Part 1: Evolution of Trust - Adapting and Utilising CISA’s Zero Trust Maturity Model in an AI World
Education, Training, Certification, and Thought Leadership
Recently active
In this guide, the Netskope Red Team outlines its strategic framework for identifying and mitigating vulnerabilities within AI/LLM ecosystems. Given the unique challenges and threat landscape associated with AI and LLM systems, a specialized methodology is essential to ensure the robustness, integrity, and confidentiality of our AI-driven features and services.Our methodology is designed to be comprehensive, covering the entire lifecycle of the AI/LLM application — from data ingestion and model training to deployment and continuous monitoring. 1. Phased Approach to AI Security TestingSecurity testing for AI applications is structured into four distinct phases, ensuring thorough coverage of all potential vulnerabilities. Phase Description Key Activities Phase 1: Design and Data Security Review Focuses on the foundational security elements before model development. Data Sanitization review, Data governance policy review, Threat Modeling for Produc
LLMs in enterprises have evolved extremely fast. What started as simple chatbots answering questions has now become AI agents that can perform real actions: like reading files, querying databases. or sending messages in Slack.But early GenAI integrations were messy. If a developer wanted an AI model to connect to PostgreSQL, Slack, and the local filesystem, they had to build three separate connectors, each with its own authentication logic, API handling, data formatting, and error management.As companies scaled, this created a major problem: AI apps + more tools = exponentially more integrations.This is the classic N × M integration problem, and it quickly becomes impossible to maintain securely. To solve this, Anthropic introduced the Model Context Protocol (MCP) in late 2024.MCP is often described as the “USB-C for AI applications.” Instead of building custom connectors for every system, MCP provides a standard way for AI hosts to connect to external tools and data sources through M
We have two major releases to announce for our ServiceNow ecosystem — the brand-new Netskope CMDB Integration app, now available on the ServiceNow Store, and version 3.0 of the Netskope SecOps (SIR) app, which brings significant new capabilities to security operations workflows.Whether you're an IT operations team looking to bridge your CMDB with Netskope's Zero Trust visibility, or a SOC team wanting richer incident response automation — there's something here for everyone. PART 1 — NEW APP Introducing the Netskope CMDB Integration AppThe Netskope CMDB Integration app is a first-of-its-kind release that connects Netskope's Security Service Edge (SSE) platform directly to ServiceNow's Configuration Management Database. This app is purpose-built for IT and security operations teams who want Netskope's asset, policy, and access data living natively within their ServiceNow CMDB — no custom scripts, no middleware, no manual exports. 1. Private App Bidirectional SyncThe CMDB app supports
Hear from our security engineers as they demonstrate how CE's three integration pillars of Cloud Threat Exchange (CTE), Cloud Ticket Orchestrator (CTO), and Cloud Risk Exchange (CRE) connect Netskope to the tools we already rely on, turning isolated signals into coordinated, automated action.Learn how to: Automatically ingest curated threat feeds and STIX-formatted IOCs from Feedly's AI-powered intelligence engine and any TAXII-compliant source Bidirectionally share email-borne threat indicators from Mimecast and endpoint-detected IOCs from CrowdStrike Falcon Propagate AWS infrastructure threat findings from GuardDuty and supply chain risk signals from GitHub directly into Netskope's threat intelligence pipeline Feed Mimecast email threat signals into Netskope's User Confidence Index (UCI), dynamically adjusting cloud access policies For more information, check out our blog post. View past events in this series! Check out some customer questions below, or feel free to comment
This is a demo covering how Netskope provides full visibility, control, and protection for genAI app usage. Learn more.
This is a demo of the Netskope One Agentic Broker, which provides unified visibility and real-time protection for the autonomous AI ecosystem by decoding and securing Model Context Protocol (MCP) traffic between AI agents and data sources. Learn more about Netskope One Agentic Broker.
Netskope One AI Guardrails provides real-time content moderation for every interaction, securing the enterprise against emerging AI-specific threats including prompt injection and jailbreak attempts, and unsafe use. Learn more.Netskope One AI Gateway secures the API traffic fueling your AI-powered applications. By centralizing authentication, traffic management, and content inspection between private apps and LLMs, we ensure autonomous agentic data flows remain governed and secure. Learn more.
