Part 1: Evolution of Trust - Adapting and Utilising CISA’s Zero Trust Maturity Model in an AI World
Education, Training, Certification, and Thought Leadership
Recently active
Multiple users have reported issues with the stability of Zoom, as well as the performance of the application itself. Common complaints or issues relating to audio dropping, audio quality, and screen redraws or slowness painting the screen. Due to these issues, as seen traversing a proxy, it is recommended that Zoom traffic be bypassed and go directly to the destination, at least for real-time traffic. We do recommend using our Next Generation API Data Protection for Zoom. With its current release, audit events, standard user behavior analytics alerts in Skope IT, and DLP alerts may be seen in the tenant. Future improvements to API data protection includes, threat protection, inventory and dashboard remediation actions, and retroscan. Instructions The following instruction set allows you to bypass Zoom traffic using the Netskope Client’s real-time traffic steering method. Go to https://support.zoom.us/hc/en-us/articles/201362683-Zoom-network-firewall-or-proxy-server-setti
Steer It And You Can See It It goes without saying that if you cannot see data exfiltration then you cannot stop it from happening. CASB applications need to be steered in order to be seen, including SSL certificate pinned applications, destination locations, applications (CFW and CASB custom applications), and a few other bypass exceptions. For reference SSL certificate pinning is when a desktop or mobile application validates if the proposed server certificates match the hardcoded ones in the application. It's a security technique used to prevent man-in-the-middle attacks (MITM). We recognize some vendor ssl certificate pinned applications by default which need to be bypassed, Amazon Drive for example. So, in order for end users to use the application without errors resulting, we need to bypass the application traffic and allow it to go directly to the destination. In order for that to occur, we define the application and the hosts or domains to
Netskope Endpoint Data Loss Prevention (Endpoint DLP) provides data protection at the endpoint by utilizing Netskope cloud DLP capabilities. You can use Endpoint DLP to monitor and govern USB storage devices connected to your endpoint. Endpoint DLP is an optional add-on capability to the Netskope Client and does not require deploying and managing a separate client or agent on the endpoint. With Endpoint DLP, you can create Device Control and Content Control policies. Device Control policies enable granular control over which devices are allowed and which users can access them. Whereas, Content Control policies enable the full use of Netskope DLP profiles and rules to inspect and control data movement between an endpoint and a USB mass storage device. To avoid user interaction during deployment, please ensure that full disk access is enabled for all Mac OS systems for which the endpoint DLP service would be deployed. Within the Customer Zero team, we have
There are many things that characterize good security hygiene. One obvious aspect is clearly defined trust boundaries and secure connectivity requirements. Allowing an unmanaged and untrusted device to be directly plugged into a trusted network would significantly violate one of the core tenets of the Zero Trust principle. The truth is, enabling secure connectivity on mobile devices cannot be done in an ad-hoc manner, it must follow a best practice approach in order to be successful. While many internet security and remote access solutions offer a self-service workflow (e.g., go to the App/Play Store, download the client, authenticate, and connect), this can lead to potential risks. Sensitive data could end up on an untrusted and unmanaged device, which could get lost, stolen, or be used for unauthorized access and data exfiltration. This poses a real risk for both internal and SAAS applications, and it raises doubts about the effectiveness of the data protection perimeter. &nbs
In this session, you’ll hear about key use cases to implement protections that stop threats, protect data and identify sources of risk. Our Product Management and Product Adoption Leads will cover the latest platform updates from Release 103, 104, and 105. Key product updates:Generative AI Web Filtering Category ChatGPT App Connector Now Available Efficacy improvements in the DLP ML models New Inline Phishing ML model Printer Device Control for Endpoint DLP UEBA - Rest API integration for UCI scores Advanced Analytics - New SSL Inspection Dashboard Next Gen SSPM & CCI (V2) Next Gen API for Jira & Confluence
