Fixing Your Mis-Deployed NGFW
Published 11/23/2018
By Rich Campagna, Chief Marketing Officer, Bitglass
The Firewall/Next-Gen Firewall has been the cornerstone of information security strategy for decades now. The thing is, changes in network traffic patterns have resulted in most firewalls protecting a smaller and smaller percentage of enterprise network traffic over time.
This post will illustrate the root cause of these firewall mis-deployments, and how the typical enterprise can correct the issue, restoring the efficacy of their security strategy.
In the beginning
In the beginning, your firewall was in position to protect the majority of your corporate data and applications. Most users were on managed devices, on network (either physically or via VPN), and connected to data and applications inside of the enterprise (private) data center. Everything was protected and the deployment was sound:
Time goes on
As time went on, the first sanctioned SaaS applications were introduced to the organization. These typically took the form of major SaaS applications like Office 365, G Suite, and Salesforce. Since these applications are publicly available from anywhere, BYOD started to rear its ugly head as well (even if you had held it off in the past). This was the first step towards firewall mis-deployment, with a good portion of corporate data now existing unprotected outside the firewall:
Eventually, the business got the idea that cloud was easier, more agile, and more cost effective than premises applications, so the demands started to increase. In addition to major SaaS apps, niche industry and/or functional applications started popping up, and the organization began migrating premises applications (both custom apps and package software) to IaaS platforms. Today's picture for most enterprises looks something like this:
Results are in
The result? Your firewall is currently protecting only a small percentage of your enterprise applications and data. There is, however, a simple fix for this deployment challenge:
With the constant wave of applications migrating to the cloud, it won't be long before we hit Firewall Zero, with Cloud Access Security Brokers taking the firewall's place as the cornerstone of enterprise security strategy.
Related Articles:
When is SD-WAN Zero Trust and When is it Not?
Published: 03/08/2023
What is a CASB and How Does it Integrate with DLP?
Published: 12/19/2022
Security Service Edge (SSE) Reflects a Changing Market: What You Need to Know
Published: 02/24/2022
Multi Cloud Security
Published: 02/17/2022