Part 1: Evolution of Trust - Adapting and Utilising CISA’s Zero Trust Maturity Model in an AI World
Education, Training, Certification, and Thought Leadership
Recently active
In this video, start building dashboards and widgets using the tools in Explore. To see more videos, visit the community page.
Hear from Netskope product and customer experience teams to learn about the latest capabilities that curb cloud risk. In this session, you’ll hear about key use cases to implement protections that stop threats, protect data and identify sources of risk. What you'll learn: Improve your understanding of attacks against your organization with the MITRE ATT&CK® framework Use policy to control what unknown users can do with data Apply real time protection with additional support for applications Use inline controls with AWS for granular protection Learn how to use Advanced Analytics to geolocate your data and spot insider threats
This article will cover how to configure Single-Sign-On (SSO) for the Netskope Cloud Exchange (CE) platform using Okta. This will allow you to manage administrator access to CE from purely within Okta, rather than configuring administrators on the platform manually. Cloud Exchange is different from the standard Netskope tenant you would have access to as a customer, and facilitates the exchange of information between your various security and operations platforms. For information on what Cloud Exchange is (including how to deploy it), please see here. Create a new App Integration Log in to your Okta administrator console and from the left-side menubar, navigate to Applications > Applications. Select Create App Integration. Select SAML 2.0 as the sign-in method and click Next. On the next screen, set the App name to be Netskope Cloud Exchange and provide an app logo if required. Click Next to proceed to the Configure SAML section. Copy the Cloud Exc
This article will cover how to configure Single-Sign-On (SSO) for the Netskope Cloud Exchange (CE) platform using Azure Active Directory (AAD). This will allow you to manage administrator access to CE from purely within AAD, rather than configuring administrators on the platform manually. Cloud Exchange is different from the standard Netskope tenant you would have access to as a customer, and facilitates the exchange of information between your various security and operations platforms. For information on what Cloud Exchange is (including how to deploy it), please see here. Create a new Enterprise Application Log into the Azure AD portal, and go to “Enterprise Applications”. You may need to search for this at the top of the portal. Click New application. Click Create your own application and name the application Netskope Cloud Exchange. Select the 3rd option to create a non-gallery app: Integrate any other application you don’t find in the gallery. Clic
In this webinar, you will learn about platform updates from Release 90 and 91. We will be focusing on the features and improvements across these core product families:* Next Gen SWG* Cloud Firewall* Netskope Private Access (NPA)* Data Protection* UEBA* Cloud Security* Threat Protection* Advanced Analytics Learn about new features and their use cases, and how these features will add value to your Netskope investment.
Learn how Netskope Cloud Exchange provides you with powerful integration tools to leverage across your security posture. Cloud Exchange consumes valuable Netskope telemetry and external threat intelligence and risk scores, enabling improved policy implementation, automated service ticket creation, and exportation of log events from the Netskope Security Cloud. What you'll learn:Share threat intelligence. Automate bidirectional IOC sharing between your defenses including Netskope, endpoints, email gateways, and SIEMs. Automate service tickets. Improve workflows where Netskope alerts create service tickets in IT service management and collaboration tools. Exchange risk scores. Normalize multiple risk scores and invoke investigations for significant changes in user or device risk scoring. Export logs. Improve security operations with rich event and alert logs into your SIEM, data lake, or XDR/MDR service.
To edit (tag) a single app, hover over the app on the main page and click the Edit tag icon. To tag multiple apps, select the checkbox in the top left corner for each app. Click the Edit tags icon in the top right corner of the page. Tip: To select all apps shown on the page, click the Select All icon beside the Edit tags icon. In the Edit Tags dialog box, there are two dropdown lists for tagging the chosen apps. The left dropdown list allows you to specify whether the app is sanctioned or unsanctioned. The right dropdown list allows you to specify whether the app is consumer, departmental, or enterprise level. To create a custom tag or to remove a tag, use the field below the dropdown lists.
CVE-2021-44228 (Log4Shell or LogJam) is a recently discovered zero-day vulnerability in the ubiquitous Apache Log4j Java-based logging library. It was reported by the Alibaba Cloud Security team as an unauthenticated RCE vulnerability in Log4j 2.0-beta9 up to 2.14.1 and could allow a complete system takeover on vulnerable systems. The bug has received the maximum CVSS score of 10, reflecting its importance and ease of exploitation. This logging library is widely used in enterprise applications from Apple, Twitter, Amazon, Tesla, CloudFlare, and products including Apache Struts2, Apache Solr, Apache Druid, and Apache Flink for its rich feature set and ability to flexibly record log information. Even Ghidra, a popular reverse engineering tool from NSA, is vulnerable to this bug. Attackers can use the feature that is used to write error logs to construct special data request packets through this vulnerability and ultimately trigger the remote code execution. Threat act
In this webinar, you will learn about what's new with Netskope Cloud Firewall, Browser-based Private Access, Advanced UEBA with User Confidence Index, and Adaptive Access. As well as, get the latest updates to threat and data protection, detections and applications enhancements for SSPM, and much more.
