This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

SASE: New Reality and Cloud Security

Download resources

About this session

Nico Popp, chief product officer at Forcepoint, makes the case that cloud security is converging on SASE, the Gartner-coined secure access service edge. He gives three arguments: network security has always consolidated (firewall to UTM to next-generation firewall) and will do so again in the cloud; the industry is moving from on-prem point products through cloud pure plays to platforms; and the pandemic put users at home and applications in SaaS, so backhauling traffic to an on-prem stack no longer makes sense. He then describes SASE's four jobs, his 'four horsemen', through the story of an employee working from home: threat protection with a cloud web gateway, firewall as a service, sandboxing and remote browser isolation; secure access through a global edge, an intelligent agent, SD-WAN, CASB and zero trust network access as a VPN replacement; data protection with DLP both in the cloud and on the endpoint, since printing at home is now a problem; and continuous trust assessment, where a real-time user risk score drives DLP, CASB and access policy. Three product demos and an overview of Forcepoint's July launches close the talk.

In the last 5 years, the world of IT has moved to the cloud. Business application have moved to the cloud with Salesforce and O365. Storage has moved to the cloud with Box and Dropbox. Our data centers have moved to the cloud with AWS and Azure.

With the pandemic, our employees have moved to the cloud work from a branch office of one called “home”! When everything moves to the cloud, so must cyber security. Only one question remains: What does security in the cloud really look like? 

Key takeaways

  • If users are at home and applications are in SaaS, put the security stack in the cloud rather than backhauling traffic to an on-prem gateway.
  • Use remote browser isolation for uncategorised or risky sites instead of a flat block; the page runs in the cloud and active content never reaches the endpoint.
  • Replace per-user VPN tunnels with zero trust network access: users reach on-prem apps through the browser with least privilege, MFA and DLP applied, and the VPN concentrator stops being the bottleneck.
  • DLP in the cloud is not enough once data lands at home; an endpoint agent has to control printing and copying to personal storage as well.
  • Feed a continuous user risk score back into the control points so that a risky user is automatically limited in what they can download, reach or open.

Speakers

Nico Popp
Nico Popp
Forcepoint

Resources

Tags

More from GoSec 2020

Also from Nico Popp

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.