Zscaler’s Advantages Over Websense

Transcription

WHITE PAPERZscaler’s Advantages Over WebsenseAvoid the costs and complexities of hybrid security solutionsAre you worried about selecting the wrong web security solution for your enterprise?Are you concerned about deploying and managing even more appliances throughoutthe organization at a time when many leading companies are moving security tothe cloud?While enterprises around the world are taking advantage of the productivity benefits of cloud and mobileenvironments, Websense (now Forcepoint) users are still shackled to security appliances that hog resourcesand demand increasing investments in MPLS, bandwidth, and backhauling services. As the number of remoteemployees, cloud services, and mobile users grows exponentially, traditional appliance-based hub and spokemodels are unable to scale.In contrast, the Zscaler Cloud Security Platform delivers advanced web security and real-time global policyenforcement with more than 100 global data centers that process 20 billion transactions every day. WithZscaler, the need for branch office appliances and MPLS networks is eliminated, resulting in some cases toa reduction in traffic backhauling costs of 80 percent or more.Recognized as a leader, and one of the fastest-growing vendors in web security, Zscaler delivers all thefeatures of a secure web gateway (SWG) through a globally distributed cloud network. By eliminatinghardware and its associated complexity and overhead, Zscaler’s advantages over Websense can be bestsummarized through the following four CE& SCALABILITY04SUPERIORFUNCTIONALITYSUPERIORVALUE

ZSCALER’S ADVANTAGES OVER WEBSENSESUPERIOR ARCHITECTUREWhen you’re considering web security solutions,the architecture of the solution is a long-termdifferentiator, because the solution you choosewill be reflected in your capital expenses as well asyour operating costs for years to come. Appliancebased solutions require deployments in multiplelocations and ongoing maintenance and upgrades,while Zscaler’s 100% cloud-based architecture offersnumerous advantages over the Websense hybridhardware-based gateway and cloud-based offerings.Zscaler’s Cloud Security Platform acts as a globalcheck post in the cloud and allows remote usersand offices to access the data and applications theyneed from anywhere, anytime, and from any device,while ensuring security and enforcing compliancewith granular user policies.which had previously acquired the originaldeveloper, BlackSpider Technologies Limited.Websense currently operates just 15 security datacenters worldwide.No agents requiredUnlike Websense, Zscaler requires no softwareagents on end-user computing devices, such as PCs,laptops, tablets, smart phones, unless the deviceis not connected to Active Directory or other LDAPcompliant directory. By eliminating the need forsoftware agents, you can much more easily supporta heterogeneous computing environment withoutIT having to become experts on every potentialclient computing platform in use within a givenorganization.World’s largest cloud security networkZscaler scans all incoming and outgoing trafficbetween any device and the Internet to identifyand block potential threats. Zscaler’s awardwinning security solutions have been 100 percentcloud-based since the company’s inception in 2008.Today, Zscaler boasts the world’s largest cloudbased infrastructure built from the ground up withinnovations derived from more than 60 patents.Zscaler’s global platform processes over 20 billiontransactions per day with near-zero latency tosecure over 15 million users in 180 countries, withno on-premises hardware or software required.Zscaler has the world’s largest security cloud withover 100 data centers worldwide, and doesn’trequire IT organizations to purchase expensivehardware and software to secure mobile usersor remote offices around the globe. The Zscalerinfrastructure delivers superior reliability andperformance for a mobile and increasingly globalworkforce. Zscaler is transforming the marketfor IT security in much the same way that SaaSapplications transformed the CRM market. Incontrast, Websense originally developed its cloudsolution through the acquisition of SurfControl,Internet andCloud ApplicationsSECUREGATEWAYNO POLICY ORPROTECTIONMPLSWANVPNBACKHAULMOBILE EMPLOYEEHQREMOTE OFFICESNo backhaulingWebsense customers often pay a fortune eachyear to backhaul traffic from branch offices to acentral Websense V-Series or X-Series appliance atheadquarters, effectively paying for their Internettraffic twice—once at each branch office locationand again at headquarters when they backhaulit. With Zscaler, there is no need to backhaultraffic. You simply point your traffic to the Zscalercloud, and all of your users are instantly secure—regardless of where they’re based or what devicethey’re using.