In this webinar, Steve Riley, Field CTO and previously the lead author of Gartner’s Market Guide for Zero Trust Network Access (ZTNA), explores the most successful and repeatable Zero Trust Network Access (ZTNA) use cases for organizations. He walks through best practices that have helped organizations deliver leading ZTNA experiences for their user communities and will share advice on identifying quick wins for your organization. We would love to get your feedback on what topics you'd be interested in learning about on our upcoming customer webinars. Please comment below with topic suggestions!
Check out our latest blog series on AWS Best Practices on Logging! Although CloudTrail is a well-trodden subject for AWS Security, there were still a few interesting findings among a slice of our customer base: Enable VPC flow logs: 81% of VPCs do not have VPC flow logging enabled, which will hinder incident response and investigations. Encrypt CloudTrail logs at rest: 91% of CloudTrail logs are not encrypted at rest. Encryption at rest supports data compliance controls and is easy to do. Ensure S3 bucket access logging is enabled for CloudTrail buckets: 41% of CloudTrail buckets do not have server access logging enabled. Logging should be enabled for all CloudTrail S3 buckets. Ensure CloudTrail logs are integrated with CloudWatch or a SIEM: 54% of CloudTrails are not integrated with CloudWatch. These should be reviewed to ensure they are integrated with a production log search service or SIEM. If your AWS accounts fall into these c
Why create a brand new PPT meeting deck every time you host a User Group?! Check out our latest User Group PPT template attached below! Every quarter our Community team will update this PPT to include the latest Netskope Community news & announcements, upcoming events, and product release information. All you need to do is: Download the template Fill in your User Group information (leader head shots, updates, survey, etc.) Share at your next meeting Last Updated: 9/15/2021
We just published another blog related to application risk from OAuth applications: Who Do You Trust? Challenges with OAuth Application Identity . This follows up on several other recent blogs related to OAuth: Who Do You Trust? OAuth Client Application Trends New Phishing Attacks Exploiting OAuth Authorization Flows (Part 1) In this blog, we discuss some of the challenges that aren't addressed by the OAuth protocol, specifically the challenges in identifying an OAuth application that a user is trusting with access to data or other resources. The scenario is: A user or administrator or an organization is prompted whether to trust an application -- you see an application title (created by the developer) -- is it real or is it fake? Unlike the more-established field of malware that utilize DNS, we have nothing akin to DNS registrars, passive DNS databases, certificate authorities, so it makes the task of identification and att
We just published A Real-World Look at AWS Best Practices: Networking, part 6 of our AWS Best Practices series, looking closer at networking configurations with NACLs and Security Groups with respect to inbound access from the Internet to RDP and SSH, as well as the use of Default Security Groups (not recommended). In reviewing anonymized customer, we found opportunities to improve security: Use More Secure Remote Access: Replace security groups that allow inbound Internet access to remote admin ports with more secure methods to remotely administer EC2 instances. 4% of the security groups in use allow inbound Internet access for SSH or RDP. Do Not Use Default Security Groups: Ensure that default security groups do not allow any traffic and are not used. 609 default security groups (1% of all security groups) are being used and allow traffic of some kind. Some additional, relevant material you may want to also read: It’s All About Access: Remote Access Statisti
Open forum for anyone who has completed the Netskope Security Cloud Introductory Online Technical Training. Feel free to ask questions, provide feedback or help out your peers with anything you can contribute.
