CloudLock is a cloud security option acquired by Cisco in August 2016.
N/A
Zscaler Internet Access
Score 8.9 out of 10
N/A
Zscaler Internet Access™ (ZIA) is a secure web gateway (SWG), delivering cloud native cyberthreat protection and zero trust access to the internet and SaaS apps.
Cisco Cloudlock is a good fit for my organization consisting of 150 end users. While we have a small office product that can expand to cover any size organization, I would assume the overhead to monitor would increase. While my organization's business is in real estate, I would highly recommend this for all businesses that handle sensitive and private data. Being able to monitor our cloud infrastructure has allowed our security team to be more flexible in allowing approved users access as well.
Zscaler Internet Access is an internet tunnel that pairs with the network adapter to secure traffic between servers and workstations. It can refresh policies automatically and log intrusions but does not broadcast intrusions. Cloud-based Zscaler Internet Access is easy to deploy and scale, with no hardware or software needed. In a hybrid model, Zscaler Internet Access performs some security functions on-premises and others in the cloud, allowing organizations to keep infrastructure. There is a slight learning curve from VPN and appliance architecture to this paradigm.
My personal opinion about Zscaler is their idea is that all the services are online and are moving to the cloud but the truth is some of them have to stay on-premise and employees still need to work from an office. Zscaler simply doesn't have any on-premise solutions like an NGFW to provide a complete package. We are supporting Fortinet NGFW for our on-premise solution.
As mentioned earlier Zscaler being hosted online we don't get the full flexibility of managing our firewalls. Although it's a good thing we keep running into problems like when we want to allow list a service from a specific source IP Zscaler cannot provide a static IP for that. They route traffic through multiple IP addresses and the IP's keep changing every 15-20 minutes. So you cannot allow list a specific IP on the receiving end. The only way to move forward would be to allow an entire range of IP's which opens a security loophole on the receiving end.
For every small thing we have to keep opening a ticket with Zscaler. Their response rate is fast but still in a fast-moving world it's not fast enough. Especially since we need to get approval from our change control to get something done and then again we have to raise a ticket to get something done from the Zscaler side.
Zscaler is a mandatory solution required by almost every large organization with a workforce working remotely or using cloud-based apps. Its deployment is relatively easy and it keeps on working in the background without actively bothering the user. Apart from a few weird messages which a user is unable to comprehend, Zscaler is able to provide fast and safe access to the internet and other external applications.
They are very quick to respond and go the extra mile to help address our issues. That said, we've only needed them at the early stages of implementation for support help and occasionally when we want to do a full re-scan of our site. They are very flexible in working with us on the timing of such scans.
I cannot give a fair rating for this as I have not had to contact Zscaler support. There was one time we had to contact them because we needed to check if they were having issues on their end. Our ISP was actually the problem but support seemed very friendly.
Amazon Macie is limited to an AWS environment and fulfills some of the same functions that CloudLock does in SaaS products. Both are very valuable tools, so the decision is not really which to use, but whether to use both for their respective environments. In general I feel CloudLock is a more powerful tool because it connects to Microsoft 365, which is more business critical for our organization, but that really is a personal call.
Zscaler Intenet Access proved to be superior and the difference for us was the speed of policy delivery since your policy is applied in a web console and is effective in a matter of seconds. Another point to congratulate the solution is its compatibility with different platforms (macOS, Linux, Windows, Android, and iOS).