Netskope is recognized as a Leader again in the Gartner® Magic Quadrant™ for SASE Platforms. Get the Report
Works Human Intelligence (WHI) is the developer and provider of the “COMPANY” series, a comprehensive HR system that covers a wide range of human capital management operations, including personnel management, payroll, attendance, and talent management. Aiming to create a society where people enjoy working, WHI positions itself as a leading company in the HR tech industry. For WHI, protecting sensitive data—including HR data entrusted by client companies—is a top priority. To achieve a Zero Trust security model, WHI adopted Netskope as their SASE (Secure Access Service Edge) / SSE (Security Service Edge) solution.
WHI’s “COMPANY” system, delivered via the cloud, holds the top market share in the HR and payroll domain within the SaaS-based ERP market in Japan (2022 ERP Market Report by ITR). As of the end of 2024, the HR data managed by COMPANY covers approximately 5.4 million licensed users. “For us, data security and privacy protection are extremely important,” says Junichi Hasegawa of the Data & IT Div. Corporate Security Dept. / WHI-CSIRT
Since its inception, WHI has proactively utilized cloud services such as Google Drive and Slack while balancing convenience and security. However, they also needed to address unintentional data leaks, such as accidental use of unauthorized cloud services or attaching sensitive data to Slack messages from personal smartphones.
To mitigate these risks, WHI decided to shift from a traditional perimeter-based security model to a Zero Trust approach.
We evaluated several products and services, prioritizing stable service delivery and robust features.
Between 2021 and early 2022, WHI selected Netskope to implement Zero Trust security. “We evaluated several products and services, prioritizing stable service delivery and robust features,” explains Hasegawa.
Netskope had been recognized in the Gartner® Magic Quadrant™ for SSE in 2022 as a Leader based on completeness of vision and ability to execute. Its ability to monitor not just selected cloud services but the entire cloud environment proved to be a key advantage in WHI’s decision.
During deployment, WHI focused on preventing unintentional data exposure caused by human error or productivity-driven shortcuts. They made effective use of the “Exception” feature to exclude specific activities from monitoring, ensuring operations—such as development or accounting—weren’t disrupted. “We identified exceptions in advance and rolled out deployment incrementally from a limited number of devices to avoid major issues,” says Hasegawa. They also ensured legal and ethical compliance by obtaining employee consent in advance and establishing strict internal policies for Netskope monitoring.
This contributes to reducing the variance in security assessments of cloud services and the amount of work required for assessment. For cloud services whose safety has not been confirmed, we can disapprove their use based on Netskope’s risk assessment, allowing us to properly manage them.
Hasegawa outlines three key expectations for leveraging Netskope. The first is “visualization and control of cloud usage.” Netskope enables visibility not only into URLs, but also into who performed what actions and when—allowing the organization to proactively block high-risk activities such as uploading sensitive data to generative AI platforms. “One of the key strengths of CASB within SASE is that it allows us to monitor uploads to Google Drive from personal accounts,” says Hasegawa.
The second expectation is “monitoring and controlling authorized cloud services.” For officially contracted services such as Slack, WHI utilizes API integrations to enforce granular control and monitoring. “For example, by integrating with Gmail via API, we can monitor whether sensitive data is being sent from company email addresses to personal ones,” explains Hasegawa.
The third is “enhancing risk management for cloud services.” When an application to use a service is submitted, the service is evaluated using Netskope’s cloud service risk assessment (Cloud Confidence Index: CCI). “This contributes to reducing the variance in security assessments of cloud services and the amount of work required for assessment. For cloud services whose safety has not been confirmed, we can disapprove their use based on Netskope’s risk assessment, allowing us to properly manage them,” says Hasegawa.
Thanks to these measures, WHI has been able to securely adopt tools like Slack, GitHub, and generative AI for business purposes. Netskope plays a critical role as an enabler—not a blocker—by reducing risks and ensuring secure, confident cloud usage.
We’re reviewing these cases and aiming to expand our monitoring coverage to reduce risks further.
WHI is now entering a new phase focused on operational optimization. While the Exception feature has helped ensure a smooth rollout, there have been cases where uploads to some cloud services went undetected due to broad exception rules. “We’re reviewing these cases and aiming to expand our monitoring coverage to reduce risks further,” says Hasegawa.
Regarding the SOC (Security Operation Center) services provided by Tokyo Electron Devices (TED), the company’s implementation partner, Hasegawa said, “There are limits to what we can do to operate and monitor Netskope all on our own, so TED’s services have been extremely helpful.” He concluded by saying, “TED has already implemented filtering of false positives, and we look forward to further improvements in operations as we begin to hold regular Netskope meetings.”
By balancing safety and convenience, WHI continues to provide an environment where employees can truly enjoy working—paving the way toward achieving their vision.
* Source : Gartner®️, Magic Quadrant™️ for Security Service Edge, Charlie Winckless, Thomas Lintemuth, Dale Koeppen, Charanpal Bhogal, 20 May 2025
Gartner®️, Magic Quadrant™️ for Security Service Edge, John Watts et al., 30 March 2022 (This research has already archived.)
(Netskopeは2022年から現在まで、連続してリーダーの1社として評価されています)
GARTNERは、Gartner, Inc.および/または米国とその他の国におけるその関連会社の商標およびサービスマークであり、MAGIC QUADRANTは、Gartner, Inc.および/またはその関連会社の登録商標であり、本書では許可を得て使用しています。All rights reserved. Gartnerは、Gartnerリサーチの発行物に掲載された特定のベンダー、製品またはサービスを推奨するものではありません。また、最高のレーティング又はその他の評価を得たベンダーのみを選択するようにテクノロジーユーザーに助言するものではありません。Gartnerリサーチの発行物は、Gartnerリサーチの見解を表したものであり、事実を表現したものではありません。Gartnerは、明示または黙示を問わず、本リサーチの商品性や特定目的への適合性を含め、一切の責任を負うものではありません。