ネットスコープは、2022年Gartner®社のセキュリティ・サービス・エッジ(SSE)のマジック・クアドラントでリーダーの1社と位置付けられました。レポートを読む

  • セキュリティサービスエッジ製品

    高度なクラウド対応の脅威から保護し、あらゆるベクトルにわたってデータを保護します。

  • Borderless SD-WAN

    すべてのリモートユーザー、デバイス、サイト、クラウドへの安全で高性能なアクセスを自信を持って提供します。

  • プラットフォーム

    世界最大のセキュリティプライベートクラウドでの比類のない可視性とリアルタイムデータおよび脅威保護。

ネットスコープ、2022年Gartner社のセキュリティ・サービス・エッジ(SSE)のマジック・クアドラントでリーダーの1社と位置付けられる

レポートを読む 製品概要に移動
Netskope Gartner マジック・クアドラント 2022 SSEリーダー

Gartner® Quick Answer:NetskopeのInfiot買収はSD-WAN、SASE、SSEプロジェクトにどのような影響を与えますか?

レポートを読む
クイックアンサー:NetskopeによるInfiotの買収は、SD-WAN、SASE、SSEプロジェクトにどのように影響しますか?

Netskope は、データと脅威の保護、および安全なプライベートアクセスを実現するための機能を統合した、最新のクラウドセキュリティスタックを提供します。

プラットフォームを探索する
大都市の俯瞰図
  • 変身

    デジタルトランスフォーメーションを保護します。

  • セキュリティの近代化

    今日と明日のセキュリティの課題に対応します。

  • フレームワーク

    サイバーセキュリティを形作る規制の枠組みを採用する。

  • 業界ソリューション

    Netskopeは、クラウドに安全に移行するためのプロセスを世界最大規模の企業に提供しています。

最小の遅延と高い信頼性を備えた、市場をリードするクラウドセキュリティサービスに移行します。

詳しくはこちら
Lighted highway through mountainside switchbacks

シングルパスSSEフレームワークを使用して、他のセキュリティソリューションを回避することが多い脅威を防止します。

詳しくはこちら
Lighting storm over metropolitan area

SSEおよびSASE展開のためのゼロトラストソリューション

詳しくはこちら
Boat driving through open sea

Netskopeは、クラウドサービス、アプリ、パブリッククラウドインフラストラクチャを採用するための安全でクラウドスマートかつ迅速な旅を可能にします。

詳しくはこちら
Wind turbines along cliffside
  • 導入企業

    Netskopeは、フォーチュン100の25以上を含む世界中の2,000以上の顧客にサービスを提供しています。

  • カスタマーソリューション

    お客様のため、Netskopeでお客様の成功を確実にすべく、あらゆるステップを共に歩んでまいります。

  • トレーニングと認定

    Netskope training will help you become a cloud security expert.

私たちは、お客様が何にでも備えることができるように支援します

お客様を見る
Woman smiling with glasses looking out window

Netskopeの有能で経験豊富なプロフェッショナルサービスチームは、実装を成功させるための規範的なアプローチを提供します。

詳しくはこちら
Netskope Professional Services

Netskopeトレーニングで、デジタルトランスフォーメーションの旅を保護し、クラウド、ウェブ、プライベートアプリケーションを最大限に活用してください。

詳しくはこちら
Group of young professionals working
  • リソース

    クラウドへ安全に移行する上でNetskopeがどのように役立つかについての詳細は、以下をご覧ください。

  • ブログ

    Netskopeがセキュリティサービスエッジ(SSE)を通じてセキュリティとネットワークの変革を可能にする方法を学びましょう。

  • イベント&ワークショップ

    最新のセキュリティトレンドを先取りし、仲間とつながりましょう。

  • 定義されたセキュリティ

    サイバーセキュリティ百科事典で知っておくべきことすべて。

セキュリティビジョナリーポッドキャスト

Episode 18: Fostering Relationships for Security Awareness

ポッドキャストを再生する
Black man sitting in conference meeting

Netskopeがセキュリティサービスエッジ(SSE)機能を介してゼロトラストおよびSASEジャーニーを実現する方法に関する最新情報をお読みください。

ブログを読む
Sunrise and cloudy sky

SASE Week

Netskope is positioned to help you begin your journey and discover where Security, Networking, and Zero Trust fit in the SASE world.

詳しくはこちら
SASE Week

セキュリティサービスエッジとは何ですか?

SASEのセキュリティ面、ネットワークとクラウドでの保護の未来を探ります。

詳しくはこちら
Four-way roundabout
  • 会社概要

    クラウド、データ、ネットワークセキュリティの課題の先取りをサポート

  • ネットスコープが選ばれる理由

    クラウドの変革とどこからでも機能することで、セキュリティの機能方法が変わりました。

  • リーダーシップ

    ネットスコープの経営陣はお客様を成功に導くために全力を尽くしています。

  • パートナー

    私たちはセキュリティリーダーと提携して、クラウドへの旅を保護します。

Netskopeは仕事の未来を可能にします。

詳しくはこちら
Curvy road through wooded area

Netskopeは、組織がゼロトラストの原則を適用してデータを保護できるように、クラウド、データ、およびネットワークのセキュリティを再定義しています。

詳しくはこちら
Switchback road atop a cliffside

思想家、建築家、夢想家、革新者。 一緒に、私たちはお客様がデータと人々を保護するのを助けるために最先端のクラウドセキュリティソリューションを提供します。

当社のチーム紹介
Group of hikers scaling a snowy mountain

Netskopeのパートナー中心の市場開拓戦略により、パートナーは企業のセキュリティを変革しながら、成長と収益性を最大化できます。

詳しくはこちら
Group of diverse young professionals smiling

A Closer Look at Hybrid Work Environments and Cyber Insurance Coverage

Dec 29 2022

Organizations seeking cyber insurance coverage are typically required by their insurer to provide evidence of a panoply of controls around information security, disaster recovery, and related risk and technology requirements and best practices.  

