How can Netskope help in protecting data, assets and users from a SASE perspective?

Author: Paul Graham
Release Date: 24/11/2021

Key factors in discussing SASE as a security concept is that of everywhere and anywhere as examples, your data could now be everywhere and your users could be anywhere. Gone are the days when users, resources and data existed within the four walls of an on premise infrastructure and Netskope’s SASE week highlighted how Netskope are embracing SASE as a fundamental of their overall solution and offerings.

In 2021, more than 53% of web gateway traffic was classed as being related to cloud applications and services, 85% of breaches involved the human element, phishing was present in 36% of data breaches and comprises occurred more in cloud based technologies than of those that were on premise.

These are trends that are likely to increase and not just because of the pandemic, but due to the changing methods of working globally. On average, 2400 cloud services are used by large enterprises, for web traffic as a whole – 80% of this is now driven by cloud apps & services, 33% of workers are now working remotely, of all cloud apps used by an organisation 2% are IT led wherein IT staff have full admin control leaving 98% that are not IT led giving IT staff no administrative control of them. It is also easier from an attacker’s point of view to access a cloud app via phishing than it would be to bypass on premise security tools.

Coupled with all of the above, consideration has to be given to the fact that there is a growing number of people, particularly younger people, who have been raised on the Internet in an app based world, this is known as having a digital native workforce.

So how can Netskope help?

Starting with the cloud based Secure Web Gateway, user’s web traffic is assessed via a cloud tenant hence it does not matter if a user is on premise or working remotely. There is also no need to “hairpin” a user’s traffic back into the on premise network in order for it to be inspected. Typical category based filtering and malware protection comes as standard with the SWG component to allow for easily defined blanket block or allow policies as well as the means to block threats at source.

Add to this the CASB feature that provides granular control of Cloud Applications giving an Administrator experience to apps that can also be controlled centrally. Netskope understands the new language of the internet hence it can block individual activities being performed on Cloud Apps as opposed to outright blocking resources based on their domain. This is key for collaboration with customers and suppliers i.e. say we are a Google house and use Google Drive, yet our customer uses Office 365 – instead of blocking all of Office 365 since it is not an in house sanctioned application, we can control the individual activities that our users can perform on this particular app such as blocking uploads but allowing downloads.

Netskope is also fully content aware hence when it comes to uploading and downloading files to or from cloud applications via it’s real time Data Loss Prevention feature. With this, we could allow uploading and downloading of data to a 3rd party cloud application however Netskope can be configured to block sensitive data from being shared.

Both the SWG and CASB elements also offer full visibility of user activities. Typical SWGs would tend to only show a user visited or attempted to visit a particular domain but with Netskope full visibility encompasses the user, their activities on the page or in the the app, the username used, the file transferred, etc.

Within SASE is the concept of Zero Trust Network Access and Netskope answers this via a variety of methods.

The first is via their Private Access feature which at its heart is essentially an always on VPN. As an example, there is a web app within the company perimeter that remote users need to access. At present they use a typical 3rd party VPN to connect to the company network and then they load the private web app. With Netskope’s Private Access, they would be able to open that private app securely from anywhere as their traffic would be getting directed to a Netskope Cloud Tenant, the Cloud Tenant is securely connected to an on premise Publisher and the Publisher can connect to the private app. It should be noted that private apps don’t have to be solely web based applications and protocols such as RDP or SSH are supported.

As with the granular activity controls that can be applied to policies within Netskope, further granular controls can also be applied such as adaptive controls based on the user, team, browser used, device being trusted, etc. which when configured correctly allows for a full zero trust experience that is also highly customizable based on a business’ needs.

Netskope’s Cloud Firewall, which is a new feature, can also provide further protection especially in relation to blocking sensitive data exfiltration. As an example, say we have set up all our SWG and CASB controls to stop data exfiltration in relation to web or cloud traffic, what stops a user RDPing or SSHing to a remote resource to then transfer the data to this? Netskope’s Cloud Firewall would allow for the further blocking of protocols like RDP or SSH to prevent this.

In relation to SASE as a whole, the end state benefits are listed below, all of which can be provided via use of Netskope as a solution:

  • Consistent Policy Enforcement – regardless of location & covering all types of access
  • Ease of Administration via a consolidated policy control plane
  • Sensitive Data Visibility and Control coupled with Threat Detection
  • Consistent coverage for all types of entities including users and devices at branch office, campus and edge locations
  • Single pass inspection of encrypted traffic and content at line speed
  • Highly available, low latency services with contractually enforced SLAs
  • Zero Trust Networking Security Posture
  • Transparent and simplified end-user experience
  • Unified IT responsibility for access engineering

And the key questions to ask yourself when it comes to SASE are:

  • Do you have the visibility into cloud, web, SaaS, IaaS and users that you need?
  • Can you secure the work-from-anywhere workforce without impacting on performance?
  • Can you secure your data in the cloud and prevent unwanted data theft & movement?

Want to learn more about SASE?

Book an introductory call with us and get started with Netskope & SASE.

Scroll to Top