How the combination of zero trust and SASE strengthens your security posture
Download resourcesAbout this session
Bob Gilbert, VP of strategy and chief evangelist at Netskope, argues that combining Secure Access Service Edge (SASE) with zero trust is now necessary because most users, apps and data sit outside the corporate network, SaaS traffic (including Microsoft 365) has become the dominant malware delivery path, and legacy VPN hairpinning wrecks performance. He frames SASE around four principles: security must follow data everywhere, performance must follow the user, protection must be AI-powered to catch fake login pages threat intelligence has not seen yet, and access should rely on continuous adaptive trust rather than one-time verification, using an Alcatraz analogy to argue even trusted insiders need ongoing scrutiny. A live demo of the Netskope One platform walks through five scenarios: replacing VPN with zero trust network access, distinguishing a corporate from a personal ChatGPT login before allowing source-code uploads, blocking uploads to a low-trust app while redirecting to an approved alternative, flagging a Slack channel with an external member before a sensitive file is shared, and restricting a Salesforce user with a poor behavioral-trust score, plus AI detection of screenshots and ID documents pasted into personal email. Q&A covers customer examples, BYOD, Active Directory's role, and pricing versus Cisco Umbrella.
The shift to the cloud, the transition to remote work, and digital transformation render legacy, datacenter-centric security architectures ineffective in defending against threats, protecting sensitive data, and ensuring that users have unfettered access to the resources they need to get their work done. Join this session to learn about a more practical approach to security that combines Secure Access Service Edge (SASE) and zero trust principle alignment to ensure security controls follow the data and app performance follows the user.
Key takeaways
- Stop trusting SaaS traffic by default; Microsoft 365 and other trusted channels are now the primary malware delivery path precisely because they often go uninspected.
- Replace VPN and data-center hairpinning with zero trust network access, which connects verified users directly to a specific application rather than to the broader network, removing lateral-movement risk.
- Distinguish personal from corporate logins to the same SaaS domain (e.g. two ChatGPT sessions) before allowing sensitive uploads like source code, rather than blocking or allowing the whole domain.
- Score third-party apps against a trust database (such as the Cloud Security Alliance Cloud Controls Matrix) and redirect users to an approved alternative instead of only blocking risky destinations.
- Use real-time coaching, warnings, justification prompts, or an accept-risk option, instead of a flat block, so users become part of the security decision rather than working around it.
Speakers

I am on a relentless mission to empower organizations to fortify their security and networking infrastructure, equipping them to thrive in a dynamically evolving world. My expertise lies at the intersection of Security Service Edge (SSE), Secure… Read moreRead less
I am on a relentless mission to empower organizations to fortify their security and networking infrastructure, equipping them to thrive in a dynamically evolving world. My expertise lies at the intersection of Security Service Edge (SSE), Secure Access Service Edge (SASE), and Zero Trust frameworks. I combine hands-on technical experience with my ability to illustrate a positive business impact. Over the past couple of decades, I have established myself as an influential speaker, captivating presenter, and skilled product demonstrator, engaging live audiences across 50+ countries. I have a fervent passion for education, teaching cybersecurity courses at ESADE's International Business School, and serving as a guest lecturer for the University of San Francisco's MBA program for the past several years. Throughout my 25 plus year career in Silicon Valley, I have held strategic leadership roles in product marketing and product management and I have a proven track record of helping companies like Netskope and Riverbed go from early stage with zero revenue to market leaders with market caps in the billions. My fascination with cybersecurity began in the 1980s when, as a teenager, I hosted a popular Bulletin Board System (BBS) from my parents' living room. It was then that I developed a firewall tool to safeguard my site from potential hackers, sparking a lifelong passion for protecting digital assets and shaping the future of cybersecurity.