When organizational data resides only on-premises, documenting, evaluating and maintaining these controls have their challenges but are fairly straightforward for the IT, security and business teams responsible for them. They may need to install certain types of locks on data center doors, add cameras for monitoring foot traffic, and implement specific protocols limiting who can access what information. Within highly regulated industries, insurance carriers’ requirements often track closely with regulatory compliance.

However, COVID-19 threw a monkey wrench into cybersecurity insurance and cyber risk management for many organizations. When a substantial proportion of the workforce began working remotely, the appropriate security control structure became less clear-cut. The challenge was exacerbated by the simultaneous increase in corporate use of Software as a Service (SaaS) solutions.

Today, perhaps the only thing more challenging than building an effective control structure is producing evidence that the structure is effectively protecting corporate applications, data and users. 

Now, corporate cybersecurity managers need to focus on understanding how their controls should be structured post COVID, as well as how they can demonstrate those controls to internal and external auditors, as well as their insurers. 

What exactly changed?

The pandemic inspired a migration of workforces around the world. Employees are still doing the same jobs they used to do in the office, but many are doing so from home or other remote locations.

It’s now much harder for traditional perimeter security methods to be effective in this hybrid environment. Even if the security team had the bandwidth to travel to each employee’s residence, installing security cameras and deadbolts on home office doors would not make sense. Nor is it feasible for a third-party auditor to travel to each disparate location to validate that the employee’s security environment is up to snuff.

Similar challenges certainly arose before COVID-19 existed. Some people traveled for their jobs, while others needed to occasionally take work home at night. Security teams required those types of remote workers to connect to the corporate network via a virtual private network (VPN). Auditors might ask how the company was protecting those connections, but when the company needed to prove that its most crucial controls were working, remote employees were typically the exception rather than the rule.

Hybrid work and cloud transformation flipped that equation on its head. The importance and effectiveness of perimeter based controls and related security technologies has unraveled. Having to connect to the corporate network before using a SaaS application or browsing the internet can be tedious and may come with poor user experience.

During the pandemic, some organizations made risky technology decisions for remote access by allowing the bypass of overwhelmed and oversubscribed remote access solutions that increased their attack surfaces. This combined with the increase of personal time spent on devices meant that the attack surface also now extended to often trusted services like Office 365, Google Suite and a host of other tools that employees use in both their professional and personal lives. This left gaps in many security technology strategies where traditional capabilities lack the ability to determine the difference between a corporate instance of Office 365 and a personal instance used at home. As a result of this quickly changing business operating environment and hybrid work landscape, cyber insurance providers’ control requirements have only intensified as the frequency of attacks and resulting losses from security incidents continue to mount. 

What are insurers’ expectations?

When an organization seeks a cyber insurance policy, the insurer is naturally going to want information about the prospective business, operating environment, cybersecurity program, and related controls. This information is typically captured through the primary application process, supplemental coverage application, and the overall assessment methodology required to support underwriting the risk. The often paper-based process of explaining controls, providing an overview of the cybersecurity/risk management program and providing supporting documentation is a common place to start — but more and more the insurer also is expecting to see proof.

Producing evidence may often be supported by attestations derived from external audits, assessments and penetration tests. However, any audit or assessment outcome is a snapshot in time and reflective of the efficacy and operating state of controls during a static time period and thus does not reflect the ebbs and flows of how an organization’s attack surface can quickly change. More and more, insurance companies are moving towards opportunities for continuously monitoring their insureds for changes to highlight emerging risks and vulnerabilities that could indicate, and better predicate, situations that may result in a claim.  

What does this mean for both the policyholder and the insurance company? 

The reality is, there is opportunity for both sides to gain insights from continuous visibility. The challenge is that with hybrid work and the impacts of continued digital transformation in business, it is crucial to look beyond just the inventory of users, identities, devices, applications and data that can be abstracted from the traditional data center operating environment. It is now critical to fully understand those key data points along with the inventory of cloud services in use: those that are sanctioned by IT; those being driven by business units (shadow IT); and those more personal services that are introduced everyday by end-users. 

While the inventory is a starting point, it is also important to understand who is accessing those services and how are they configured, as well as how much data is being sent to the services in question are all key elements that can quickly change a risk profile of an insured and often goes unchecked. Lastly, there is a need to evaluate the aforementioned cloud services from a supply chain risk and threat perspective and be able to answer questions about the organization’s cloud security posture.

The industry is certainly seeing more insurers integrate actuarial science, cybersecurity attack surface evaluation, controls and threat monitoring; basing pricing on telemetry-driven predictions of which users are most likely to experience a data breach or other security incident that leads to a claim. Regardless of whether, or when, that fully comes to pass, security teams that are transforming their environments and modernizing their architectures have the capabilities and data needed to understand their cyber risks and ultimately provide proof that they are effectively managing the risk that they wish to transfer. 

This article was originally published by Security Magazine

author image
Nathan Smolenski
Nathan is an experienced CISO & risk management and technology leader with over 19 years of experience across financial services, management consulting, insurance, and software industry verticals. He currently serves as Director, Head of Enterprise Security Strategy as a member of the global strategy team at Netskope, focused on digital transformation and the impacts on cybersecurity programs and strategies.