Author: Stevan Pierce & Madhura SridharDate: March 16, 2026Modern security teams are drowning in “partial truths.”Your email gateway flags suspicious links. Your EDR finds a questionable process. Your SASE platform sees risky SaaS behavior. Your IAM solution logs a strange login pattern. Each tool is doing its job yet each is also speaking its own language, in its own console, with its own definition of “risk.”The result is a familiar and frustrating reality:Analysts jump between dashboards Teams argue over whose alert is “right” Critical context is trapped in silos And incident response lags behind the adversaryAt Netskope, we faced this exact problem in our own environment. As “Customer Zero,” our security team not only secures Netskope but also pushes our own platform to its limits, trying to solve the same challenges our customers wrestle with every day. This is where Netskope Cloud Exchange (CE) comes in.Cloud Exchange is how we connect the Netskope One platform with the tool
Proactively identify and address vulnerabilities in private AI deployments. Automate adversarial simulations to find and fix vulnerabilities, to ensure your AI is resilient and production-ready before it reaches your users. Learn more about Netskope One AI Red Teaming.
The "Missing Chapter" Problem in Product RequirementsEvery new product feature begins with a Product Requirement Document (PRD)—the blueprint of what is to be built. But for security architects, reviewing these documents often feels like looking for a needle in a haystack, or worse, looking for a needle that isn't even there yet.The challenge isn't just finding security flaws; it's identifying architectural omissions before a single line of code is written. Engineers focus on functionality, often leaving security as an "implementation detail" rather than a design constraint. This leads to the "Missing Chapter" problem: PRDs that describe what works, but not how it remains secure. Reviewing these manually is mentally taxing. It requires a Principal-level mindset to look at a high-level plan and immediately spot that the lack of defined tenancy boundaries will likely lead to data leakage.I realized we didn't just need a vulnerability scanner; we needed a design partner. We needed a virtu
Hear from our internal IT and security team as we share how we deployed Netskope Enterprise Browser within our managed endpoints here at Netskope. We will cover: Overview of high impact use cases Deployment to Windows Endpoints: Leveraging Intune with the focus on Auto Enrollment deployment internally Deployment to MacOS Endpoints: Leveraging Kandji with the focus on Auto Enrollment deployment internally Troubleshooting deployment issues and remediation examples Alternative Deployment Method: Manual user invite—Non managed device user install and enrollment For more information, check out our resources below: Deploying to Mac Fleet | Deploying to Windows Fleet | Enterprise Browser Usage Dashboard | Enterprise Browser Risk Dashboard | How to Import a Dashboard into Advanced Analytics View past events in this series! Check out some customer questions below, or feel free to comment and continue the discussion! Q: Do users need admin permission to install?A: Users do not need l
Looking for nice well presentation for netskope with video shots
Hear from our Product Management and Product Adoption leads as they cover the latest platform updates from Release 130, 131, and 132. Key product updates: DNS as a Service (DNSaaS) provides a high-performance cloud-hosted recursive DNS resolver, DNS security, and DNS content filtering for business and security risk categories DLP for FTP prevents data exfiltration over non-web FTP file transfers DLP on Demand enables new data protection integrations for Netskope technology alliance partners and on-premises support for customers NextGen Data Protection for Microsoft Co-pilot can now support policy creation, DLP, threat protection using ongoing scan, alerts, and more NG SWG allows seven new granular subcategories for Generative AI, available within URL categorization, enabling their use in Real-Time Policies Explore past webinars in this series!
