Netskope named a Leader in the 2022 Gartner® Magic Quadrant™ for Security Service Edge. Get the Report.

  • Platform

    Unrivaled visibility and real-time data and threat protection on the world's largest security private cloud.

  • Products

    Netskope products are built on the Netskope Security Cloud.

Netskope delivers a modern cloud security stack, with unified capabilities for data and threat protection, plus secure private access.

Explore our platform
Birds eye view metropolitan city

Netskope Named a Leader in the 2022 Gartner Magic Quadrant™ for SSE Report

Get the report Go to Products Overview
Netskope gartner mq 2022 sse leader

Make the move to market-leading cloud security services with minimal latency and high reliability.

Learn more
Lighted highway through mountainside switchbacks

Prevent threats that often evade other security solutions using a single-pass SSE framework.

Learn more
Lighting storm over metropolitan area

Zero trust solutions for SSE and SASE deployments

Learn more
Boat driving through open sea

Netskope enables a safe, cloud-smart, and fast journey to adopt cloud services, apps, and public cloud infrastructure.

Learn more
Wind turbines along cliffside
  • Customer Success

    Secure your digital transformation journey and make the most of your cloud, web, and private applications.

  • Customer Support

    Proactive support and engagement to optimize your Netskope environment and accelerate your success.

  • Training and Certification

    Netskope training will help you become a cloud security expert.

Trust Netskope to help you address evolving threats, new risks, technology shifts, organizational and network changes, and new regulatory requirements.

Learn more
Woman smiling with glasses looking out window

We have qualified engineers worldwide, with diverse backgrounds in cloud security, networking, virtualization, content delivery, and software development, ready to give you timely, high-quality technical assistance.

Learn more
Bearded man wearing headset working on computer

Secure your digital transformation journey and make the most of your cloud, web, and private applications with Netskope training.

Learn more
Group of young professionals working
  • Resources

    Learn more about how Netskope can help you secure your journey to the cloud.

  • Blog

    Learn how Netskope enables security and networking transformation through security service edge (SSE).

  • Events & Workshops

    Stay ahead of the latest security trends and connect with your peers.

  • Security Defined

    Everything you need to know in our cybersecurity encyclopedia.

Security Visionaries Podcast

Bonus Episode: The Importance of Security Service Edge (SSE)

Play the podcast
Black man sitting in conference meeting

Read the latest on how Netskope can enable the Zero Trust and SASE journey through security service edge (SSE) capabilities.

Read the blog
Sunrise and cloudy sky

Netskope CSO speaking events

Meet the Netskope CSO team at one of our upcoming events.

Find an event
Netskope CSO Team

What is Security Service Edge?

Explore the security side of SASE, the future of network and protection in the cloud.

Learn more
Four-way roundabout
  • Company

    We help you stay ahead of cloud, data, and network security challenges.

  • Why Netskope

    Cloud transformation and work from anywhere have changed how security needs to work.

  • Leadership

    Our leadership team is fiercely committed to doing everything it takes to make our customers successful.

  • Partners

    We partner with security leaders to help you secure your journey to the cloud.

Netskope enables the future of work.

Find out more
Curvy road through wooded area

Netskope is redefining cloud, data, and network security to help organizations apply Zero Trust principles to protect data.

Learn more
Switchback road atop a cliffside

Thinkers, builders, dreamers, innovators. Together, we deliver cutting-edge cloud security solutions to help our customers protect their data and people.

Meet our team
Group of hikers scaling a snowy mountain

Netskope’s partner-centric go-to-market strategy enables our partners to maximize their growth and profitability while transforming enterprise security.

Learn more
Group of diverse young professionals smiling
Blog CSO, Full Skope, Web Security Next Gen SWG Use Case #1 – Monitor and Assess Risk
Mar 11 2020

Next Gen SWG Use Case #1 – Monitor and Assess Risk

This is a series of articles focused on Next Gen SWG uses cases.  This is the first in a series of six posts.

