Bitglass ICION Webinar
Bitglass ICION Webinar
Bitglass ICION Webinar
Extending Zero Trust Fencing beyond Corp Premises Growing SaaS Footprint – benefits of OpEx & Biz Agility
1 2
3
Problem CASB : Cloud Access Security Broker
Cloud, collaboration and mobility are beyond the firewall...
Unmanaged apps Managed apps
data threat
visibility compliance protection protection
apps, data, users & apps, data, users & in the cloud, at
devices devices access, and on malware, APT,
hijack
devices
Legacy Tech
Firewall
Cloud access security brokers have become an essential element of
Web Proxy any cloud security strategy, helping organizations govern the use of
Security Gaps !! cloud and protect sensitive data in the cloud. Security and risk
IPS / IDS Data leakage & threat risk management leaders concerned about their organizations’ cloud use
DLP should investigate CASBs.
MDM
By 2022, 60% of large enterprises will use a CASB to govern some
cloud services, up from less than 20% today.
Unmanaged devices Managed devices
3 4
Cloud and mobile are beyond the firewall... Bitglass is a Gartner Leader
unmanaged apps managed apps
5 6
1
4/24/20
Case Studies
CASB
DLP, Malware and Sharing control
for data created or existing in cloud
3. Reverse Proxy on any Device services
Real-time security for managed apps;
Access control, visibility and DLP with 2. Forward Proxy on Managed
no agent or change in user experience Devices
Block, coach, Read-only, DLP &
threat protection for managed and
unmanaged apps; Real-time
access control and visibility
7 8
Secure Remote Workers (any app, any device, any network) Secure File Sharing (OneDrive, Box, DropBox, GDrive, S3…)
Challenges Challenges
■ Remote employees at greater cyber risk ■ Poor visibility into data at rest in the cloud in SaaS and IaaS
■ VPN to corporate network is a bottleneck ■ Protect intellectual property leakage
■ Protect against malware
Solution ■ Meet compliance requirements
■ Enable secure access to cloud and on-prem applications
■ Restrict usage of risky applications
■ Enable secure use of personal devices Solution
■ Enforce DLP & threat protection ■ High-performance API scanning, scans finish for large data sets
■ DLP controls, data visibility and data classification
Bitglass Advantage ■ Malware and threat control
■ Real-time security on any device, with or without agents
■ High-performance Polyscale architecture for scalability Bitglass Advantage
■ High-performance Polyscale architecture for scalability
9 10
Secure Productivity Apps (O365, G Suite, Slack...) Secure HCM & ERP (Oracle, Workday, Salesforce, Success Factors, Ultipro…)
Challenges
■ Secure productivity on any device, anywhere Challenges
■ Protect intellectual property from leakage ■ Enable secure access from any device, anywhere
■ Growing cloud footprint with uncertain needs ■ HR & ERP apps are deeply integrated into payroll and internal
business and personnel processes
Solution ■ Visibility, access control and threat protection
■ Agentless AJAX-VM iproxy for any device,
■ Real-time proxy control for managed devices Solution
■ DLP & Malware protection on any device ■ Agentless, inline proxy for unmanaged devices
■ High-performance API scanning for data at rest in the cloud ■ Real-time proxy control for managed devices
■ 3 week rollout ■ Real-time malware protection on any device
■ Seamless integration with enterprise infrastructure
Bitglass Advantage
■ Multi-mode CASB deeply integrated with ecosystem Bitglass Advantage
■ Interoperable with existing infrastructure ■ Secure any app on any device, including custom apps
■ Dynamically handles application updates and changes
■ No change to the User Experience
■ High-performance Polyscale architecture
11 12
2
4/24/20
13 14
Sample Apps Secured at Customers Discover & Control Cloud App Usage
Challenges
■ Poor visibility into cloud application usage
■ Compliance and data leakage risks
Solution
■ Discover and analyze application usage
■ Coach, Block or read-only control of unlicensed apps
Bitglass Advantage
■ Largest index of cloud apps with 600K+ entries, constantly
updated threat intelligence on these and new applications
■ New apps in any language automatically classified
■ Make any app “read-only”
■ Polyscale technology scales globally
15 16
Threat Mitigation ●
●
Integrated with leading IDP
Native SSO & SAML proxy
Identity Visibility
● UEBA (Behavioral Analytics)
17 18
3
4/24/20
Identity Management
Access Control Data Threat ● No vanity URLs, device config, or user experience change Auth MFA
Protection Protection
19 20
Any User,
Any Device
21 22
Managed and Unmanaged Device Control Access Control – IP Address and Predefined locations
23 24
4
4/24/20
Access Control – Two Factor Authentication SSO Landing Page to Cloud Apps for user-1
25 26
SSO Landing Page to Cloud Apps for user-2 Securing Bitglass employees
27 28
Identity Visibility
Next-Gen CASB
29 30
5
4/24/20
31 32
33 34
Flexible DLP Policy options Store private cloud data in public cloud apps
Full-strength security
Advanced remediation - allow without risk
● Alert, Track/Watermark, Encrypt, DRM, Redact, Block ● US Patent 9,047,480
● Read-only/Preview ● Operations-preserving 256-bit AES with 256-bit IV
35 36
6
4/24/20
Data Loss Prevention for Files – Upload Block Data Loss Prevention for Files – Download Encrypt
37 38
Data Loss Prevention for Files – Download Block Data Loss Prevention for Files – Download DRM
39 40
41 42
7
4/24/20
43 44
45 46
47 48
8
4/24/20
Uptime
Visibility & Polyscale Data
Protection
Threat
Protection
99.99%
SLA, Metadata logs, Shadow-IT, CSPM
Identity Visibility
Since 2013
49 50
51 52
Shadow IT Discovery to Unmanaged App Control Cloud Security Posture Management (CSPM)
Discover Shadow IT
53 54
9
4/24/20
55 56
Total Cloud
Q&A
Security
any app
any device
any network
57 58
10