close
close
Your Network of Tomorrow
Your Network of Tomorrow
Plan your path toward a faster, more secure, and more resilient network designed for the applications and users that you support.
          Experience Netskope
          Get Hands-on With the Netskope Platform
          Here's your chance to experience the Netskope One single-cloud platform first-hand. Sign up for self-paced, hands-on labs, join us for monthly live product demos, take a free test drive of Netskope Private Access, or join us for a live, instructor-led workshops.
            A Leader in SSE. Now a Leader in Single-Vendor SASE.
            A Leader in SSE. Now a Leader in Single-Vendor SASE.
            Netskope debuts as a Leader in the Gartner® Magic Quadrant™ for Single-Vendor SASE
              Securing Generative AI for Dummies
              Securing Generative AI for Dummies
              Learn how your organization can balance the innovative potential of generative AI with robust data security practices.
                Modern data loss prevention (DLP) for Dummies eBook
                Modern Data Loss Prevention (DLP) for Dummies
                Get tips and tricks for transitioning to a cloud-delivered DLP.
                  Modern SD-WAN for SASE Dummies Book
                  Modern SD-WAN for SASE Dummies
                  Stop playing catch up with your networking architecture
                    Understanding where the risk lies
                    Advanced Analytics transforms the way security operations teams apply data-driven insights to implement better policies. With Advanced Analytics, you can identify trends, zero in on areas of concern and use the data to take action.
                        The 6 Most Compelling Use Cases for Complete Legacy VPN Replacement
                        The 6 Most Compelling Use Cases for Complete Legacy VPN Replacement
                        Netskope One Private Access is the only solution that allows you to retire your VPN for good.
                          Colgate-Palmolive Safeguards its "Intellectual Property” with Smart and Adaptable Data Protection
                          Colgate-Palmolive Safeguards its "Intellectual Property” with Smart and Adaptable Data Protection
                            Netskope GovCloud
                            Netskope achieves FedRAMP High Authorization
                            Choose Netskope GovCloud to accelerate your agency’s transformation.
                              Let's Do Great Things Together
                              Netskope’s partner-centric go-to-market strategy enables our partners to maximize their growth and profitability while transforming enterprise security.
                                Netskope solutions
                                Netskope Cloud Exchange
                                Netskope Cloud Exchange (CE) provides customers with powerful integration tools to leverage investments across their security posture.
                                  Netskope Technical Support
                                  Netskope Technical Support
                                  Our qualified support engineers are located worldwide and have diverse backgrounds in cloud security, networking, virtualization, content delivery, and software development, ensuring timely and quality technical assistance
                                    Netskope video
                                    Netskope Training
                                    Netskope training will help you become a cloud security expert. We are here to help you secure your digital transformation journey and make the most of your cloud, web, and private applications.

                                      What is SSE? Security Service Edge

                                      SSE, or Security Service Edge, is a framework that integrates multiple security services like secure web gateways, cloud access security brokers, and zero trust network access. It aims to secure user access to the internet, cloud services, and private applications, regardless of user location.
                                      Security Service Edge
                                      6 min read

                                      What is the definition of Security Service Edge (SSE)? link link

                                      SSE, as defined by Gartner, is an evolving stack of different cloud-based security tools including:

                                      These tools are one half of a SASE architecture, which is the convergence of networking and security tools within a cloud infrastructure.

                                       

                                      What's the difference between SASE and SSE? link link

                                       

                                      But let’s zoom out a little bit and understand what needs to happen with SSE security beyond the discussion of core technology requirements. We love our acronyms in tech, and we see the eyes roll and hear the sighs when we meet with customers and partners and are asked to describe Netskope’s position regarding yet another acronym—SSE—and its relevance to the bigger stories around SASE and Zero Trust. We like to steer this SSE conversation into a useful discussion of what SSE services will allow us to do, when properly implemented.

                                      SaaS Security Posture Management definition


                                      Blog: Understanding Security Service Edge and SASE


                                       

                                      What are the four core security service edge components? link link

                                      1. Security must track data from various sources
                                      2. Security must be able to decode and analyze cloud traffic
                                      3. Security must provide adaptive data access
                                      4. Security can’t slow down the network

                                      The early era of cybersecurity relied on firewalls, on-premises web proxies, sandboxing, SIEMs, and endpoint security, all of which aren’t equipped for a cloud-dominated space. These days more and more data is moving outside the network perimeter, beyond the reach of firewalls which aren’t equipped to read cloud traffic anyway. Couple this with the growing number of endpoints connecting to enterprise networks are BYOD. In totality, you have a recipe for extremely unreliable oversight of company data.