Goal: Create a guide on how to pass Tenant Admin role from Okta to Netskope.Example: When logging in to Netskope Admin Console through Okta, different roles should be passed as per the requirement of the flow.Information coming from Partner: Administrator should be able to configure different roles for different members as per the requirement definition.Limitations: For a single Okta application, only 1 SSO can be configured in Netskope. To achieve this either we need to have multiple groups or single application with defined role.Key Concepts:Netskope Tenant - Admin should have local tenant admin account access to the Netskope tenant so that he can create custom roles / see the predefined roles during first time configuration. Workflow:This can be solved using 2 methods. Method 1 - Using Group AttributesIn this method you can create multiple groups. Just remember that the group name should be the same as the Predefined role / Custom role configured in the Netskope Tenant. Steps:1 - S
The Netskope Model Context Protocol (MCP) server was initially introduced as a self-hosted prototype, marking a significant first step in integrating Netskope’s rich security context directly into Large Language Model (LLM) workflows. This initial version demonstrated the power of the concept, enabling pioneering users to run a Docker image and establish a vital link between their LLM agents and the Netskope platform.Today, we are announcing the Netskope MCP Server Hosted Version in Technology Preview, building upon the capabilities of the initial prototype while dramatically simplifying deployment and adoption.📈 Enhanced Accessibility: Zero Infrastructure, Immediate ValueWe have moved from a "bring your own infrastructure" model to a fully managed service, eliminating the overhead of self-management. The benefits are clear:No Containers Required: We have eliminated the need for local Docker execution or complex infrastructure setup. Instant Connection: Access is provided via a direct
Hear from our internal security team as they share how we use Enterprise Browser to provide the granular visibility and control needed to secure all web activity at Netskope. We will cover: Preventing Data Loss (DLP): How to enforce real-time policies to stop data exfiltration by controlling copy/paste, screen captures, file downloads, and printing, all within the Enterprise Browser. Securing Unmanaged Devices: Strategies for safely enabling BYOD and third-party contractor access to corporate apps without requiring an installed agent or VDI. Advanced Threat Protection: Blocking phishing, malware, and malicious websites at the browser level before they can impact the endpoint or network as well as control 3rd party browser extensions. Enforcing Zero Trust Access: Integrating with your identity provider to apply adaptive access controls and ensure only authorized users access specific applications. For more information, check out our blog post. View past events in this series!
The Blank Page Problem in Security TestingEvery security assessment begins with a mountain of documentation and a crucial question: "Where would an attacker start?" For testers, translating functional specs, architectural diagrams, and API details into a concrete set of high-impact security tests is one of the most challenging and time-consuming parts of the job. It's a process that relies heavily on experience, intuition, and a meticulous, almost paranoid, mindset.The "blank page" problem is real. You can spend hours sifting through documents, trying to connect the dots between a new feature and a potential vulnerability. It’s easy to get lost in the details, miss a subtle logic flaw, or simply run out of time and fall back on a generic checklist. I realized that what we needed wasn't just another tool, but a partner—a virtual expert that could do the heavy lifting of analysis and brainstorming, allowing testers to focus on verification and exploitation. This led me to create the Abus
How to Finally Solve the BYOD, Contractor, and M&A Access DilemmaAuthor: Stevan PierceDate: November 9, 2025 The perimeter is long gone, and the "unmanaged device" is the new CISO headache. How do you grant access to contractors, BYOD users, and new M&A employees without opening a Pandora's Box of data-leakage risk?The Netskope One Enterprise Browser is an approach that isolates the application, not the device. It’s a hardened, corporate-managed browser that integrates directly into the Netskope One platform, acting as a new enforcement point for your Security Service Edge (SSE).It is a self-contained corporate workspace that:Separates Work & Personal: Creates a distinct corporate profile on any device, managed or unmanaged, separating all corporate browsing activity and data. Provides Granular DLP: Enforces in-browser controls like copy, paste, print, and screenshots—stopping data leaks at the source. Delivers Agentless ZTNA: Bakes Netskope Private Access (NPA) capabilitie
why does netskope selects the pop's in another country when GSLB is enabled
