Part 1: Evolution of Trust - Adapting and Utilising CISA’s Zero Trust Maturity Model in an AI World
Education, Training, Certification, and Thought Leadership
Recently active
In case you missed the latest webinar in our Inside Netskope series—where Netskope experts show you how we protect our users, applications, and data using our own cloud-based architecture—a recording and recap of our recent session on “Managing Certificate Errors with Netskope Client” can be found below. Feel free to comment and continue the discussion! 📽 Watch on-demand 🍿 Q: Our recommendation from a Netskope implementation engineer was to keep developers in a steering configuration group that was only cloud apps, not all traffic. This doesn't seem like a feasible nor secure option. Is this recommended to most all customers?A: This is the initial approach to temporarily resolve the issue and keep things running. But as mentioned in the webinar, you will have to work with the developers and understand their traffic patterns to add the Netskope CA to tools to securely enable developers. Q: There is a script that is available on your Support site but it doesn't appear to be updated oft
In today's dynamic digital landscape, organizations are increasingly leveraging a diverse array of Software-as-a-Service (SaaS) applications. While publicly available SaaS apps offer immense benefits, many organizations also rely on custom-built or specialized in-house applications. This presents a unique challenge: how to effectively monitor the security posture of these custom SaaS apps alongside your standard, out-of-the-box solutions? Netskope Security Posture Management (SSPM) has the answer! We're thrilled to announce our new Bring Your Own App (BYOA) feature, designed to extend SSPM's comprehensive monitoring capabilities to your custom SaaS applications. What is Bring Your Own App (BYOA)?BYOA allows you to seamlessly integrate any custom SaaS app, whether it's publicly available or developed internally, into Netskope SSPM. This means you can now define configuration attributes to be monitored, create custom rules, and enjoy continuous monitoring and reporting for all your uniqu
Hear from our Product Management and Product Adoption leads as they cover the latest platform updates from Release 127, 128, and 129. Key product updates: Copilot for CCI (SkopeAI) gets smarter with new enhancements for expanded insights across multiple applications directly from Cloud Apps pages Netskope One DSPM data visibility and risk assessment for OneDrive, SharePoint, Google Drive, Box, and Oracle Cloud Infrastructure NextGen API Protection Jira Support for ongoing and retroactive DLP and threat scans for Jira NextGen API Protection SharePoint enhancement to detect files in SharePoint that are exposed to Copilot, helping to prevent sensitive data overexposure Enterprise Browser now supports screenshot, screen sharing, and watermarking Browser Protection Policies Cloud TAP now supports AWS IAM Roles Anywhere to securely store tapped data into S3 buckets Netskope Client Secure Enrollment capabilities Netskope Client Debug Mode makes log collection frictionless for e
Certificates have become the backbone of communicating securely over the internet. When the Netskope Client intercepts the traffic to perform DLP & TSS, certain applications might have adverse effects because of how the application certificates are handled. Hear from our internal security team as they cover: The basics about application certificates and their working How the Netskope Client handles application certificates How to configure the Netskope Client to work with certificate pinned applications How to resolve certain certificate issues by bypassing them For more information, check out our blog post. View past events in this series!
In case you missed the latest webinar in our Inside Netskope series—where Netskope experts show you how we protect our users, applications, and data using our own cloud-based architecture—a recording and recap of our recent session on “Netskope Data Loss Prevention for Sentiment Analysis” can be found below. Feel free to comment and continue the discussion! 📽 Watch on-demand 🍿 Q: If we are creating keywords in English, will the dictionary be captured in all regional languages?A: No, I think it would just be for the keywords which are specified within the framework. So as far as regional languages, we'll have to check internally if we are supporting those. Q: When creating and deploying a DLP policy for AI, can you provide some tips on how to identify false positives in the Alerts?A: It involves extensive analysis of the incidence and forensic data because this is something that is a challenge for us as well whenever we implement a new DLP framework or a policy. So, we take a step by
Hear from our internal security team as they explain how Netskope DLP can be applied for sentiment analysis of user queries in Generative AI web applications. Learn how to: Compile positive and negative words into CSV files, creating dictionaries and DLP rules for these words in the Netskope tenant console Create Realtime policies to perform sentiment analysis on Gen AI categories Identify the intent and thought of users when using Gen AI with policies that check for the overall sentiment of users, whether it is positive or negative Extend this application of DLP profiles to other use cases like detecting social media trolling or abusive messages For more information, check out our blog post. View past events in this series!
