Part 1: Evolution of Trust - Adapting and Utilising CISA’s Zero Trust Maturity Model in an AI World
Education, Training, Certification, and Thought Leadership
Recently active
The majority of enterprise employees are already using AI applications their IT organization has not approved. Your Identity pillar does not see them — the agent authenticates through a personal or unsanctioned service account. Your Network pillar does not flag them — AI API calls look like ordinary HTTPS. Your Data pillar does not catch the exposure — DLP rules were written for file exfiltration, not conversational data ingestion at scale. Five pillar teams, five telemetry blind spots, and a single AI application slipping through all of them simultaneously.Structural gaps in AI security are best addressed by extending existing architectural controls rather than fragmented tuning. CISA's Zero Trust Maturity Model v2.0 provides the necessary ownership domains to govern AI assets. This document establishes the five-pillar baseline—the essential "enforcement" foundation for AI security. The architectural controls defined here in part 1 are the necessary prerequisite for the governance fra
Hear from our Product Management and Product Adoption leads as they cover the latest platform updates from Release 136, 137 and 138.Key product updates:Enterprise Browser Now Covers Every Device, Everywhere: Expanded protection to all major platforms, including IGEL thin clients, with new features like watermarking, sandboxed clipboard controls, and NPA integration on mobile. AI Security: From Threat Testing to Real-Time Enforcement: Use AI Red Teaming to identify LLM vulnerabilities, detect deepfakes via API, and enforce real-time guardrails on AI traffic, including custom topic controls. Data Lineage: The Full Story Behind Every File: Built into Incident Management, this allows DLP analysts to follow sensitive data from origin to destination for faster investigations and to stop unauthorized data movement. Zero Trust Private Access: Performance, Compliance, and Coverage: Enhanced for better network throughput (BBR congestion control, dual-stack IPv4/IPv6 support), geo-fencing, and en
A brief introduction to Advanced Analytics.
Hear from our Product Management and Product Adoption leads as they cover the latest platform updates from Release 133, 134, and 135. Key product updates: Comprehensive AI Security and Governance: Protect private AI applications with the Netskope AI Gateway and AI Guardrails, providing real-time content moderation, threat protection, and vulnerability assessments via AI Red Teaming to ensure compliance and quality Advanced Visibility for Agentic Workflows: Gain full oversight of Model Context Protocol (MCP) communications through the Agentic Broker, featuring detailed audit logs and policy enforcement for remote MCP servers and clients within Skope IT Steganography detection: Identify and protect sensitive information from the growing threat of sophisticated data-hiding techniques Manager Escalation: DLP Analysts can now initiate a review workflow to request feedback from the manager of the user who committed the DLP violation DLP on Demand: Power your DSPM scans using Netskop
We’re excited to introduce a simpler, more transparent way to register for training at Netskope Academy! You can now self-register for courses using training vouchers, which means no more forms or back-and-forth. Just purchase training, receive your voucher, and enroll in minutes. Any existing, non-expired training credits you already have will automatically convert into vouchers. We’ve created a short video to show you how the new system works. See the new process in action: We’re confident this update will make your learning experience faster and easier.Questions? Contact us at training@netskope.com
Learn how to best monitor & manage the AI applications being used in your organization with our latest AI Usage Dashboard.
A common use case using Netskope One SSE and Okta is to extend your zero trust perimeter using Okta Network zones and the Netskope NewEdge network. This will create an additional obstacle for an attacker to use compromised credentials and is recommended by Okta as a defense against credential stuffing attacks. The Netskope One client checks the device posture or compliance in real time via Device Classification to ensure that only Corporate managed devices are allowed to connect to Okta. The following Okta authentication policy rule scenarios are presented below: (these would also apply when using tunnels)Prerequisites for all policy scenarios Scenario: Restrict access to application(s) for users that originate from Netskope NewEdge Scenario: Restrict access from Netskope NewEdge in the United States Scenario: Restrict access to originate from Netskope NewEdge and the user’s client IP originates in the United States Scenario: Restrict access for Administrators to originate from Netsk
This video helps you get started with Advanced Analytics in around 5 minutes, which includes an overview of the UI, copying & pasting dashboards, customizing dashboards, and editing widgets (visuals).