Hear from our internal security team as they demonstrate how we use the Netskope One platform to gain visibility into AI usage and enforce data protection policies that prevent risky behavior.Learn how you can:Discover which Generative AI applications are being used across your enterprise Protect sensitive data from being uploaded to both sanctioned and unsanctioned AI tools Coach employees on safe AI usage with real-time, targeted user notificationsFor more information, check out our blog post. View past events in this series! Check out some customer questions below, or feel free to comment and continue the discussion! Q: Is it possible to allow read access to Gen AI sites, but block write actions, like put and post?A: It is possible to allow for read-only access to applications/sites that are in the Gen AI category, provided we are able to see the activity using a connector or activities of browse are seen. Q: Can Netskope come up with public email domain (Gmail, Yahoo, etc.) inst
Generative AI is rapidly reshaping how we work. However, unsanctioned AI tools can create significant blind spots, leading to the potential loss of sensitive data. Security leaders are left with the critical challenge of discovering how to embrace the benefits of AI, without exposing the organization to risk.We are going to cover the who, what, when, where, and how when it comes to discovering the use of generative AI in your organization and how to ensure its safe use with the enterprise. Rapidly Reshaping WorkThe rapid integration of Generative AI into our daily workflows marks a pivotal moment in enterprise technology. These powerful tools are no longer niche innovations but have become standard, expected features within the products and services we rely on, promising unprecedented gains in productivity and creativity. As we embrace this transformative wave, however, we must also recognize that this new frontier comes with inherent challenges. The very nature of AI tools, with their
“Another Security Assessment report to review? I’ll need coffee… and maybe another pair of eyes.” If you’ve ever found yourself buried in long, detailed Security Assessment reports, you know the pain.Pages of findings to go through. CVSS scores that may (or may not) be consistent. Missing screenshots or vague remediation steps. And the endless back-and-forth just to make the report business-ready.Sound familiar? You’re not alone. Manual report reviews are slow, error-prone, and rely heavily on the reviewer’s bandwidth and expertise. But what if we had a smart first-pass reviewer that flagged gaps, standardized structure, consistency in findings & recommendations and freed us to focus on the real contextual risk analysis?That’s exactly what we set out to build — an LLM-powered Report Reviewer. Why Report Reviews Matter More Than EverSecurity assessments don’t end when testing is complete. The report is what travels to:Engineering teams → to guide fixes. Executives and stakeholders →
We know that managing legacy systems like MPLS and outdated VPNs can be a challenge.As we continue to build the future of SASE, we're dedicated to delivering a truly unified, single-vendor platform that makes your network more secure and agile. That's why we acquired our own SD-WAN solution in 2022, to simplify the journey for customers like you.Join Netskope CEO Sanjay Beri and CPO Parag Thakore and discover a practical way to evolve your network with SASE. You’ll learn how to simplify that process, reduce costs, and still deliver a high-performance, secure experience for your users.We'll dive into the practical steps of your SASE journey, including:Migrating from legacy networks to a unified SASE platform Simplifying branch infrastructure and securing IoT devices Delivering consistent zero-trust access everywhere
Hear from our internal security team as they discuss how to leverage User and Entity Behavior Analytics (UEBA) to gain full visibility of the risks that end-users face or perform and ways to take action based on User Confidence Index (UCI) scores. Key Topics:What is User and Entity Behavior Analytics (UEBA) How does Netskope use and implement this within our SOC (Security Operation Center) Detection/Ticket Creation from UCI (User Confidence Index) Enabling user risk scores from our other applications feeding into a user's UCI Policies within Netskope to coach users, or taking action for specific users’ depending on their UCI View past events in this series!
How the Salesloft Drift breach highlights the urgent need for visibility into SaaS-to-SaaS connections.The recent Salesloft Drift security incident has impacted hundreds of organizations and serves as a powerful reminder of a growing threat: risk from third-party SaaS-to-SaaS integrations. This attack exploited trusted connections between applications to access sensitive data, bypassing traditional security controls. The attack chain: How stolen tokens led to data exfiltrationThe incident began when a threat actor acquired OAuth and/or refresh tokens connected to Salesloft's Drift application. Drift, an AI chatbot, integrates deeply with platforms like Salesforce to log user interactions, leads, and meeting data. By using these stolen tokens, the attacker could effectively impersonate the legitimate Drift application. This allowed them to make authorized API calls to their victims' Salesforce instances, exfiltrating sensitive customer accounts and meeting information. The full extent
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.