Part 1: Evolution of Trust - Adapting and Utilising CISA’s Zero Trust Maturity Model in an AI World
Education, Training, Certification, and Thought Leadership
Recently active
How do you create a "shadow" group that is only located in the tenant, not reliant on an IDP? Add the group to the SCIM database directly using Postman or similar method and/or tool. The use case in this instance is to create a group that is specific only to the tenant and "hidden" from the sight of others who are not Netskope tenant admins. A good example of this is creating a group which contains users who should be in an "offboarding" group, but are also members of the team who manages the IDP, i.e. Okta, that is set to provision users and groups to the tenant. This will only apply to users who are provisioned to the tenant via SCIM from an IDP such as Okta. It cannot and should not be used when users are provisioned to the tenant using the Netskope Directory Importer or manually added to the tenant. A high level overview of meeting this use case are: Download and install the Postman application; Import a Postman Collection for Netskope SCIM; Create a "shadow" group using Pos
In this session, you’ll hear about key use cases to implement protections that stop threats, protect data and identify sources of risk. Our Product Management and Customer Experience team will cover the latest platform updates from Release 100, 101, and 102. Key product updates include: Extended DLP capabilities to on-prem email via Netskope SMTP Proxy Expanded CASB coverage with new API functionality for Zoom Team Chat, Atlassian (JIRA/Confluence), and ServiceNow, as well as Security Posture Management (SSPM) coverage for Microsoft SharePoint, Exchange Online, and Salesforce Increased context awareness with UEBA for User Confidence Index (UCI) and improved app request workflow in Cloud Confidence Index (CCI) Enhanced threat protection with digital rights enforcement in Netskope RBI and defense against C2 attacker traffic via Netskope Intrusion Prevention Improved the Netskope Client user experience with optimal gateway selection improvements and Linux OS support
On March 29, 2023, a number of security companies were warned about harmful activity that was traced back to a legitimate binary file from the communication technology firm 3CX. The file, called 3CXDesktopApp, is a popular video-conferencing software that can be downloaded on different platforms. Several analyses have attributed the threat campaign to state-sponsored threat actors, and security firms have observed malicious activity in both Windows and Mac environments. On Thursday, March 30th, 3CX confirmed that multiple versions of its desktop app for Windows and macOS were affected by a supply chain attack. The version numbers include 18.12.407 and 18.12.416 for Windows and 18.11.1213, 18.12.402, 18.12.407, and 18.12.416 for macOS. This post will describe how to use Netskope to identify possible indicators of use (IOUs) of the 3CX desktop app, indicators of compromise (IOCs), and how to mitigate any further malicious activity. Indicators of Use If you are uncertain about the u
Salesforce is an enterprise cloud computing company that provides business software on a subscription basis. The company provides on-demand customer relationship management (CRM) solutions such as Sales Cloud, Service Cloud, Data Cloud, Collaboration Cloud, and Custom Cloud. As the Customer Zero team (CISO group), we are currently monitoring and securing access to Salesforce internally with a breadth of products that are developed and maintained by the development and QA teams. These capabilities include areas such as client enforcement, inline protection, API-enabled protection, SaaS security posture management (SSPM), and Cloud Firewall, to name a few. In this guide, we will provide a perspective of how Netskope’s products and capabilities are used internally for securing enterprise data. Real-time Protection We are restricting access to the Salesforce app for Netskope employees through client enforcement, whereby access to Salesforce would be granted only if users are connect
Are you planning for a Shift Left approach for your security architecture? This document provides practical guidance on “Shift Left”, its approach and applicability towards enterprise wide security architecture and governance, covering both the corporate and product lifecycle. In this document we will talk about the Common Architecture Criteria (CAC) as a framework to apply at the architecture, design, and implementation layers such that Shift Left helps drive a concise and consistent approach across onboarding third-party applications or developing and deploying internal applications early on throughout the lifecycle that provides multiple benefits such as architecture optimization, operational efficiency, faster delivery, and more. Shift Left principle: The Shift Left principle advocates identifying and shifting tasks as early as possible into the lifecycle, which in turn helps for better planning and execution translating into better quality and workflow optimizations. T
The Netskope Threat Exchange module within Cloud Exchange is our open source solution to IoC sharing between security tools. Once configured, Threat Exchange can store and share thousands of IoC’s from tools such as Netskope, CrowdStrike, Microsoft Defender, ThreatConnect and many others, alongside the capability of adding IoC’s via Cloud Exchange’s API. The large amount of data pulled can be overwhelming, so we wanted to share some best practices for Threat Exchange that you can follow and use within your own environment. Refine Your Business Rules. Your business rules are one of the most important aspects of your Threat Exchange instance since they are used for your sharing configurations. Unless you want everything being shared over to your set of configured tools, you will need to refine your business rules to the specific items you want to send. You can leverage fields found within the IoC’s you pull. For example, some plugins will allow you to pull severity information from t