Why Certificates and What is Cert-Pinning?In the internet age, it has become mandatory for all organisations and services which are hosted on the internet to rely on certificate based authentication and authorisation in order to protect the confidentiality and integrity of their data accessible and traversing over the internet. Certificates help prove your identity over the internet when communicating with parties/services which you have not interacted with before. As organisations and service providers started heavily relying on certificates for their security needs, they wanted to be sure that there was no chance of data leakage through techniques such as man-in-the-middle attacks. This led to the rise of adoption of the concepts like trusted certificate stores and certificate pinning.Certificate pinning is a security method which protects the service providers against man-in-the-middle attacks. The server/host is associated with a specific certificate or public key and the applicati
The Netskope One Enterprise Browser (NOEB) is a security solution designed to provide security access to sensitive applications and content in specific scenarios. The NOEB enables Netskope One SSE (Secure Service Edge) services such as Secure Web Gateway (SWG), CASB, as well as threat protection and DLP to be extended to cover corporate users with unmanaged/personal devices, as well as non-employee contractors. NOEB leverages the Netskope One platform, with a single policy engine and admin console. It enables organizations to secure access to sensitive applications and content when devices are unmanaged and also when Netskope client services are not running on devices. NOEB can be deployed through MDM solutions and supports automation for installation and profile management. How is NOEB used by the customer zero team?At the customer zero team, we have been involved in designing, implementing and validating security use cases and protection strategies with NOEB. Some of the specific sc
Netskope provides a comprehensive data loss prevention (DLP) enforcement solution for cloud applications and public cloud resources that is ideal for addressing regulatory compliance requirements and protecting sensitive data in your enterprise. In addition to securing traditional confidential and sensitive data on the web, Netskope DLP can also be diversified for some creative data analysis. In this blog post, I would like to share one of the use cases that can be implemented with Netskope DLP, which is sentiment analysis of user queries in Gen AI web apps. Sentiment Analysis is a technique used to determine the overall sentiment expressed in a piece of text, such as a customer review, social media post, or email. Sentiment analysis relies heavily on positively and negatively used words to determine the overall sentiment of textual data. To learn more about this topic, read the following and register for our upcoming webinar—where we’ll cover this live in more detail and answer custom
In case you missed the latest webinar in our Inside Netskope series—where Netskope experts show you how we protect our users, applications, and data using our own cloud-based architecture—a recording and recap of our recent session on “Tracking Client Bypasses with Netskope Endpoint SD-WAN” can be found below. Feel free to comment and continue the discussion! 📽 Watch on-demand 🍿 Q: We are in the process of implementing BWAN functionality in OCC. I would love to understand how we can get rid of bypasses, specifically for cert pinned apps such as ZoomA: Well, there's a couple different things. One, in order to see those bypasses we would have to steer it one way, shape, form, or another. So you're either steering it with the NG SWG traditional Client, steering it with the BWAN client, or you're not steering it at all. If you don't steer it at all, you don't get that visibility or that functionality. So it's really who, what, when, where, and how on being able to monitor as well as use
Hear from our Product Management and Product Adoption leads as they cover the latest platform updates from Release 124, 125, and 126. Key Product Updates: NextGen API Protection Enhancements for Zoom – DLP/TSS support for In-Meeting and Team Chat conversations Retroactive Scan Enhancements – Advanced Scan Filter options based on Time Ranges Next-Gen API – Write Google Labels Support for Customizing SSPM Scoring – Customize SSPM scoring as per your organization requirements Netskope Private Access (NPA) – Explicit Proxy Configuration Support on a Publisher Netskope Private Access (NPA) – Updated Limit for Publishers per Private App Definition Log Streaming – Product capabilities for direct to cloud integrations Explore past webinars in this series!
Hear from our security engineers as they discuss how we use Netskope Endpoint SD-WAN for gaining real-time visibility into bypassed traffic, tracking SSL certificate-pinned applications, and uncovering the roots of "shadow IT" behavior. Learn how to: Use the SD-WAN console to capture and analyze bypass flows Configure AppX policies to flag "interesting" traffic Monitor and investigate SSL-pinned app behavior (including custom and pre-defined apps) Strengthen security posture with intelligent exception handling Leverage this capability for troubleshooting, resource tuning, and forensics For more information, check out our blog post. View past events in this series!