                                      For example, safe usage of generative AI, such as the wildly popular ChatGPT app, requires an application connector to enable real-time user coaching, data protection of what is uploaded, and application activity controls.

                                      If we usefully organize how the SSE platform solves what security must do in this newer world of keeping data safe in the cloud, several principles guide our discussion.

                                      SSE Component #1: Security must track data from various sources
                                      We now have lots of traffic that a traditional web proxy or firewall can’t understand, and can’t really even see. We have users who are now everywhere, apps that are in multiple clouds, and data being accessed from anywhere. Given this, you have to have a security inspection point that follows data everywhere it goes. And if that inspection point non-negotiably needs to follow the data, that means the inspection point needs to be in the cloud so that its benefits can be delivered to users and delivered to the apps.

                                      SSE Component #2: Security must be able to decode and analyze cloud traffic
                                      Decoding cloud traffic means security must be able to see and interpret API JSON traffic, which web proxies and firewalls can’t do.

                                      SSE Component #3: Security must provide adaptive data access
                                      We must go beyond merely controlling who has access to information and move toward continuous, real-time access and policy controls that adapt on an ongoing basis based on a number of factors, including the users themselves, the devices they’re operating, the apps they’re accessing, activity, app instance (company vs personal), data sensitivity, environmental signals like geo-location and time of day, and the threats that are present. All of this is part of understanding, in real-time, the context with which they’re attempting to access data.

                                      SSE Component #4: Security can’t slow down the network
                                      The user needs to get their data fast, and the network has to be reliable. If security is slowing down access or operability, productivity suffers, and teams dangerously begin trading off security controls for network speed and reliability. One might think that this is as simple as moving the security controls to the cloud. It’s not as simple as that. Ultimately the cloud ends up traversing a dirty place—called the internet— that can cause a whole slew of issues in routing and exposure. This is where private networks come into play so that we can ensure a smooth and efficient path from the end user to their destination, and back again.


                                      Learn More: What is a CASB?


                                       

                                      SSE Security is all about getting leverage back link link

                                      Because of all these needs, your traditional perimeter has disappeared, and you have to move your inspection point. An SSE architecture provides that inspection point—or rather, many distributed inspection points that get as close as possible to where and how data is accessed, whether it’s in the cloud or a private application.

                                      This has profound implications for how you design security and infrastructure, and why we now need SSE and SASE to help us get organized. Think of it this way: if 90 percent of your security spend is for on-premises-focused security, but 50 percent of your apps and 90 percent of your users are off-premises, your security is already being stretched like a rubber band. You’re trying to pull security from the on-premises model into all of these other things it wasn’t designed for, creating tension for the business and leading to an eventual snap of that rubber band, breaking your security. That won’t work.

                                      You will also notice, in the four principles listed above, that the last principle references the network. Too often, we’ve historically had network conversations to address security problems, and that was because we often assumed that our data was on our network and that network was safe. But now, our data is not on our network, and our users are not on our network. This doesn’t obviate the need for network security or marginalize the importance of things like access control. It just means that some of the lines are blurring and we need to account for that.

                                      With Netskope SSE cyber security, your internet inspection points are in place, you’re consolidating your cloud and web and data inspection capabilities, and, crucially, all of those inspection capabilities are firing off atomically—all at the same time, not sequentially or one at a time. If you want to learn more about Netskope’s SSE security capabilities and how they work into a SASE architecture, check out our rundown of the Netskope Security Cloud. You can learn all about Netskope SSE, as well as the individual SSE components that make up the security half of the Secure Access Service Edge.


                                      Solution brief: Netskope Security Service Edge (SSE)
                                      Blog: Netskope Real-time Threat Protection and AV-TEST Results
                                      eBook: Designing a SASE Architecture for Dummies


                                       

                                      plus image
                                      Gartner report

                                      Netskope debuts as a Leader in the Gartner® Magic Quadrant™ for Single-Vendor Secure Access Service Edge

                                      Single-Vendor SASE delivers multiple converged-network and security-as-a-service capabilities, combining software-defined wide-area network (SD-WAN) with Security Service Edge (SSE) components such as secure web gateway (SWG), cloud access security broker (CASB), network firewalling and zero trust network access (ZTNA). These offerings use a cloud-centric architecture and are delivered by one vendor.

                                       

                                      In the new report, find out why Netskope debuted as a Leader. You will also get an understanding of:

                                      • The broad market trends driving adoption of SASE
                                      • The criteria used to position vendors within the Magic Quadrant
                                      • The approach taken by vendors when converging network and security services into a Single-Vendor SASE offering
                                      Netskope debuts as a Leader in the Gartner® Magic Quadrant™ for Single-Vendor Secure Access Service Edge
                                      OSZAR »