ZSCALER’S ADVANTAGES OVER WEBSENSESUPERIOR PERFORMANCE ANDSCALABILITYWith Zscaler, you get a single solution with theindustry’s most advanced web and mobile security,with no hardware or software required. And withZscaler’s cloud architecture, you can secure branchoffices and road warriors without backhaulingtraffic to a central location, potentially saving yourorganization millions of dollars each year. Thissection contrasts the performance and scalabilityof Zscaler Cloud Security Platform with securitysolutions from Websense (now Forcepoint).Zscaler has the largest globalcloud footprint, with more than 100enforcement nodes in 30 countries.– “Magic Quadrant for Secure Web Gateways,” Gartner28 May 2015Built for performanceUnlike appliance vendors that are now “movinginto the cloud,” the Zscaler cloud platform wasbuilt in the cloud and today is comprised ofmore than 100 data centers spread out aroundthe world—at least four times as many as anyother vendor on the planet. Traffic generated byZscaler customers is intelligently routed to thenearest cloud-based point of presence. Zscalercan therefore combine ultra-fast processing withpatented compression technology to deliver theindustry’s most advanced security with near-zerolatency. Since Zscaler never impacts the user’sweb browsing experience, IT doesn’t need to worryabout users attempting to bypass your securitymeasures to improve performance.Websense/Forcepoint offers both appliancebased gateway solutions and hybrid solutionsthat combine enterprise-based appliances withcloud-based solutions in “Websense TruHybridDeployments,” which Websense defines as, “Mixedappliance/cloud deployment(s) enabling cloud forremote or small offices and appliances for mainlocations, plus cloud as failover for appliances.”There are hundreds of companies offering someform of IT security. The difference is that Zscaler isa pure cloud solution that requires no hardware orsoftware. Unlike appliances from our competitorsthat are static and sit at the server or corporatenetwork, Zscaler is built from the ground up toenable web, mobility, and cloud applications forbusiness. Enterprises can avoid the performancedegradation of appliances by relying on the ZscalerCloud Security Platform.Enterprise-class scalabilityWhile Websense solutions burden the customerwith deploying, maintaining, and upgradingappliances, Zscaler is transforming enterprisenetworking and security with the world’slargest cloud security platform, which securelyenables the benefits of cloud, mobile, and socialtechnologies without the cost and complexityof traditional on-premises appliances andsoftware. Scaling is a function of the cloudinfrastructure, not of the enterprise IT resources.Your organization can become more agile andscale your security resources more nimbly withthe Zscaler platform. Zscaler has more than 5,000enterprise cloud security customers in over 180countries, and offers customer lists, case studies,and videos you can sort by vertical markets andgeographic regions on the Zscaler Customer page,so you can find companies similar to yours andlearn more about their experiences growing theirsecurity infrastructure with Zscaler.

ZSCALER’S ADVANTAGES OVER WEBSENSEBacked by measurable SLAsUnless there are real consequences for failingto meet a service-level agreement (SLA), an SLAis merely a best-effort intention. Zscaler offersdocumented SLAs for both availability andlatency with stated financial penalties—nextmonth’s service credit—if Zscaler fails to meetits obligations. Websense offers a 100% SLA forprotection from known viruses with subscriptionto its cloud anti-virus service and offers 99.999percent minimum availability SLA for its HostedEmail Security Service and 99% spam detectionfor its Websense Cloud Platform, but otherwisedoesn’t even seem to make significant referenceto the need for SLAs on its public website.A non-relational data store optimized for loggingand reporting, NanoLog is purpose-built with 65:1compression to allow IT organizations to quicklyanalyze massive log histories such as web pagedownloads, web mails, and attachments sent, postspublished on social networking sites, or instantmessaging transcripts—all in just seconds. Thisunique capability brings together massive logs fromvarious locations to a central logging server for easyreporting and analysis, while sophisticated indexingtechnology fetches detailed historical information.Mobile-based appsCloud-based appsSUPERIOR FUNCTIONALITYSocial mediaCLOUD SERVICESZscaler offers several key advantages overWebsense solutions, including the following:ReportingWebsense offers separate user interfaces (UIs)for its appliances and cloud services, forcing theenterprise to learn two UIs to manage and developreports on Websense solutions. Meanwhile, Zscaleroffers true real-time reporting and dashboardanalytics, enabling users to interact with data inreal time. Zscaler’s patented NanoLog technologyis an entirely new kind of web logging, reporting,and analytics application built from the ground upto address today’s Big Data ticationBoth Zscaler and Websense support single signon (SSO) authentication using local databases,LDAP, SAML, and Active Directory, but Websenselacks support for Active Directory FederationServices (ADFS). Zscaler supports ADFS, a softwarecomponent developed by Microsoft that can beinstalled on Windows Server operating systemsto provide users with SSO access to systemsand applications located across organizationalboundaries. It uses a claims-based access controlauthorization model to maintain application securityand implement federated identity management.

