Skyhigh Security Security Service Edge (SSE)
Skyhigh Security Security Service Edge (SSE)
Skyhigh Security
Security Service Edge (SSE)
The SSE security service empowering cloud transformation
1
SOLUTION BRIEF
Corporate Network
Network Security
Applications
Appliances
Private
VPN Tunnels
Cloud
MPLS Lines
Internet
Traffic Flow
Accelerate Your SSE Adoption with Our Skyhigh Security’s cloud-native Hyperscale
SSE Integrated Security Service Edge Service Edge—which processes your traffic for
Solution unauthorized access, data risk, and threats from
Security Service Edge (SSE) — anywhere in the world—and then directly to the
defined by Gartner2— is a Skyhigh Security SSE solution is the SSE security
cloud, eliminating the need to route traffic
collection of integrated, cloud- fabric that delivers data and threat protection to
through your data center and back out.
centric security capabilities that any location, so you can enable fast and secure
facilitates safe access to direct-to-internet access for your distributed • By transforming to a cloud-delivered SSE that
websites, cloud, and workforce. converges connectivity and security,
applications. The SSE framework organizations are then able to reduce cost and
As digital transformation creates a shift for
converges all security services, complexity while increasing the speed and
organizations to “Work from Anywhere,” enabling
including Secure Web Gateway, agility of the workforce.
fast and secure access for your remote workers to
Cloud Access Security Broker, your internal apps and data is crucial. With access • An SSE architecture delivers complete
and Zero Trust Network Access, delivered from a secure service edge, you can visibility and control over data at every policy
into a single, cloud-native protect users and data in new ways; from full decision point, whether it be at the endpoint,
framework. This integrated visibility over remote worker traffic, to unmanaged through the web, or in the cloud.
approach supports the digital device control, and cloud-native activity • Threat protection controls that adapt to
business transformation and monitoring. changes in risk and context allow for
workforce mobility, while
Unlock direct internet access by seamlessly protection against even the most
minimizing the impact on
routing office locations and remote users through sophisticated cyberattacks and data loss.
security performance,
complexity, and cost.
Cloud Apps
Mult
tion i-V Pervasive DLP Across
tec ec Endpoint, Cloud and Web
Figure 2. Security Service Edge User & Entity Behavior ro
Analytics (UEBA) Real-Time Collaboration
to
tP
Control
rD
rea
Head Quarters
Deliver SSE with Skyhigh Security SSE The capability to provide the fastest access to
cloud applications possible, often outperforming
SD-WAN can transform your network with
direct-to-cloud access.
greater simplicity, cost effectiveness, and user
productivity by simplifying and accelerating the A simplified architecture that empowers you to
connections between users and cloud resources. enable the access patterns of your workforce—
However, unless it is coupled with a ubiquitous anywhere, any application, and from any device.
cloud security platform, traffic must still be Operates at 99.999% uptime to keep your
forced back to your data center. But doing this workforce connected without disruption.
slows down productivity and doubles down on an
Converge SD-WAN and ZTNA with our cloud-
already outdated architectural model.
delivered service edge to simplify your
Skyhigh Security’s Hyperscale Service Edge is technology stack so you have less to manage.
the cloud-native security fabric between your Enjoy low latency and unlimited scalability with a
workforce, WAN infrastructure, cloud services, global cloud footprint and cloud-native
and the web. Additional capabilities of our service architecture. By bringing together Skyhigh
edge include: Security SSE in a seamlessly integrated SSE
Over 60 Points of Presence (PoPs) peered with solution, organizations can reduce complexity
content providers at global Internet Exchange and costs while delivering a blazing fast user
Points (IXPs). experience.
Private
Cloud
IPSec/GRE
Internet
Tunnels
SECURITY
SERVICE EDGE
Branch Offices
Internet
Traffic Flow
Multi-Vector Data Protection: Data • Shared data protection policies are enforced
Awareness at Every Access Point at every control point, allowing you to easily
decide who can see your data and what they
Cloud transformation has meant that a large
can do with it.
portion of enterprise data now resides and is
being accessed outside of the network perimeter • Unified incident management between con-
and beyond the reach of traditional data security trol points with no increase in operational
controls. Collaboration from the cloud to third overhead.
parties, between cloud services, access by Skyhigh Security SSE draws incident event
unmanaged devices, and devices at home information from all control points into one
connected to peripherals have created new blind management console for a single view of your
spots that typically require multiple fragmented data protection environment. The unified data
data protection solutions. classification and management view delivers
Skyhigh Security multi-vector data protection consistent detection results and prevents the data
provides full-scope data protection for your loss prevention (DLP) security gaps that occur
workforce and eliminates data visibility gaps. when using multiple tools with disjointed policies
Each control point works as part of a whole and reporting. Our solution enables the correlation
solution. of data incidents across all vectors, enabling
administrators to identify signs of potentially
• Data classifications can be set once and
serious attacks.
applied across policies protecting the end-
point, network, web, and cloud.
Figure 4. Skyhigh Security Block upload of Enables transfer of sensitive files to internal recipient
sensitive docs
SSE multi-vector data b & Can’t share with unapproved 3rd parties
We San
protection use cases isk ps ctio
i u m R w Ap ned
d o Saa
Me Shad S
G CA
SW SB
Shado k Web &
to internal recipient
risky sites and enforce
Email
tenant restrictions
CASB
SWG
3rd parties
High
User
P
DL
CN
nt
AP
oi
dp
P
rk
wo
En
Network DLP
et
lN
Lo
&
Defense Against Cloud-Native Threats User and Entity Behavior Analytics (UEBA) finds
and Advanced Malware threats that traditional technologies miss by
monitoring cloud activity across all your cloud
As valuable resources have shifted to the cloud,
services and refining millions of events to identify
threat actors have followed. New methods of
anomalies and threats in your environment. These
attack are emerging that leverage the features of
anomalies are correlated to DLP incidents, cloud
cloud providers to fly under the radar while
configurations, and app vulnerabilities to create a
searching for and stealing information.
pre-built view of cloud-native attacks using the
Additionally, the advanced malware and
MITRE ATT&CK framework.
malicious code used in fileless attacks remain an
evolving threat. New protection methods are Any malware that attempts to land on your
needed to detect and block these threats without endpoints meets a rigorous, line-speed inspection
impacting end-user productivity. Skyhigh path that includes the industry’s most accurate
Security’s integrated SSE solution defends real-time emulation sandbox. In cases where
against cloud-native threats, advanced malware, attacks forego malware in favor of zero-day
and fileless attacks with an array of traditional exploits or fileless attacks that leverage operating
and state-of-the-art threat protection capabilities. system commands or website code, users
These defenses mitigate the risk of attack and automatically enter a Remote Browser Isolation
data loss as your enterprise transforms its session, allowing for full use of the web with zero
network and productivity tools into cloud-based possible infection.
services. Additionally, all events can be shared with third-
party SIEM solutions to empower security
operations teams.
Anti-Malware
Emulation
Sandbox
Safe Risky
Remote Browser
Isolation
Learn More
For more information visit us at skyhighsecurity.com
6220 America Center Drive Skyhigh Security is a registered trademark of Musarubra US LLC. Other
San Jose, CA 95002 names and brands are the property of these companies or may be claimed
888.847.8766 as the property of others. Copyright © 2022. March 2022
skyhighsecurity.com