Overview This is a short write-up on different approaches and nuances of Netskope Android client (NSClient) deployments, as it differs from, for example, the deployment of the Netskope iOS Client.This post will cover a rather easy and common deployment of steering and protecting certain app traffic to Netskope. This is similar to how iOS enables per-app VPN deployment. If you are interested is the high-level overview of our mobile capabilities, you might want to check out the following blog post: Netskope's capabilities on mobile platforms - The Netskope Community The mentioned functionalities and configuration of the Netskope Android client are described in the documentation center: https://docs.netskope.com/en/netskope-client-supported-os-and-platform.html. When you start deploying the NSClient with a Mobile Device Management (MDM) solution such as VMware Workspace and Microsoft Intune, the NSClient will be installed under the work profile. This is a neat feature in And
Netskope Private Access and Cloud Exchange running in Azure Overview Using Netskope’s Private Access (NPA) can help secure workloads in Azure like deploying Netskope’s Cloud Exchange there. In this solutions guide NPA is used to front end a Cloud Exchange server that doesn’t have direct inbound internet access. Requirements Netskope tenant with a NPA license Azure account Setup Steps Netskope Configure a Netskope Publisher in your Tenant Azure Deploy Virtual Machine Netskope Publisher Cloud Exchange Setting up Cloud Exchange in Azure Deploy Virtual Machine Ubuntu Server Add Access to Cloud Exchange via NPA Setup Cloud Exchange on Ubuntu Server Verify Netskope Tenant sees your publisher Check your client for the NPA tunnel Try to access cloud exchange on your private IP Configure a Netskope Publisher in your Tenant Go to your Netskope Tenant > Settings > Security Cloud Platform > Publishers Click New Publisher
Welcome to the world of Reverse Proxy! Today, I will be your guide on creating a Reverse Proxy as a Service (RPaaS) in Google Workspace. We’ll then apply contextual awareness to “guide” employees to steer traffic to Netskope using RPaaS if they are not originating from a Netskope IP address. This is similar to what we do with Microsoft Azure AD RPaaS and conditional access policies; the contextual awareness is Google’s implementation of conditional access. There are requirements needed for licensing as well as caveats which warrant mentioning. You will need to be licensed for Protect your business with Context-Aware Access - Google Workspace Admin Help . There are a limited number of applications at this point which context awareness works with or for, see pic below. For SAML apps, policy evaluation occurs on sign-in to the app. Third party SAML apps that use Google as the identity provider. A third party identity provider (IdP) can also be used (third party IdP federat
I am excited to start a series of posts covering Netskope for Mobile. This kick-off note will provide an overview of Netskope's capabilities on mobile platforms. In the upcoming posts, I will delve into greater detail on enabling Netskope for both corporate and BYOD devices, enforcing data perimeter on mobile, navigating SSL Inspection and certificate pinning challenges, and many other topics. Why Netskope on Mobile? While there are significant differences in capabilities, user experience, ownership models, and even weight and portability, mobile devices are similar to desktops in that they can be used to browse the internet, access personal and corporate applications, and move data around. Consequently, our information security policies, tools, and procedures are expected to cover both desktop and mobile use cases. Based on my observations, many organizations have significant gaps in their security posture between corporate desktops and mobile platforms, and Netskope can defini
Users are provisioned in three different methods within the tenant-manually adding them, Netskope Tools Directory Importer, or via System for Cross-domain Identity Management (SCIM). SCIM is an open standard designed to manage user identity information. It is possible to use all three methods to provision users to the tenant. However, it is recommended that only one method be used to avoid confusion. As more and more resources migrate to the cloud, it makes sense to use an Identity Provider (IDP) which resides in the cloud as well. SCIM provides a defined schema for representing users and groups, and a RESTful API to run CRUD operations on those user and group resources. This guide provides administrators the ability to migrate from the Netskope Tools Director Importer to SCIM, regardless of the service provider such as Okta or Ping. Netskope Tools Directory Importer Netskope Tools Directory Importer is installed, running, and on the latest
I hope this will just be a pointer to the resource...Is there a repository with more details about what the signatures are. Or a way to see what caused the match? Some of the descriptions are quite vague, and it's hard to determine if an exception should be created.eg: Sig 20019 "MALWARE-CNC User-Agent known malicious user agent - test"
