Google Cloud rolled out its second BeyondCorp zero-trust security product today with additional enterprise capabilities and a partner ecosystem that includes VMware, Citrix, CrowdStrike, and Tanium.

Back in April 2020, Google Cloud announced BeyondCorp Remote Access. This was its first commercial product based on the zero-trust approach to network security that Google pioneered and has used internally for a decade. The cloud-based service lets employees access internal web apps from most devices and from any location without a traditional remote-access virtual private network (VPN).

The April launch happened earlier than Google originally planned. The cloud giant had slated the release of an enterprise-scale BeyondCorp product later in 2020, but then the COVID-19 pandemic, and newly remote global workforce, dramatically increased the demand for remote worker security. So Google bumped up the release date for a portion of the full BeyondCorp stack that targeted enterprise’s working-from-home employees.

Enterprise-Grade Security

Today’s release, BeyondCorp Enterprise, replaces BeyondCorp Remote Access and is the full zero-trust product. It’s a scalable platform that includes agentless support delivered through Google’s Chrome Browser. Google’s global network includes 144 edge locations in more than 200 countries and territories. This means users can work from anywhere and use BeyondCorp’s security capabilities to protect data and applications across devices and clouds.

Chrome serves as a sort of “zero-trust OS” that sits on top of customers’ hybrid environments and provides zero-trust security from endpoints to applications, Google Cloud Security SVP and GM Sunil Potti explained. “Given the new work-from-home environment, but also the recent supply chain attacks … unless we take a seismic change in offering a zero-trust OS of some sort as a layer that sits on top of this hybrid environment, I don’t think we’ll ever make a sea change in terms of trust and risk management.”

Chrome has about 2 billion users worldwide, Potti added, and this allows Google to “light up Chrome to provide BeyondCorp capabilities, advanced data leak, data loss prevention.”

Chrome’s newly-added embedded data and threat protection prevent malicious or unintentional data loss and exfiltration and malware infections from the network to the browser, Potti explained.

BeyondCorp Enterprise uses phishing-resistant authentication to ensure that users are who they say they are, microsegmentation to prevent malware from moving from users to apps, and it requires continuous authorization for every interaction between a user and a BeyondCorp-protected resource. It also includes automated public trust SSL certificate lifecycle management for internet-facing BeyondCorp endpoints powered by Google Trust Services.

Google also boosted its BeyondCorp Alliance, which allows customers to integrate zero-trust protection with their existing network and endpoint security tools from vendors including Check Point, Citrix, CrowdStrike, Jamf, Lookout, Palo Alto Networks, Symantec, Tanium, and VMware.

BeyondCorp Began Inside Google Cloud

Google started developing BeyondCorp in 2010 after Chinese hackers successfully breached Google and other Silicon Valley tech giants’ networks, and stole intellectual property. This spurred Google to shift access controls from the network perimeter to individual users and devices.

“There was a major investment by Google to essentially hit the reset button on how to approach protection of both employees and assets,” Potti said in an earlier interview with SDxCentral. “And core to this was the fact that we shouldn’t differentiate between external threats versus internal threats. So when I’m in the office, or I’m at Starbucks, or I’m at home, everyone is viewed as an external user from a security-posture perspective. Independent of your location, you should be operating like a user on the network as long as you’re the right user.”

A year later the company rolled out BeyondCorp. It’s a zero-trust access approach that assigns rules and policies to workloads, virtual machines (VMs), or network connections, and then only allows necessary actions and connections in a workload or application and blocks anything else. The goal was to enable every Google employee to work from untrusted networks without the use of a VPN.

“Fast forward 10 years later, inside Google we have 100,000-plus employees who, with two weeks or a few weeks, we went from our majority being internal employees to external employees with no major ramp up of any additional technology,” Potti said.