Building a CrowdStrike Falcon Dashboard on Netskope Data: a Step-by-step Guide How my team streamed Netskope web, DLP, and alert telemetry into CrowdStrike Falcon Next-Gen SIEM, wired up automated indicator sharing, and built a cross-source security dashboard that correlates Netskope, Falcon, and Okta signals in one place. Everything below is enough to build the same thing in your own tenant. Why we built this My security operations team lives in CrowdStrike Falcon. That is where analysts triage, hunt, and respond. But a lot of the signal they need sits in Netskope: web transaction logs, DLP violations, anomaly alerts, and policy actions from the Netskope One Security Service Edge (SSE) platform. Every time an analyst had to pivot out of Falcon to check the Netskope Admin Console, we lost time and context. Our solution had two parts. First, stream Netskope logs into Falcon LogScale so analysts get a native Netskope dashboard inside Next-Gen SIEM, sitting next to t
There's a question every security vendor eventually has to answer: do you actually use your own product to protect your business? At Netskope, the answer isn't just yes — it's the foundation of how we operate. As the Customer Zero team, our job is to deploy our Netskope products before they reach customers. That includes our full portfolio of AI-powered security capabilities, which today sit at the center of how we detect threats, govern data, control access, and keep our workforce productive without sacrificing visibility. This isn't a case study from a customer. It's what we do every day. And the products we've deployed across our own environment paint a clear picture of where enterprise AI security is headed — and what it actually takes to get there.Our internal security strategy is structured around four primary pillars, which collectively ensure that our AI-driven capabilities provide comprehensive protection across every layer of the organization. Capability Problem So
The problem we kept running intoEvery day, multiple Netskope employees would post in our internal #customerzero Slack channel asking for Enterprise Browser (EB) access. The messages were nearly identical: someone had just heard about EB, wanted to try it out, and needed a license key or enrollment invite to get started.The CZ team would then manually look up the user, send an enrollment invite through the Netskope admin console, and reply in the thread. This worked, but it was repetitive, manual work that pulled our team away from higher-value investigations and dogfooding activities.We started asking ourselves: why are we the bottleneck here? The process was entirely mechanical — receive request, identify user, send invite, confirm. It was a perfect candidate for automation.📊 By the numbersAfter analyzing 200+ posts in #customerzero, Enterprise Browser invite/license key requests were the second most common issue category — 16+ posts, fully repeatable, zero judgment required to resol
Hear from our SOC manager and Sr. Data Analyst as they share how we leverage AI security dashboards to monitor AI usage, uncover AI security concerns, and convert this into actionable insights. Learn how to:Monitor AI adoption, uncover risky AI usage, and gauge overall AI risk level using the AI Usage and AI Risk Assessment Dashboards Manage risky user and model behaviors using the AI Guardrails Dashboard Monitor and control AI app-to-app traffic using the AI Gateway Dashboard Monitor MCP usage using the Agentic Broker - MCP Dashboard For more information, check out our Advanced Analytics forum. View past events in this series! Check out some customer questions below, or feel free to comment and continue the discussion! Q: Where can I access this Activity in the AI Apps dashboard within the console?A: Visibility into user activities can be found in the "Activity in AI Apps" section of the AI Usage Dashboard. Q: How can Netskope monitor and control the use of unsanctioned AI to p
Visibility in the Age of Artificial IntelligenceAs enterprises rapidly shift toward a cloud-first and AI-driven landscape, the traditional boundaries of the corporate network have dissolved. Employees are accessing sophisticated AI tools from everywhere, making the internet the primary delivery mechanism for business productivity. This transition introduces a critical challenge: a loss of visibility into network paths, user experience, and application performance. Enter Netskope Digital Experience Management (DEM). DEM is a native component of the Netskope platform designed to provide comprehensive operational status and health visibility for all customer traffic. By leveraging a highly scalable data architecture, DEM pulls telemetry from various back-end sources to deliver real-time, actionable insights into the overall user and application experience. From monitoring tunnel status to tracking client steering and service availability, Netskope DEM ensures that IT teams maintain contro
INTEGRATION GUIDEAutomating Noncompliant Device Enforcement with Netskope Cloud Exchange and Microsoft IntuneCloud Exchange × Microsoft IntuneThis guide shows how the Netskope Cloud Exchange Risk Exchange (CRE) module reads device compliance from Microsoft Intune, tags noncompliant devices in the Netskope tenant, and drives real-time enforcement. The result is a closed loop between your Mobile Device Management (MDM) system and Netskope, with no manual handoff between consoles.How the integration worksMicrosoft Intune continuously evaluates enrolled devices against its compliance policies. Cloud Exchange pulls that device data through the Microsoft Intune plugin, merges it with the matching Netskope device record, and, when a business rule matches, pushes a device tag back to the Netskope tenant. A Device Classification rule reads that tag, and a Real-time Protection policy acts on the classification.The stages below trace a single noncompliant Windows device end to end. 1 2