In case you missed the latest webinar in our Inside Netskope series—where Netskope experts show you how we protect our users, applications, and data using our own cloud-based architecture—a recording and recap of our recent session on Client Troubleshooting can be found below. Feel free to comment and continue the discussion! 📽 Watch on-demand 🍿 Q: Is there a solution to force Netskope to switch multiple devices (>100) to a specific POP in case of issues with one POP?A: It is my understanding that our GSLB will detect those issues and reroute you to a new POP very quickly. Q: How to troubleshoot issues with uninstallation process for older Netskope clients? (Netskope client unable to be removed)A: I recommend renaming the folder. After renaming it, you can uninstall the old client. Here is a great troubleshooting guide! Q: How would you go about troubleshooting a Microsoft Teams call performance issue to confirm if Netskope proxy is the root cause or its something else?A: For me,
Hear from our internal security team as they discuss the systematic approach we take at Netskope to diagnose and resolve client issues effectively. Key Topics:Understanding Netskope Client Architecture – How the client interacts with cloud security services and network components. Common Client Issues and Root Causes – Connectivity failures, latency, and policy misconfigurations. Troubleshooting Tools and Logs – Leveraging Netskope Client Debug Logs, Packet Captures, and Browser Developer Tools. Best Practices for Resolution – Steps to address common client-side issues and optimize deployment. DEMO: Using the Netskope Client itself to troubleshoot issues on the OS and applications.For more information, check out our blog post. View past events in this series!
This one is more for my tech partners than for customers. If you tie your idp into your Netskope tenant you would never do this. This is really just for a lab environment. This will create users and groups that you can then use in policy. Create API token for scimGo to Settings > Tools > REST API v2 > New Token Create an API token that has the two scim endpoints added. With the token copied and stored somewhere. Go to API Documentation. Add the token to the Authorize In the scim section use the apis to view and create the users/groups. Adding a userStart by adding the user. Be sure to change the userNamePOST /api/v2/scim/Users{ "schemas": [ "urn:ietf:params:scim:schemas:core:2.0:User" ], "userName": "taylorkelce", "name": { "familyName": "kelce", "givenName": "taylor" }, "active": true, "emails": [ { "value": "taylor@eras.tour", "primary": true } ], "externalId": "User-Ext_id", "meta": { "resourceType": "User" }} Search for your user
Hear from Deepti Hemwani, Director of Product Management, as she demonstrates how to better understand your data landscape, uncover hidden security risks, and enforce security policies to protect your most valuable assets against future threats with Netskope One Data Security Posture Management (DSPM). To learn more, check out our Customer Exclusive DSPM event on-demand!
Many organizations lack a structured and practical approach to enhance their cybersecurity maturity, resulting in inconsistent security practices, increased vulnerability to cyber threats, and difficulty in demonstrating compliance.Organizations often struggle to effectively improve their cybersecurity posture due to the absence of a clear, actionable roadmap. This lack of guidance leads to ad-hoc security measures, gaps in protection, and an inability to measure and track progress. "A Hands-On Guide to Improve Cybersecurity Maturity" addresses this problem by providing a practical framework, such as OpenSAMM, to systematically assess current security practices, identify weaknesses, and implement targeted improvements. This approach enables organizations to move beyond reactive security measures and proactively build a robust and mature cybersecurity program, ultimately reducing risks and enhancing overall security resilience. Understanding OWASP SAMMSAMM stands for Software Assurance
Hear from our internal security team as they discuss the possible settings and changes which can be made in the Netskope tenant to accommodate a lost/stolen corporate managed device. Learn how to: Modify settings in the tenant proactively for lost/stolen device cases in the future Effectively deal with lost/stolen devices by setting up protective measures against device misuse Minimize data loss in case of lost/stolen device cases by blocking data movement from the device Check out our blog for more information!
