TOYOTA INDUSTRIES IT SOLUTIONS Inc. (TIIS) manages IT for the Toyota Industries Group, a global manufacturer. To resolve internal challenges — and apply the lessons learned across the wider group — TIIS set out to build a zero trust, cloud-native environment. The key to its success: deploying Netskope SSE (Security Service Edge) together with Netskope SD-WAN to achieve complete, single-vendor SASE (Secure Access Service Edge). By converging security and networking, TIIS strengthened its data-loss prevention, streamlined operations, and optimized network costs — and is now turning its attention to visibility and control for AI.
TIIS was established in 1991 as a spin-off from the information systems division of Toyota Industries Corporation. It underpins the IT of the Toyota Industries Group, whose businesses — automobiles, industrial vehicles, and textile machinery — span the globe. The company’s strength lies in working closely alongside the business, from IoT-enabling production sites and applying AI to strengthening cybersecurity, and supporting the full IT lifecycle from strategy and planning through development and operations. TIIS also blends the philosophy of the Toyota Production System (TPS) with IT expertise to deliver optimal solutions to customers outside the group as well.
As the Group’s IT professionals, TIIS is expected to be an early adopter of advanced initiatives and to feed the resulting knowledge and know-how back to the wider group. In pursuit of greater agility and a willingness to embrace new technology — and to avoid owning assets outright — nearly all of TIIS’s systems now run in the cloud. Naoyuki Nogaya, General Manager of the IT Infrastructure Department, IT Platform Unit, recalls that this cloud-native environment brought security challenges on two fronts: the business and the workplace. “On the business side, our security foundation hadn’t kept pace with growing use of cloud services,” he says. “We were also concerned that the trade-off between data-loss prevention and usability would become a drag on our digital transformation efforts. On the workplace side, hybrid work — which has continued well beyond the pandemic for reasons of work-life balance and talent retention — was exposing the limits of traditional perimeter-based defense.”
To resolve both challenges, TIIS launched a project in 2024 to build a zero trust, cloud-native environment that lets employees work securely anytime, anywhere. Asked about the key to success, Nogaya points to one decision: “achieving complete SASE — SSE plus SD-WAN — from a single vendor.”
After comparing several products, we found that Netskope’s CASB (Cloud Access Security Broker) gave us the best visibility into cloud service usage.
For its zero trust, cloud-native environment, TIIS first selected an SSE solution. “After comparing several products, we found that Netskope’s CASB (Cloud Access Security Broker) gave us the best visibility into cloud service usage. Beyond visibility, it also stood out for its fine-grained control,” Nogaya explains.
“From a data-loss prevention standpoint, being able to block file uploads to cloud services is essential. But if you prohibit use of a service outright to stop uploads, you also lose the ability to download from it. We needed an approach beyond a simple allow-or-deny choice. Netskope’s CASB lets us control and block uploads and downloads independently, which we felt could flexibly meet the needs on the ground. Being able to distinguish between personal and corporate tenants — and control access accordingly — further strengthens our defenses.”
In April 2024, TIIS decided to adopt Netskope SSE, which consolidates CASB, SWG (Secure Web Gateway), ZTNA (Zero Trust Network Access), and other security functions into a single platform.
Kiyotaka Naruse, of Group 1, IT Infrastructure Section 2, IT Infrastructure Department, describes what mattered most during rollout: “Zero trust means trusting no access or communication by default, but we were concerned that applying overly granular controls from day one would complicate operations and keep the environment from taking hold in the field,” he says. “So we defined broad groupings — the whole organization, individual departments, individual users — and set the communication controls each group needed. We also had to be careful with SSL decryption, which inspects the contents of traffic within SSE, since it can inadvertently block application traffic. To guard against that, we kept SSL decryption exclusions to a minimum and fine-tuned our operations to maintain strong security.”
By adding Netskope SD-WAN alongside Netskope SSE, we can apply the same security policy to devices that can’t run an agent.
As TIIS migrated from its legacy security environment to Netskope SSE, a new challenge emerged: how to cover the areas SSE alone couldn’t reach, Nogaya recalls.
“Our sites include devices that can’t run an agent — time clocks, printers, IoT devices, and PCs used for on-site customer maintenance,” he says. “Extending our existing security environment to cover them would have made operations more complex and made it difficult to consistently enforce security policy.”
TIIS turned to SD-WAN (Software-Defined Wide Area Network), which uses software to control the wide area network (WAN) connecting its sites. “The key was to achieve complete SASE by unifying security and networking under a single vendor,” Nogaya says, continuing: “By adding Netskope SD-WAN alongside Netskope SSE, we can apply the same security policy to devices that can’t run an agent. Combining products from multiple vendors, by contrast, tends to mean building and maintaining separate, overlapping policies. Consolidating and simplifying operations with a single vendor means we don’t have to piece together routers and other components — SASE becomes achievable through configuration alone, which is a major operational advantage.”
With Netskope’s SSE and SD-WAN, we’ve built the foundation for a zero trust, cloud-native environment.
In August 2025, TIIS’s zero trust environment, powered by Netskope SSE, went fully live. Naruse describes the impact: “Netskope uses its own algorithms to block uploads even to cloud storage services that other vendors’ products fail to identify, so we feel we’ve achieved far more thorough upload control than before,” he says. “And because downloads are now allowed, users can get the information they need exactly when they need it — the volume of download-related requests has dropped sharply. We’ve also restricted use to a company-approved standard generative AI tool; any other AI service requires a request, and only approved services are permitted.”
TIIS is now rolling out Netskope SD-WAN to complete its SASE deployment. Beyond covering what SSE alone can’t reach, Naruse notes it is also optimizing network costs: “Our previous inter-site network billed us based on bandwidth consumed, and it was difficult to rein in costs that kept climbing,” he says. “Now, traffic from PCs running the Netskope agent goes out over the internet, while traffic SSE can’t handle — server-originated traffic, for example — is routed over SD-WAN, optimizing our overall network costs. Traffic from every site also passes through a SASE gateway, so the same security policy is enforced consistently across Netskope’s platform. We’ve also eliminated the performance slowdowns at our sites that used to occur during events like Windows updates.”
“With Netskope’s SSE and SD-WAN, we’ve built the foundation for a zero trust, cloud-native environment,” Nogaya says. “We’ll put the knowledge and know-how we’ve gained to work driving digital transformation and workstyle reform across the Toyota Industries Group.”
Looking ahead, both Nogaya and Naruse say TIIS will accelerate AI-driven development and the transformation of its operations through AI agents. They’re also looking forward to Netskope One AI Security, which will let TIIS visualize, control, and protect its entire AI ecosystem — including visibility into communication between AI agents and real-time analysis of prompts.