How do you feed the Netskope SSPM Alerts to SaaS Application Administrators? The Netskope Cloud provides a wide range of innovative and competitive products, among which one of the most important offerings should be Netskope SSPM. SSPM stands for SaaS Security Posture Management and is used to continuously monitor cloud-delivered Software-as-a-Service applications. This service monitors the SaaS applications' configuration to ensure that they are configured securely and in compliance with regulations. Security administrators can set policies and receive alerts for SaaS application instances that do not adhere to the required policy. Typically, SaaS application administrators are not part of the company's core security team. Instead, the security team receives the SSPM alerts for all the SaaS applications. These alerts must be forwarded to the respective SaaS application owners so that they can work on remediation. In some cases, the security team might be hesitant to gran
Netskope Administration for Departing Users When a user announces their departure from the organization, it's crucial to implement stringent controls and checks to protect corporate data and resources. The user's account should immediately be placed into a "Leaving Users" group within their Identity Provider or Directory Services. This move should trigger a set of pre-configured policies for these accounts. Critical Policies to be Enabled Restricted Activities: This policy limits certain user activities to prevent potential loss of data: Unable to Delete Files: Prevents the user from unintentionally or maliciously deleting crucial company information. Unable to Share Files to Any Non-Corporate User: Ensures sensitive company data isn't shared externally. Unable to Download from Salesforce: Ensure customer and prospect data from being downloaded. Restricted Instances: This policy confines the user's interaction with certain instances: Unable to Upload any files to Non-
Netskope Administration for Contractors & Third Parties Contractors and third parties often require access to company resources to fulfill their tasks, yet they exist outside the organization's direct control and may not be fully aligned with the company's security culture or protocols. The necessity for elevated or different security protocols for contractors and third parties stems from the unique risks these roles introduce. This document will outline some approaches within Netskope to protect business assets from contractors and third parties. Deployment Modes Forward Proxy (Netskope Client Installed) For contractors or third parties given a managed corporate device with a Netskope Client installed, we recommend using Netskope's Forward Proxy Mode. This mode offers granular control over web traffic and cloud app usage, ensuring secure access and data protection. Pros: Large Scope Access Control: Forward proxies can be used to limit acce
Netskope Administration for Developers While it is necessary to provide adequate security measures in your environment, it's important to be aware of the unique needs of your developers and coders. Their work often involves accessing and interacting with various applications like GitHub, which may lead to issues if proxy services interfere with their work. Here are some recommendations: Bypass SSL Inspection for Specific Applications While not generally recommended, it may be beneficial to bypass SSL Inspection for applications such as GitHub, which developers frequently use. This ensures that developers' traffic is not interfered with during their code creation. Instead, opt to utilize Netskope's API-enabled protection to provide visibility and partial control over the data inside GitHub. Remember that GitHub traffic would be inspected if accessed by anyone outside of the Developers User Group. Deployment Modes To cater to developers' needs, you have
Hybrid work changes the way people use applications. In this video, learn about how Netskope Cloud Firewall delivers the protection you need everywhere your business operates.
Securing administrative access to the Netskope tenant is an important security control. When Single Sign-On (SSO) is not an appropriate choice for some administrators, Multi-Factor Authentication (MFA) should be used. Docs.netskope.com describes the process for enabling MFA for local Netskope admins who are not managed via SSO. The default authenticator is Google Authenticator, but other ones can be used. https://docs.netskope.com/en/multi-factor-authentication-for-netskope-admins.html This article describes how to set up Microsoft Authenticator. 1) Enable MFA on tenant 2) Next time the tenant admin logs into Netskope tenant 3) Tenant admin presented with authenticator setup (note Google Authenticator default) 4) Admin opens Microsoft Authenticator app on device 5) Add Work or school account 6) Scan QR code from Microsoft Authenticator 7) Use Authenticator code when prompted to login to Netsk
Organizations are grappling with the decision to allow or block ChatGPT given the risk of leaking sensitive data. In this video, Bob Gilbert, VP of Security Cloud GTM Strategy and Chief Evangelist, demos how Netskope solutions can help your organization enable safe usage of tools like ChatGPT with active user coaching and data protection.
