as SSL traffic inspection. The appliances did not have the capacity to inspect all the necessary traffic; the capability was available with additional licensing, but the hardware could not carry the load, and expensive upgrades would have been needed at each premises.
The provider went to market, researched many vendors and tested a smaller pool of them. Its second choice was a leading Secure Web Gateway (SWG) provider whose product was really a web filtering solution with Data Loss Prevention (DLP) and other features built in. Because it lacked full firewall capabilities, WWIT could not have used it to replace the customer's firewall appliance, which would have meant higher costs and more management overhead.
WWIT's customers were particularly concerned with web-based threats, especially newer variants of ransomware and crypto-malware that arrive as an email link to a web-based payload. Small offices lacked the resources to purchase a robust network security stack, and customers making acquisitions needed new offices brought online and connected quickly without a lot of upfront cost.
The flexibility we got with Cato Cloud, and particularly with the SSL inspection, meant we didn't need to upgrade any hardware on-premise to inspect all necessary traffic to keep customers safe.
The solution
WWIT selected the Cato Cloud and adopted Cato Networks' Firewall as a Service (FWaaS). Cato's scalable SSL inspection was the initial draw: with inspection performed in the cloud, WWIT did not need to upgrade any on-premises hardware to inspect the traffic required to keep customers safe. Looking at the wider platform, WWIT's leadership saw a more complete vision than vendors that were primarily web gateways, and judged Cato's easy deployment and ability to roll out rapidly to customers as the tipping point.
Customers connect to the service either through Cato Sockets, Cato's hardware endpoints, or by sending traffic through their existing firewalls. Where a customer's firewall is still new, WWIT leaves it in place and uses Cato to add a further layer of filtering and the capacity to perform SSL inspection, with the option to replace the appliance as it ages. For multi-office customers, WWIT uses Cato to unify policies and protection across all sites, and as a partner it can manage all of its customers from one view.
Before committing, WWIT reviewed the Cato Cloud architecture and was impressed by the degree of redundancy built into the network, an important check for any organization relying on a single platform to handle all of its traffic and security services. WWIT also found Cato to be channel-focused and flexible, open to ideas from partners and able to incorporate them into the platform quickly.
The results
- SSL inspection of all necessary customer traffic without upgrading any on-premises firewall hardware
- Active traffic scanning stops web-based ransomware and crypto-malware attacks that reach customers as email links
- Small offices gain affordable protection with policies and robustness previously available only in high-end appliances
- Unified security policies and protection across multi-office customers, managed from a single view
- Acquired sites brought online with connectivity and security quickly, without building a full infrastructure stack at each location
Get the full case study
Download the original document as published by Cato Networks (PDF, 930.1 KB).
Your story could be next
Want results like these?
Every result on this page started with one conversation — let's have yours.