PostgreSQL is the world’s most advanced enterprise-class open source database management system that is developed by the PostgreSQL Global Development Group. It is a powerful and highly-extensible object-relational SQL (Structured Query Language) database system popular for its reliability, feature robustness, and high performance. It is known to be highly scalable, both in the amount of data it can store and manage and in the number of concurrent users it can accommodate. How does it work? PostgreSQL uses a client-server model where the client and the server can reside on different hosts in a networked environment. The server program manages the database files, accepts connections to the database from client applications. It can handle multiple concurrent connections from clients by “forking” a new process for each connection. It executes database requests from clients and sends the results back to the clients. Remote clients can connect over the network or internet to the serv
Netskope Alerts via Slack Messages Prerequisites: Slack channel with a webhook.https://slack.com/help/articles/115005265063-Incoming-webhooks-for-Slack Cloud Exchange version 3.2 and above. Netskope Tenant added to Cloud Exchange. Procedure: Step 1. Netskope ITSM (CTO) Plugin Setup (skip to step 2 if already setup): Login to Cloud Exchange as a user with admin privileges. Navigate to Settings > Plugins. Click on the Netskope ITSM (CTO) plugin. Name the configuration and set the tenant field to the Netskope tenant you want to receive alerts from. Click Next. Navigate to Ticket Orchestrator and click on Alerts. Make sure the section is being populated with alert data from the configured tenant. Step 2. Notifier Plugin for Slack Webhook (CTO) Setup: Navigate to Settings > Plugins. Click on the Notifier (CTO) plugin. Name the configuration and set the sync interval. The default of 60 minutes is recommended, but for
Are you facing excessive Netskope DLP alerts which are false positives? The Netskope DLP solution provides a wide range of capabilities for detecting data theft and data mishandling. While setting up these policies, one of the common difficulties a security team faces is applying proper allowlisting mechanisms to reduce the amount of false positives. Luckily, the Netskope DLP solution has native effective ways that help allowlist certain applications, instances, users, and activities. Here are a some of those approaches to consider: Exclude certain external domains from within API data protection policy: This option helps analysts to exclude permitted vendors and partners from a particular API protection DLP policy. For example, an organization may be allowed to share sensitive financial information with its financial consulting firm. So the PCI DLP policy could exclude that particular domain/site for the “External Share” policy. The list of applications supporting this feature
In this session, you’ll hear about key use cases to implement protections that stop threats, protect data and identify sources of risk. The Product Management and Customer Experience team will cover the latest platform updates from Release 97, 98, and 99. What you'll learn: New Advanced controls that leverage context gathered via API’s and make it available for Inline enforcement, along with extended coverage for Instance based access control New API’s to programmatically leverage CCI as the centralized app risk database in SOC orchestration workflows Enhanced policy controls across DLP, Threat and UEBA for granular controls and high fidelity detections Enhanced Netskope client with support for Linux platform Granular policy controls with application discovery and ability to tag applications Prevent data exfiltration and phishing protection with the ability to make an isolated website (RBI) read-onlyQuarterly Product Release Update - December 2022
In the previous blog post I have reviewed the "what", "why" and "how" about Netskope Private Access and Windows Autopilot. What was missing is the actual visualization of the true user experience - in less than 10 mins we can turn factory default device into full business ready state fully secured by Netskope! Demo - Windows Autopilot and Netskope Private Access
This is an educational webinar focused on how organizations can benefit from a single-vendor SASE provider. Organizations looking for maturity among single-vendor providers of SASE should ensure advanced data protection capabilities, context-aware web and cloud security capabilities, and other differentiating offers are in place before they consolidate their vendor partnerships too narrowly.
Requirements Transaction Streaming SKU What is Threat Hunting? Threat hunting is the process of using the scientific method to proactively and iteratively search through an organization's environment to identify threats that have evaded detection. One of the goals of threat hunting is to enrich and automate detection that is unique to an organization's environment. Additionally your team builds knowledge of your organization's environment, understanding the gaps and further enriching your security solutions. This document is to help you understand the basic process of threat hunting using data logged with Netskope. We have included an example of a threat hunt. The Hunting Loop Figure 1: The Hunting Loop Hypothesis A threat hunt starts with a hypothesis that should be realistic for your environment. We recommend reviewing research articles on the threats you want to hunt to assist with hypothesis generation and avoid hunti
This new “Notification portal” provides customers an early access, easy to consume view into product changes coming in the next Release and changes being released as part of dynamic updates that are not part of the regular release cycle. These changes can affect enforcement outcomes and an early access view gives customers sufficient time to plan for config optimisations. The Portal provides a view of:- -Future/Upcoming Release (For Example You can see changes coming in R100 on the portal now.)-Weekly Changes (These are changes pushed as part of dynamic updates on a weekly cadence.)-Current Release (For reference in case the user has missed changes in the current release.)-Previous Release (For historical reference.) Customer must use their Netskope Support account to access this portal. In the current version notification portal provides the ability to view product updates/changes to App Connector, App Category and CCI. The portal also provides the abili
Help upper management digest the key performance indicators of your organization's security program using this dashboard from the Advanced Analytics Library. For a list of other videos on Advanced Analytics, visit the community
Hi How can I become a Cloud Security Sales Associate ? Still there is the certification of level entry ? Thank you !
