Forcepoint rolled out its Web Security platform across 160 global points of presence (PoPs). It’s the first phase of the vendor’s strategy to build out a disaggregated cloud security infrastructure that will ultimately provide customers anywhere with access to all of its security services while also addressing performance and regulatory requirements such as low latency, data sovereignty, and content localization.

“The idea behind us doing this is customers experience,” said Nico Fischbach, global CTO at Forcepoint. “When you want to deliver top-notch, best-in-class user security, you need to be close to the end user. And end users are not static anymore.”

The company has “thousands” of customers, primarily large and very large enterprises and government agencies including IBM, Walmart, Microsoft, Boeing, Dow, Qualcomm, and Toyota. And the new platform enables them to securely access web-based content by integrating features including cloud access security broker (CASB), cloud sandboxing with advanced malware protection, and policy enforcement across sites, mobile users, and endpoints.

“We’re delivering web security now, which is security hygiene,” Fischbach said. “But the second part: we will be expanding into data protection so you will be able to protect your data and your roaming users based on analytics and output from the analytics engine.”

Those capabilities, he added, are coming in the near future.

With today’s announcement, however, Forcepoint Web Security does provide data center security certifications including SOC2, ISO 27001, and Privacy Shield. It also boasts two other major certifications: ISO 27018, which governs personally identifiable information, and Cloud Security Alliance (CSA) Star Gold, based on the GDPR Code of Conduct, which governs software security and cross-functional operations in a cloud setting.

Putting these security and data privacy services close to end users and devices requires a distributed, edge architecture instead of a centralized computing approach.

Security at the Edge

“It depends what problem you are trying to solve. With the need to have near-real-time decisions being made close to the end user, you need edge computing,” Fischbach said. “Some things can be done centrally, like policy logs, but anything that affects the customer experience needs to happen very, very close to the end user. Today we are trying to balance where do we need to enforce, and where do we need to make decisions to make sure the experience is the best without compromising the security or safety of the system.”

Some vendors and analysts see this as the way security infrastructure will be deployed in the future — but it requires deep networking expertise.

“We see a lot of vendors heading this way, and we do see this as the way all should or will move in the future,” Doug Cahill, senior analyst at ESG, said in an earlier interview. ESG calls this “Elastic Cloud Gateways,” and Cahill said Forcepoint’s approach is a prime example.

“More specifically, Forcepoint’s expanded cloud infrastructure enables local, secure access to Internet-based resources, a central attribute of an Elastic Cloud Gateway,” Cahill wrote in an email. “This architectural approach alleviates the performance penalty organizations incur when they backhaul remote traffic to the corporate network for access controls and content inspection.”

While other security vendors including Netskope, Zscaler, Palo Alto Networks, and Cisco are also moving toward Elastic Cloud Gateways, but Fischbach said Forcepoint’s strategy has some key differentiators. Some of these vendors take a more infrastructure-centric approach and focus on protecting workloads rather than users and data, he said. “We are changing the game by looking at the layout of both what the users are doing and how they interact with the data.”

Plus, Forcepoint targets major enterprises and government agencies with its existing global footprint as well as security capabilities and certifications that many of its competitors don’t have, Fischbach added.

“Connectivity is key, and we want to make sure customers connect to us once, and once they connect they can add more security services in a seamless manner,” he said. “We are enabling them to grow with us.”