On May 3rd 2023 Google Registry announced the release of eight new top-level domains (TLD). Two of these domains share the same naming conventions as common file names which are .zip and .mov. These TLDs could pose an increased risk to organizations through the use of social engineering attacks. For example https://github.com/kubernetes/kubernetes/archive/refs/tags/@v1.27.1.zip looks likes a legitimate domain to a GibHub repo to download a .zip file for kubernetes, however the link actually takes you to the domain of v1.27.1.zip. How does Netskope mitigate the threat from these domains? The Netskope platform can help prevent phishing attacks through the use of deep learning for phishing website detection and remote browser isolation which work across all top-level domains. Figure 1: Testing RBI with m365install.zip domain How can Netskope help provide insight into domain usage in an organization’s environment? Even with controls in
With the growing popularity and use of ChatGPT, it is increasingly important to also monitor and secure private details and company confidential information from being shared with ChatGPT. As the Customer Zer0 team (CISO group), we have implemented some DLP rules for ChatGPT. Please note that currently, Netskope does not yet have a predefined connector for ChatGPT. We would hence need to create a custom connector so that DLP rules can be applied instead of an outright block to the webapp. We want our users to continue to use ChatGPT with discretion in an enterprise environment. This custom connector can be built from HAR logs. Here’s what we have in place: Realtime policy The Netskope chatgpt custom DLP profile contains the ‘netskope’ keyword. Results and end-user experience In this example, DLP source code classifier is getting triggered, and hence the question is not being posted to ChatGPT. PII and PCI data being blocked from getting poste
In this demo, learn about basic Advanced Analytics concepts and start building a dashboard from Explore. Do you want to see demos of other Advanced Analytics use cases? Leave a comment and let us know.
Netskope experts Parag Thakore and Muhammad Abid will discuss how the enterprise architecture is at a crossroads, and how it must evolve to converge network and security at every edge. They’ll talk about how Netskope SASE makes no sacrifices on network performance or security protection and helps organizations to consolidate products, reduce costs, and simplify operations. What you’ll learn:How Netskope SASE delivers consistent performance and security for any user, app, device, cloud or site. How Borderless SD-WAN addresses multiple use cases with a single lightweight software. How to implement a truly converged platform that simplifies operations and reduces costs. Get answers to all of your toughest questions on SASE and future-state architecture.
The Netskope SMTP Proxy can be used as a service to scan outgoing emails over SMTP for DLP violations. In this solution, an email initiated by the user is received by a cloud email service such as MS O365 Exchange or Gmail. The email is then passed through the Netskope SMTP Proxy integrated into your SMTP workflow. Netskope SMTP Proxy verifies the contents of the email against Real-time Protection policies and acts on DLP violations based on the policy configuration. The email is then passed on to an upstream MTA which looks up the DNS of the destination email service and sends the email to the recipient's server. As the Customer Zer0 team (CISO group), we implement SMTP proxy for our Gmail corporate instance and have been implementing DLP rules to monitor and control the movement of sensitive and confidential internal only emails to non-Netskope email addresses. Netskope Configuration Workflow Ensure SMTP proxy is configured on your Netskope tenant: https://
Steps That Should be Taken by the Security Group, Business Continuity, and Finance Teams Introduction On Friday, March 10, 2023 news broke that SVB was in trouble. With this news, activities started within our organization to understand our direct exposure. As with any event what we have learned over time is that fraudsters are quick. This rang true with Silicon Valley Bank (SVB). At that point cybersecurity, third-party risk, and business continuity were not included. When these situations arise, it’s important to ask questions like, what if your company was hit with a bank fraud event like SVB Bank? Are you prepared? Do you know what steps to take before, during and after the event? In this document we want to share a few things we learned from the SVB event and how those learnings could help you in your business. Our first step when the news broke was to look inward. The financial and accounting teams looked at how SVB Bank impacted us directly. Whil
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.