The Ragnarok ransomware gang had been around since 2019, and suddenly ceased operations today, posting a universal decrypter and instructions on how do use it. What does this mean for the risk of ransomware? Not much. This week, we published a blog post about BlackMatter, a newcomer to the ransomware space. This is just the normal revolving door of ransomware operators, all following the same ransomware-as-a-service business model, using the same tactics, and trying to put controls in place so their affiliates don't target anyone that results in too much attention for the operators. Netskope protects against ransomware using a multi-layered approach that includes signatures, machine learning, static heuristics, and sandbox analysis to prevent ransomware from making its way onto any of your endpoints. One of the most common ransomware delivery tactics we are actively blocking is ransomware delivered as next-stage payloads by malicious Microsoft Office Documents. Our Office Docum
In part 5 of our continuing series on AWS Best Practices, we cover real-world stats on storage, specifically public access on buckets and encryption of EBS volumes: https://www.netskope.com/blog/a-real-world-look-at-aws-best-practices-storage One of the challenges is having a clean process to provision, secure, and continually monitor whether data storage such an S3 bucket should be public or private. How does your organization manage this? - do you use tagging, resource groups, or accounts to identify whether buckets are expected to be private or public? - do you enforce that a bucket is completely public/private by using bucket level ACLs/policies rather than object-level? - do you have additional audit checks on the above? Additionally, how do you look upon encryption at rest? Is it solely for compliance, so AWS keys are sufficient or do you use CMKs of your own for real data privacy? Would love to hear comments on how customers are managing this crucial
I have read somewhere that completing Netskope Cloud Introductory Online Technical Training and Netskope Security Cloud Hands On Training will get me a Netskope Could Security Specialist. I've completed both training but still haven't received anything regarding the specialist certification. Can someone help me how can I grab Cloud Security Specialist certification?
We just published the first three parts of a multi-blog series on new phishing attacks that can exploit OAuth 2.0 authorization flows: https://www.netskope.com/blog/new-phishing-attacks-exploiting-oauth-authorization-flows-part-1 https://www.netskope.com/blog/new-phishing-attacks-exploiting-oauth-authentication-flows-part-2 https://www.netskope.com/blog/new-phishing-attacks-exploiting-oauth-authentication-flows-part-3 We believe there will be an increasing trend in phishing and other attacks that abuse the OAuth protocol itself in order to gain advantages such as: obtaining OAuth session tokens which bypass MFA and are practically permanent, as well as take advantage of quirks such as being able to spoof other applications easily. This is based upon a Def Con 29 presentation given on August 7, 2021. Currently, there is more exposure for Microsoft O365/Azure users due to their implementation of the device authorization grant flow. However, much of the material applies to a
We recently published a blog, Operationalizing IP Allow Lists for Cloud Environments, talking about the process and phases for effective implementation of IP allow lists. IP allow lists have traditionally been difficult to maintain without getting quickly out of date. We'd love to hear about your experiences. Do you use IP allows lists? For what, in which contexts? What do you use to mitigate compromised credentials? MFA? IP allow lists? other? Does Netskope's proxy architecture help you implement more effective IP allow lists? Was the blog post helpful or too high-level? Would it be useful to have more prescriptive examples (code) ?
We recently published Who Do You Trust? OAuth Client Application Trends which looks at real-world trust of applications by users using Google Identity for authentication and approval. It highlights some of the common applications and permissions being requested. Some questions for you: Are you aware of which OAuth client applications are being trusted by your users? Do you have good visibility into this data? Are you locking down your environment in any way e.g. not allowing users to grant consent or approve apps? What would help you understand and manage risk from oauth client applications?
Continuing our blog series on AWS Best Practices, we've published two additional blogs looking at real-world AWS environments and practices around IAM policies and password policies, along with easy steps you can take to reduce. Our findings include: - 4% of IAM policies grant full admin privileges - 47%-67% of IAM users are using inline or directly attached policies - 73% of account password policies have password length < 14 characters - 80% of IAM user accounts have a password reuse setting < 24 times Here are some concrete steps that can be taken to reduce risk related to IAM Policies and Password Policies: Create IAM Policies and roles with only the minimum privileges necessary. Inline policies should be replaced with managed roles that are centrally managed. IAM Policies should be attached to groups or roles, instead of users. Customize your AWS Password Policy and do not use the default. Increase the password length to at least 14, and set the pass
Open forum for anyone who has attended a Netskope Cloud Security Workshop session. Feel free to ask questions, provide feedback or help out your peers with anything you can contribute.
Open forum for anyone who has attended a Netskope Security Cloud Hands On Labs session. Feel free to ask questions, provide feedback or help out your peers with anything you can contribute.
In this webinar, you will hear from our Product Management, Technical Customer Success, and Product Marketing teams to get insight into our recent product releases and how you can put them into practice. Learn about HTTP/2, the latest deployment options, enhancements to threat protection, new data protection features, the latest additions to policy and much more across Netskope products including; NG-SWG, NPA, Cloud Security, Steering, DLP and Threat. We would love to get your feedback on what topics you'd be interested in learning about on our upcoming customer webinars. Please comment below with topic suggestions! See below for a download of the webinar slides.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.