Hi can someone help me? I have a trining today Security Cloud Operation & Administration (NSCO&A) Training - EMEA (BST) - March 24-26, 2025but the link is not working:Here is your unique link - http://events.netskope.com/nscoa-emea-bst-march24-26/virtual?guest-access-hash=NDU5MTEwMTI5fDc5MDk2ODE3MHwxNzQxOTQyMzA3O2MwMDJmMzY2Nzc5ZGVhNWQxOTA5NGU3OGQ2YTcyZTcxZjE2YmM2N2Q3OTY4OGJhYzA2YzNjMjEzZWU2NjVkY2U%3D thanks
When I was asked to write an article on identifying, troubleshooting, and resolving common Netskope Client-related issues, I initially thought, "Sure! How hard can it be?" However, I quickly realized that troubleshooting is a broad and open-ended topic, varying significantly depending on the specific issues encountered.In this article, we will explore common Netskope Client problems, their root causes, and the best tools and methods to resolve them. These insights align with the key topics we will cover in our live presentation.Those topics are as follows:Understanding Netskope Client Architecture – How the client interacts with cloud security services and network components. Common Client Issues and Root Causes – Connectivity failures, latency, and policy misconfigurations. Troubleshooting Tools and Logs – Leveraging Netskope Client Debug Logs, Packet Captures, and Browser Developer Tools. Best Practices for Resolution – Steps to address common client-side issues and optimize deployme
Deploying Enterprise Browser to your Mac DevicesIntroductionEnterprise Browser allows organizations to provide secure access to sensitive applications & content for unmanaged devices or devices not running the Netskope client. Here at Netskope the Global Information Security and Information Technology teams partnered closely to successfully launch this technology internally. Below you will find instructions on how the IT team deployed this solution to our fleet of Mac devices.Netskope Enterprise Browser application is deployed through Iru/Kandji MDM using a DMG containing a .app file. The deployment process was automated with a pre-install script to audit the app’s presence, download it if needed, and ensure proper installation. Additionally, a bash script handled profile enrollment, enabling a completely zero-touch activation process. This approach significantly streamlined deployment, ensuring minimal user intervention and high success rates. Iru/KandjiIru/Kandji is a purpose-bui
Deploying Netskope Enterprise Browser to your Windows FleetIntroductionEnterprise Browser allows organizations to provide secure access to sensitive applications & content for unmanaged devices or devices not running the Netskope client. Here at Netskope the Global Information Security and Information Technology teams partnered closely to successfully launch this technology internally. Below you will find instructions on how the IT team deployed this solution to our fleet of Windows machines. This method is for deploying with Microsoft Intune. This guide details how to deploy the Netskope Enterprise Browser with auto profile enrollment. Netskope Enterprise Browser profiles are leveraging users' corporate email address and for Entra Joined Windows machines, this allows admins to leverage the UPN to have the browser auto enroll upon deployment. The method described in this guide consists of 2 steps, deploying the installer and config file to the local machine via Win32 Deployment,
In case you missed the latest webinar in our Inside Netskope series—where Netskope experts show you how we protect our users, applications, and data using our own cloud-based architecture—a recording and recap of our recent session on Operationalizing UEBA UCI Alerts can be found below. Feel free to comment and continue the discussion! 📽 Watch on-demand 🍿 Q: How can UEBA be used to detect when someone may be looking to leave the company. Can they automatically be added to a “watch list"?A: This is one of those cool ones. I've always thought UEBA has the potential to predict when someone's leaving the company before they've fully made up their mind.The two custom alerts that Uday talked about are some of the key features. For example, if those types of things start happening where a user is uploading to personal spaces instead of going to the corporate environment, which is not normal for them, this would definitely be a trigger. The automations that Uday talked about when the UCI sco
Hear from our Product Management and Product Adoption leads as they cover the latest platform updates from Release 121, 122, and 123. Key product updates: Automated root cause analysis for DEM User Experience Score Direct Internet Access Application Performance Monitoring via Enterprise Station Support remote access over RDP and SSH without using Netskope client One time password-based disable option for Netskope Client SWG services Integration of Netskope Private Access Client and Publisher with NewEdge Traffic Management API to learn and connect to the closest (by RTT) PoP GA of CloudTAP, capture traffic between a managed endpoint with Netskope Client or branch offices using IPsec or GRE tunnels and the Netskope platform Explore past webinars in this series!
User and Entity Behavior Analytics, UEBA, is a platform used to spot anomalous actions through users behavior. This platform leverages algorithms and machine learning to continuously learn and evolve based on each behavior Our analytics program includes a wide variety of detections to help provide our analysts with the best visibility. Allowing our analyst to get more insight rather than focusing on alerts made in Security Information and Event Management (SIEMs) or Endpoint Detection and Response (EDRs), having the use of UEBA can fill in the void where visibility is lacking. As the security team continues to integrate UEBA within the SOC, it's crucial to understand its functionality and how it operates. All of the information can be reached through Netskope’s user-interface (UI), but for more in-depth information you can check out the online reference information for it here. The benefits of Netskope using UEBA include detecting anomalous insider behavior, identifying unknown data m
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.