39:51The Impact of Digital Transformation in the Face of Today’s Threats
Download resourcesAbout this session
Nathan Smolenski, head of enterprise security strategy at Netskope, examines how digital transformation and the pandemic-driven shift to remote work have eroded the visibility that security, audit and quality teams once had. With most cloud usage now happening off the corporate network and data sprawling across roughly 2,500 apps in a typical enterprise, he argues that legacy castle-and-moat, data-center-centric architectures can no longer see or control where sensitive data moves. His answer is context: combining signals about the user, device, application instance, activity, threat and content to reach a single policy decision, and coaching users rather than only blocking them. He walks through data-protection, bring-your-own-device and third-party-risk use cases, then makes the case for a network inversion that puts the user, not the data center, at the centre. That model is the secure access service edge (SASE), the convergence of security-as-a-service and network-as-a-service, integrated with identity, endpoint management and automation so controls follow the data to wherever users are working.
Digital Transformation & the rapid need for supporting remote workers for digital business processes took every industry by storm. This change has presented new risks, unlike what companies have seen before, and has created the greatest loss of visibility for security, auditing and quality control professionals since the emergence of the Internet. As companies continue to adopt new technologies like Google Suite, new ways of defending, evaluating, and delivering effective technical control capabilities are required to succeed in what has come to be known as "the new normal."
Key takeaways
- Assume most cloud usage now happens off-network and extend inspection and data controls to remote users instead of relying on the data-center security stack.
- Base access decisions on combined context (user, device, app instance, activity, threat, content), not just a get/put or an allow/block on the URL.
- Use coaching prompts for risky data movements; many users abandon the action when reminded, giving measurable risk reduction without a hard block.
- Score cloud services for third-party risk and write policy against the score rather than maintaining hand-curated allow/deny lists.
- Plan toward a SASE model that converges network and security as a service and integrates identity, endpoint management and automation.