Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Technology partner

Netskope integrator in Switzerland

We design and operate Netskope One architectures — web filtering, SaaS application control, Zero Trust private access and data protection, on a single gateway. Two certifications in the team.

Why this vendor

The perimeter has stopped being a place. Users work from home, applications are hosted elsewhere, and the traffic that once passed through the head office firewall no longer does. Backhauling that traffic to inspect it — the answer of the 2010s — costs dearly in latency and in links, and it shows immediately on real-time usage.

Netskope moves the control point into the cloud, as close as possible to the user. The technical merit of their approach lies in understanding application traffic: telling a file upload to a corporate space apart from an upload to a personal space within the same service is what domain-based filtering cannot do, and it is exactly what most policies are trying to express.

The difficulty lies elsewhere: in decryption, in the exceptions to plan for, and in change management. A badly scoped deployment breaks business applications and ends in a list of exclusions that hollows the whole arrangement out. We address that risk upfront, through a discovery phase before any policy is applied.

Our work covers design, pilot, rollout in waves, then operations or a handover to your teams.

Netskope
What we bring
  • NCCSA and NCCSI in the team
  • Usage discovery before any policy
  • Design of decryption and its exceptions
  • Replacing a VPN with Zero Trust access
  • Rollout in waves, reversible
Vendor website
Diagram

One gateway, several controls

Netskope One architecture: converged gateway and six domains Web and SaaSgatewayNG-SWGCASBPrivate accessand isolationPrivate AccessEnterprise BrowserRBIDataprotectionData SecurityDLPPostureDSPMSSPMThreats andfilteringThreat ProtectionFirewallNetwork andbranch officesSD-WANSASE BranchNetskope Oneconverged gatewaySSE
Every module carries the Netskope One prefix. Traffic crosses the gateway once, however many controls are applied.

The modules we integrate

Fourteen modules under one platform. They do not all switch on at once — the order of activation is part of the design.

Web gateway and SaaS applications

Netskope One NG-SWG inspects web traffic and applies the usage policy. Netskope One CASB adds an understanding of SaaS applications: telling a corporate instance apart from a personal instance of the same service, controlling shares, spotting applications used without ever having been declared.

Netskope One NG-SWGNetskope One CASB

Private access and isolation

Netskope One Private Access replaces the VPN with access granted resource by resource, according to identity and device posture. Netskope One Enterprise Browser covers unmanaged devices without installing an agent on them. Netskope One RBI isolates risky sites by executing the page remotely: what reaches the endpoint is no longer code but an image.

Netskope One Private AccessNetskope One Enterprise BrowserNetskope One RBI

Data protection

Netskope One Data Security and Netskope One DLP handle data where it travels — an upload to a personal space, a transfer to an undeclared service, a copy to an unmanaged device. Classification upstream determines the quality of the result: a DLP policy without prior work on the data produces mostly false positives.

Netskope One Data SecurityNetskope One DLP

Data and SaaS posture

Netskope One DSPM maps where sensitive data lives and who can reach it, in cloud environments as well as SaaS services. Netskope One SSPM monitors the configuration of the SaaS applications themselves: open shares, over-permissioned accounts, settings that drift after a vendor update.

Netskope One DSPMNetskope One SSPM

Threats and network filtering

Netskope One Threat Protection analyses files and flows, detonating unknown content. Netskope One Firewall extends control to protocols that are not web, often forgotten in secure access projects even though they remain plentiful in a real information system.

Netskope One Threat ProtectionNetskope One Firewall

Network and branch offices

Netskope One SD-WAN and Netskope One SASE Branch handle the network side: connecting remote sites to the gateway without backhauling to headquarters, choosing paths per application, and converging security and transport rather than administering them separately.

Netskope One SD-WANNetskope One SASE Branch
The platform

Netskope One SSE is the converged foundation: traffic crosses the gateway once, however many controls are applied. That is what separates a platform from a stack of chained services, where each hop adds its own latency and its own point of failure.

Netskope One SSE

Our Netskope certifications

Two badges held within the team, on administration and on integration of the platform.

NCCSA — Netskope Certified Cloud Security Administrator
NCCSANetskope Certified Cloud Security Administrator
NCCSI — Netskope Certified Cloud Security Integrator
NCCSINetskope Certified Cloud Security Integrator
Our approach

How we proceed

No policy is applied before the real traffic has been seen. The discovery phase is what avoids the list of exclusions that hollows the arrangement out.

Netskope integration approach, from discovery to operations ScopingImplementationDuration01Usagediscovery02Policydesign03Pilot onone scope04Rolloutin waves05Tuning andacceptanceOperationsor handover
Discovery precedes policy: it almost always reveals applications in use that were never declared.
Frequently asked questions

Frequently asked questions

It raises questions, and they are settled during scoping. Some flows must not be decrypted — healthcare, banking, applications using certificate pinning. The exception list is built upfront and documented; it is not an admission of failure but a normal part of the design. What causes problems is discovering those cases in production.

Yes, it is the most frequent use of Netskope One Private Access. The switch happens in waves, application by application, and the VPN stays in service until every resource is covered. We have documented that approach in a dedicated use case.

No, and certainly not all at once. The usual order starts with the web gateway and SaaS control, then private access, then data protection — the last of which assumes classification work that few organisations have done before the project. Enabling everything at once guarantees a long and poorly accepted rollout.

Yes, through our support and managed service offering: day-to-day operations, policy changes, handling exceptions and tracking new usage. Or through a handover to your teams, with the architecture documented.

A perimeter that is no longer a place?

Describe your usage — we start by looking at the real traffic before proposing a policy.