This global business data giant with 20,000 employees chose Google's G Suite for SaaS productivity and needed a solution to protect data in the app.
This enterprise handles business and financial data for much of the Global 2000 and security is paramount. The firm's security team already had installed the latest "Next-Gen Firewall" appliances at every location, as well as Secure Web Gateways from Blue Coat. However, G Suite posed a new challenge.
Firstly, users expected access from any device, anywhere, so the firm's existing network-centric security hardware was of no help. Secondly, within the corporate network, the existing security hardware was not capable of understanding the semantics of G Suite to be able to enforce corporate data security policies.
The enterprise decided to use a Cloud Access Security Broker (CASB) to secure G Suite, holding a bake-off with four CSB vendors. Three of the four vendors could only support API-based visibility and control of corporate data. The solutions these three vendors put forward were limited to inspecting data at rest in the cloud, and identifying data leaks after they had occurred. Their solutions could not control data as it was downloaded to or uploaded from any device. This weak security did not satisfy the requirements of the firm's legal team. Enter Bitglass.
Bitglass' product provided the firm with exactly what it needed. Beyond API-based visibility and control of corporate data at rest in the cloud, Bitglass offers inline protection of data during any user's interactions with G Suite. Sensitive data was blocked or restricted prior to upload to the cloud and before download to unmanaged devices. Best of all, Bitglass' resilient AJAX-VM technology meant that inline control was achieved without any software on client devices.
The firm also valued the seamless user authentication experience and enhanced security presented by Bitglass' dual SAML proxy technology. Specifically, users could login directly to Google and were transparently redirected via single sgn-on through the Bitglass Omni multi-protocol proxies. Unlike competing CASBs, users entered their login credentials only into the corporate SSO, thereby limiting phishing risk.
No software. Zero touch. Visibility, security, and compliance.
"In comparing the leading CASB solutions, we found that only Bitglass delivers inline data protection during upload and download from any device. Best of all, no software or configuration is required on client devices."
– Chief Risk Officer