Hello good afternoon, I hope everyone is very well We need to prepare for the Netskope Certified Cloud Security Administrator NCCSA certification. Does anyone have any material, tips, study suggestions, share some of your experience with the exam and also does anyone know if there is any official guide for the certification by Netskope? Thank you very much I remain attentive Best regards
In this session, you’ll hear about key use cases to implement protections that stop threats, protect data and identify sources of risk. The Product Management and Customer Experience team will cover the latest platform updates from Release 94, 95, and 96. What you'll learn:Increase your visibility and control over some of the most popular SaaS applications with improved tenant and instance awareness, as well as new application and app activity support. Extend support for the latest OS and hardware platforms with a Netskope Private Access publisher support for Ubuntu and Netskope Client support for Apple Silicon M1 chips. Improve your threat protection capabilities with broader sandboxing support, web security policy enhancements, and new alert types.
Do you have existing reports that you would like to replicate in Advanced Analytics. Take a look at this video from Mary Zhang to help you get an understanding on how to make the transition.
Solution Overview Windows Autopilot Overview Traditionally IT administrators spend a lot of time on building and customizing OS images, compatibility testing with various device makes and models etc. Every device typically goes through a re-imaging process with additional pre and post validation to make sure it is ready for use in the field. This process implies major cost and time effort. Windows Autopilot is a collection of Microsoft technologies working in concert that help to simplify and streamline the bulk deployment, setup, and configuration of Windows 10/11 devices in organization to ensure they are provisioned and locked down according to corporate standards. Autopilot also can be used for device reset, repurpose and recovery. The following diagram shows a process overview of a typical device procurement and onboarding lifecycle: Windows Autopilot enables customers to: Recognize company owned devices and associate them with appropriate enrol
Enabling hybrid work is key to retaining and recruiting talent. Zero Trust Network Access (ZTNA) enables employees using any device to access desired resources to make them productive no matter where they work. In this webinar, we dive into the Netskope’s ZTNA offering, Netskope Private Access, and review its key capabilities, architecture, sample use cases such as Microsoft Autopilot integration, and new features including API for automation and pre-logon capabilities. Learn how you can:Enable access for employees and contractors (without losing control) Remotely onboard new devices including active directory and autopilot integration Secure access to applications deployed in public clouds Rapidly onboard new applications and locations
What is attack surface management? Attack surface management (ASM) is the continued discovery, classification, and monitoring of an organization's external assets. It is crucial that teams leverage the hacker mindset to look for attack vectors into the organization when performing ASM in order to prioritize the most risk prone assets for remediation. To get the most out of an ASM program, teams should leverage tactics techniques and procedures (TTP) in use by threat actors. Not only is this good practice to develop the hacker mindset but also determine the hygiene of the current security implemented by the organization. Risk in ASM typically comes from three common areas which are vulnerabilities, misconfigurations, and weak/default credentials. The goals of attack surface management are identifying and gauging the risk, and reducing the attack surface. Attack surface management aims to find what assets are being exposed by the applications, networks, and devices in your e
This is the second part of a two part video series. In this video, continue learning about dashboards and widgets using the tools in Explore. To see more videos, visit the community page.
Introduction I am super excited to announce that the Netskope security cloud can now be managed as code. "How is this possible?", you might ask. The answer is by using the newly released Terraform provider for Netskope. This has been in the works for some time now and is the first time our SSE platform has been integrated directly into an Infrastructure as Code tool. This will allow customers and partners to automate deployment of Netskope resources using Terraform. By taking a "Netskope as Code" strategy customers will be able to easily create, modify, and delete infrastructure inside of the platform. This first release has support for our ZTNA solution (Netskope Private Access or NPA) and includes resources and data sources for Private Access Publishers and Applications. Get ready to supercharge your NPA deployment by creating a simple, repeatable automated configuration. What is "Infrastructure as Code" and why Terraform Infrastructure as Code (IaC) is
Hey Community, Just wondering how can I earn the credential of Netskope Certified Cloud Security Architect. I already have Netskope Cloud Security Administrator, Integrator, and Specialist Certifications. Wondering how can I earn that credential and what are the trainings for same to learn more in depth for this great cloud security solution.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.