Overview This guide shows how to stream Netskope alerts and events into Microsoft Sentinel.The connector is called Netskope Alerts & Events Connector (via Blob Storage). Netskope publishes it. It ingests alerts and events logs from Netskope Log Streaming into Microsoft Sentinel via Azure Blob Storage, using the Microsoft Sentinel Codeless Connector Framework (CCF).The data flow does not push logs straight into Sentinel. Netskope Log Streaming writes logs to an Azure Blob Storage container. Sentinel then reads those blobs and writes the records into the Log Analytics table NetskopeAlertEvents_CL.This article is based on the connector's own deployment template (netskope_alert_events_log_streaming.json). UIs in Netskope and Azure change over time, so verify each screen against current documentation as you go.How it works (architecture)The pipeline has three stages.Netskope Log Streaming sends Alerts & Events logs to an Azure Blob Storage container. Azure infrastructure signals new
OverviewA continuation of Sending Alerts and Events to Microsoft Sentinel using the Codeless Connector Platform.The first article set up the Codeless Connector for a single Netskope tenant. This post extends it. It sends alerts and events from several Netskope tenants into one Microsoft Sentinel workspace, and it labels each record so you can tell the tenants apart.If you have not read the single-tenant article, start there. The base ideas carry over: the Codeless Connector Framework, the RBACv3 service-account token, and the REST API index. Architecture Each Netskope tenant sends alerts and events to the same connector. The connector posts the data to one Data Collection Endpoint. A separate Data Collection Rule for each tenant adds a TenantSource value and writes the record to the shared tables. The result: all tenants share the same tables, and the TenantSource column tells you which tenant a row came from.This template supports up to five tenants.What is different from the single-t
Hear from our security engineers as we share how Netskope moved beyond blanket restrictions to a more adaptive, context-aware approach that lets us safely say “yes” to SaaS and GenAI. We’ll highlight real-world patterns of risky usage, common blind spots across managed and unmanaged apps, and the unique data exposure risks posed by GenAI assistants and copilots. Learn how to:Discover and continuously assess SaaS and GenAI usage across your environment Protect sensitive data with granular, inline, and context-aware controls Apply consistent policies to managed, unmanaged, and AI-powered applications Partner with business stakeholders to securely accelerate SaaS and GenAI initiativesFor more information, check out our blog post. View past events in this series! Check out some customer questions below, or feel free to comment and continue the discussion! Q: Can you share best practices for GenAI apps control in RTP policy structure given new app connectors and capabilities?A: Discover
This document outlines the integration of Netskope Web Transaction Logs with Microsoft Sentinel on Azure US Government cloud using the Codeless Connector Framework (CCF). Separate templates are provided for comma-delimited and space-delimited blob data. This native integration provides near real-time visibility for effective threat hunting and incident management. To configure Netskope Log Streaming to send logs to your Blob storage please go through the article: https://docs.netskope.com/en/stream-logs-to-azure-blob ⚠️ Important: You can't restrict network access to your Azure Blob Storage account as per the official guidance from Microsoft.🏗️ Integration Architecture OverviewThe integration leverages several Azure services to ensure reliable and scalable log delivery: Netskope to Azure Storage Blob: Netskope pushes Web Transaction Logs into a customer-owned Azure Storage Blob Container (as gzipped CSV files). Event Grid Notification: Every time a new file (blob) is written, an auto
Anthropic’s Claude has gone from "the AI tool a few teams were experimenting with" to mission-critical infrastructure: Developers ship code with Claude Code. Analysts build entire workflows on Claude Projects. Platform teams run inference at scale through the Claude Platform. But here's the uncomfortable question: Do you have the same security governance over Claude that you have over Slack, Google Workspace, or Salesforce? If the answer is "not yet" — this post is for you.Netskope has built an integration with the Claude Compliance API, giving security and compliance teams visibility into Claude usage directly within the Netskope One Platform. This brings Claude Enterprise and Claude Platform activity under the same security umbrella as every other application in your stack.No new tools. No separate dashboards. The same console your team already uses. Let me walk you through what this looks like — and more importantly, why it matters.The Problem: AI Apps Are the New Shadow IT When
Author: Stevan PierceDate: May 8, 2026Modern security teams are stuck in an old debate.The business wants ChatGPT, Copilot, Cursor, Gemini, and the next AI assistant your CEO sees demoed at a conference. The security team sees prompts full of source code and customer PII heading to a third-party model, an MCP server nobody vetted suddenly connecting to your data lake, and an "AI Overviews" toggle that quietly turned a sanctioned search engine into a generative assistant overnight.The instinct is to block. Block the domain. Block the category. Send a stern email.It doesn't work. Blocking a sanctioned AI assistant doesn't make the data exfiltration risk go away. It just pushes the user to a personal account on their phone, where you have zero visibility. And the embedded AI in apps you've already approved? You can't block that without breaking the app.At Netskope, we faced this exact problem in our own environment. As Customer Zero, our security team not only secures Netskope but also p
In this 2 minute Ask SME Anything video you’ll discover how data lineage provides a visual roadmap of your data’s journey—revealing exactly how it moves, mutates, and who touches it along the way.Hear from Product Marketing Director, Ankur Chadda, as he explains how pairing lineage with your DLP strategy creates a powerhouse toolkit that ensures no data movement goes unnoticed.