In my recent blog, I introduced six top use cases that some of the largest enterprises in the world are covering with our Next Gen Secure Web Gateway (NG-SWG). This blog post will focus on double-clicking on the first use case, which is centered around monitoring and assessing risk with cloud app and web usage.

It is fitting that we start with this use case because visibility and risk assessment is often the starting point for any security team. One of the challenges faced today is that legacy secure web gateway products are effectively blind to cloud traffic, or at least what is happening behind the scenes. This is problematic because, for an average organization, approximately 85% of web traffic is now related to the 1,295 apps and cloud services they use. Not having visibility into what is going on with a majority of your traffic puts you in an unfavorable position.

A Next Gen SWG like Netskope provides monitoring and deep, contextual visibility of user activities and behavior when accessing websites and cloud apps. Given that more than 95% of cloud apps are outside the administrative control of IT, risk ratings for tens of thousands of apps are also required.

Here are some of the core capabilities of Netskope’s Next Gen SWG that are important in helping you monitor and understand cloud and web usage.

Simple inline proxy deployment

Netskope offers two primary inline proxy deployment modes. You can configure direct-to-internet IPsec and GRE tunnels for users at a branch or HQ location or use the method preferred by most customers, which is to deploy a lightweight steering client that will protect users anywhere they go on their managed device. Some customers will combine deployment methods.

TLS inspection + Cloud XD to eliminate blind spots and spotlight risky activities 

Netskope’s Next Gen SWG inspects TLS encrypted traffic as the first step. SSL/TLS decryption is performed in the cloud at cloud-scale with no appliances required. Seeing inside TLS alone is not enough, as you need to see beyond URLs, HTTP POST, and HTTP GET to get a clear picture of risky activities taking place within cloud apps. This is where a Next Gen SWG like Netskope has the ability to decode the API/JSON communication taking place within cloud app traffic to provide rich, contextual detail about the user, device, location, app, app instance, activity, and sensitive nature of the content.  Netskope can do this for thousands of cloud apps.

Netskope Cloud Confidence Index (CCI) risk ratings for over 33,000 cloud apps

Unlike traditional cloud app discovery, which relies on parsing logs from a perimeter device, Netskope’s next gen SWG uses the inline proxy to discover cloud apps in use and provide a comprehensive assessment of the enterprise-readiness of the cloud apps. The Netskope research team uses more than 50 different criteria to rate more than 33,000 cloud apps. Ratings of cloud apps are modeled after the Cloud Security Alliance (CSA) cloud controls matrix and includes seven profiles: security, risk, privacy, compliance, vulnerabilities, financial, and legal/audit. In addition to helping assess risk with current cloud usage, the CCI can also be used for vendor assurance as you are researching the security capabilities of a particular SaaS vendor being considered for onboarding.

AI/Ml for website and cloud app categorization

Netskope’s next gen SWG employs advanced AI/ML techniques to streamline and scale the process of categorizing websites and cloud apps that have been identified as part of the inline discovery process. Netskope can dynamically rate new and unknown web page content for 70 categories. This ensures that you have a clear picture on cloud and web usage and have accurate data you can use to enforce usage policies.

Follow data everywhere it goes

One you have Netskope’s Next Gen SWG deployed, all data is tracked as it goes to websites and flows from users to cloud apps. Without creating a policy, Netskope will alert you when it sees data going from one cloud app to another including data going from a corporate to a personal instance. This is very helpful in identifying potential data exfiltration activities and can also help you as you craft your first policies to take action.

Gaining an understanding of your cloud and web usage is important not just for the initial baseline monitoring, but also is important to perform this on an ongoing basis. You can learn more about this use case and watch a demo here. Stay tuned for my next blog post covering use case #2, granular control of unmanaged cloud apps.

author image
About the author
Bob Gilbert heads up the product marketing efforts at Netskope, a market-leading cloud security company. Bob is a prolific speaker and product demonstrator, reaching live audiences in more than 45 countries over the past decade.
Bob Gilbert heads up the product marketing efforts at Netskope, a market-leading cloud security company. Bob is a prolific speaker and product demonstrator, reaching live audiences in more than 45 countries over the past decade.