Akamai updated its cloud-based secure web gateway today with data loss prevention, application visibility and control, and end-to-end security for DNS traffic. The new capabilities round out Akamai’s secure access service edge (SASE) stack and will further support employees working from home because of the COVID-19 pandemic as well as remote, distributed infrastructure and workforces in the future, said Patrick Sullivan Akamai CTO of Security and Strategy.

“The mega trends that are driving SASE is being able to be able to move security close to end users wherever they may be — if they are working remote, if you have M&A activity, if you pick up a new office somewhere,” he said.

A SASE architecture also moves the traffic inspection and security functions closer to the compute, he added. “If you move to infrastructure-as-a-service, if you pick up some new applications that aren’t close to the existing corporate data center, you’re still going to have a very agile environment,” Sullivan said.

Akamai Enterprise Threat Protector

The first of three new capabilities integrates data loss prevention (DLP) in Akamai’s Enterprise Threat Protector secure web gateway platform. This prevents the loss of personally identifiable data or other confidential business data that might be accidentally sent out of an enterprise via the public internet.

It includes DLP dictionaries for personably identifiable information, the Payment Card Industry Data Security Standard (PCI DSS), and the Health Insurance Portability and Accountability Act (HIPAA), and users can also create custom dictionaries based on these dictionaries.

The second new Enterprise Threat Protector feature — application visibility and control — allows companies to identify which applications are being used, and then block entire applications based on a risk score. They can also block individual per-application operations such as allow uploads but block downloads.

This addresses some of the cloud access security broker (CASB) use cases included in SASE such as shadow IT discovery and control for software-as-a-service (SaaS) applications.

Across the industry, standalone CASBs and secure web gateways (SWGs) are merging, Sullivan said. “So for us, being able to do malware and browsing protection on the SWG side, and then extending that to do the CASB-type functionality with shadow IP discovery in a single proxy, it’s a simplified approach,” he explained.

And then the third new addition to Akamai’s SWG secures DNS traffic as it travels between a device and cloud resolver. It does this by allowing enterprises to add DNS over TLS (DoT) encryption through a client or through a virtual machine DNS forwarder. This encrypts the DNS traffic between enterprise devices and the Enterprise Threat Protector DNS resolvers.

The platform already supports DNSSEC, and this new capability allows enterprises to have end-to-end security for DNS to reduce the risk of attackers intercepting and manipulating this traffic.

Akamai’s Road to SASE

Akamai has an interesting SASE play. It started as a content delivery network (CDN) provider, which gave it a well-established edge network long before it waded into the hot SASE market. Its CDN remains a $1 billion business, Sullivan said.

“We’ve been an edge-based company for 20-plus years, and we’re pretty unique in our architecture, we’re built out into 4,000 POPs [points of presence],” he said. “There’s not a lot of people building architectures in that way.”

And long before Gartner came up with the sassy new security architecture term, Akamai offered cloud-based web application protection, which Sullivan said is also a $1 billion business. This includes security services such as web application firewalls and distributed denial of service (DDoS) mitigation.

After web application protection, Akamai moved into zero-trust network access and Forrester’s most recent Forrester Wave evaluating zero-trust providers named Akamai a leader in this sector.

Then in March, Akamai added SWG.

“As web security moved from the data center to the edge we had tremendous advantages there in terms of scale, the deployments, the user experience, the ability to decrypt and view traffic at Layer 7,” Sullivan said. “We think those same, sustainable platform advantages are there for us as more and more applications follow this same path.”