It is early 2026, and the intersection of AI and security has moved past the "hype" phase into a high-stakes arms race. We are currently seeing a massive shift from simple chatbots to "Agentic AI"—autonomous systems that can take actions on your behalf—which has created entirely new categories of risk. There are different types of AI agents based on reasoning complexity, functional role, system architecture and maturity level. 1. Categorization by Reasoning StrategyThis defines the "cognitive" depth of the agent—how it processes information and makes decisions.Reflexive Agents: The simplest "Trigger-Action" bots. They follow "if-then" rules (e.g., a thermostat or a basic auto-responder). Chain-of-Thought (CoT) Agents: Use LLMs to break down a prompt into a linear sequence of steps before acting. Reasoning-First Agents (ReAct/Tree-of-Thought): These agents "think" before and during execution. They use patterns like ReAct (Reason + Act) to observe the result of an action and adjust their
In this special edition of our Inside Netskope series, our internal leadership team will share our Fusion Team Framework. Hear how we integrated security architects into IT delivery cadences to resolve decision-right friction at Netskope, and the Metrics/Artifacts that validated our shift.Our CIO and CISO will cover: The Fusion Team Framework: An analysis of the shared charter and decision-rights model used to align CIO and CISO priorities Architectural Integration: A look at embedding security architects directly into IT delivery cadences to eliminate deployment friction Operational Metrics: A review of real-world data, including UAR cycle-time compression and SLA compliance for JML (Joiner/Mover/Leaver) processes Governance Artifacts: A deep dive into orphaned account remediation rates and the technical documentation powering the shift from theory to practice For more information, check out this article. View past events in this series!
Objective: Develop a comprehensive guide for configuring SAML-based Single Sign-On (SSO) between PingFederate and the Netskope Admin Console.Overview: This documentation will outline the methodology for enabling secure administrative access to Netskope using PingFederate as the Identity Provider (IdP).Prerequisites: Netskope Tenant: Local administrator privileges are required to modify SAML settings within the Netskope console. PingFederate: Administrative access to the PingFederate environment to configure the Service Provider (SP) connection. Workflow:Step 1 - Click on Application button in the top barStep 2 - Once the application page loads, click on SP Connections.Step 3 - In the SP Connections, Click on Create Connection. A SP (Service Provider) Connection is a configuration set that allows PingFederate (acting as the Identity Provider or IdP) to securely communicate and share identity data with an external application or service.Step 4 - Select Do not use a template for this co
Objective: Develop a comprehensive configuration guide for SCIM provisioning between PingFederate and Netskope.Scope: This guide will detail the end-to-end process for automating user provisioning via the SCIM protocol.Prerequisites: Netskope: Administrative access to the local tenant is required to configure SCIM settings. PingFederate: Administrative privileges within the PingFederate environment to manage application integration. Workflow:Step 1 - Login to your PingFederate Application using your login credentials.Step 2 - If it's your first time login then you will be asked to reset your password. Else, continue to the next step.Step 3 - Once you login successfully, you will see the home screen. In the home screen, you will find all the required actions items. Step 4 - Now, before enabling the SCIM integration, we need a service account for the PingFederate application to communicate with the netskope tenant. Login to your tenant which needs to be integrated for SSO / SCIM. URL w
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.