ZSCALER’S ADVANTAGES OVER WEBSENSESupport for third-party MDM solutionsCorporations often use Mobile Device Management(MDM) solutions to deploy and provision corporateapplications and data on mobile devices, such assmartphones and tablets. However, MDMs are notdesigned to be security solutions, because theydo not address advanced threats like phishing andspyware, nor do they protect against maliciousapps, including ransomware.Organizations are also restricted, because theiOS platforms used with iPhone and iPad devicesrequire digital certificates from Apple that onlyrecognize one MDM at a time to streamline devicemanageability. Zscaler complements leading MDMsolutions by extending the benefits of the Zscalerplatform to mobile devices without the need toinitiate a VPN connection first from the mobiledevice to a physical appliance located back at theoffice. Conversely, the Websense TRITON MobileSecurity solution has MDM features, restricting itsinteroperability with third-party MDM solutions.SUPERIOR VALUEBuilt-in SSL inspectionSSL-encrypted traffic comprises 25 to 35 percentof enterprise traffic, and that percentage isgrowing rapidly. In fact, according to RSS Labs,SSL is expected to consume 60 percent of all webtraffic by the end of 2016. But SSL is computeintensive, and it’s slow on Websense appliances,often requiring the deployment of twice as manyappliances. While Websense does not supportSSL in its cloud services, Zscaler provides SSLdecryption in the cloud, making this solutionmuch more seamless and cost-effective.Simplified policy managementWhile Websense allows customers to createcomplex policies that can be enforced on itsappliances, it does not offer this same controlover cloud services. IT has to learn different UIsfor managing cloud and appliance policies, andpolicies set on appliances may not apply to theWebsense cloud. Zscaler allows IT to centrallymanage IT security policies for multiple devices,applications, and locations from a central console.This console not only simplifies management andreduces costs, but it also provides new opportunitiesto correlate reporting and analysis of policyenforcement across different devices and locations.Built-in DLP protectionWebsense does not offer data loss prevention (DLP)in its cloud services, but Zscaler provides customerswith the basic DLP protection needed to preventcredit card numbers, Social Security numbers,and other forms of sensitive, structured data fromleaving your network without proper authorization.Zscaler allows IT to centrally manage IT securitypolicies for multiple devices, applications, andlocations from its central console.StabilityWhile Zscaler is a pure, cloud-based solution,Websense TRITON solution suites are installed onWindows servers in the enterprise data center. IThas to maintain and upgrade the platform, andstability is often an issue. IT also has to maintainan SQL server, and multinational organizationsthat deploy TRITON solutions typically have todeploy—and license—two separate installationsto comply with European Union privacy laws forseparating EU and U.S. traffic.GRE supportGeneric Routing Encapsulation (GRE) is a tunnelingprotocol developed by Cisco that allows networklayer packets to contain packets from a differentprotocol. It is widely used to tunnel protocolsinside IP packets for VPNs, but Websense doesnot yet support it. Because Zscaler operates inthe cloud, customers can forward or re-directoutbound web traffic to Zscaler EnforcementNodes (ZENs) using GRE tunnels.

ZSCALER’S ADVANTAGES OVER WEBSENSEA unified, seamless solutionA Websense Web Security Gateway customer wanting to purchase mobile and email security has to navigatethe confusing decisions between premises-based and cloud-based services, and likely has to purchaseadditional appliances. Analyzing the technical tradeoffs and the cost impacts can be paralyzing. Thisapproach is considerably more expensive and complex—more hardware, more rack space, more electricity,and more labor—and adds packet latency, since the packets must pass through multiple appliances insequence. Zscaler customers, on the other hand, gain all of these capabilities seamlessly and effortlessly—allinline and with negligible packet latency—at no additional charge as part of their Zscaler subscription. Andbecause Zscaler is 100% cloud-based, customers can expand and contract “on demand,” saving valuable timeand money—not to mention a few headaches.ZSCALER, THE PURE CLOUD SOLUTIONIn 2015, Websense was acquired by Raytheon and Vista Equity Partners. That organization, called RaytheonWebsense, has since acquired another company, thus creating the composite organization now known as“Forcepoint.” With the increase in cloud applications, Forcepoint has seized on the opportunity to become acloud player. According to Maury Garavello, APAC vice president of Forcepoint, “As companies are moving tocloud, we need to move our security solution to cloud.”But instead of trying to retrofit disparate hardware offerings into a cloud solution, Zscaler has always been100 percent in the cloud. Since the company’s inception in 2008, we have been focused on building ourarchitecture from scratch as a pure cloud provider. We’ve built many innovations into our distributed, multitenant architecture, based on more than 50 patents. Some of these innovations include Zscaler EnforcementNodes (ZENs), which enforce security, management, and compliance for every user on any device, anywhere.Our revolutionary Single Scan Multiple Action (SSMA) technology enables us to inspect every byte of trafficby every security function on the platform. Our ByteScan technology provides ultrafast content scanning anddetection of malicious sites and content, so you don’t have to rely on signatures any more. Our Page RiskIndex delivers dynamically computed information based on real-time web activities instead of relying onreputation alone. And Nanolog technology, which encrypts and compresses web logs for complete visibilityand drill-down in seconds.These innovations, and many more, can only be delivered as a result of the 100 percent cloud-basedarchitecture on which they were built. For example, the ability to inspect every byte of data, including SSL, isa result of the platform’s massive scale—scale that enables us to process more than 30 billion transactions aday. Global cloud scale also enables us to inspect all your data inline, so you’re protected all the time, in nearreal time, without compromising the user experience. Hardware and hybrid solutions are inherently limited bythe amount of processing power that can be housed in a single box.

ZSCALER’S ADVANTAGES OVER WEBSENSECONCLUSIONBuilt from the ground up to truly protect the Everywhere Enterprise, the Zscaler Cloud Security Platform usesglobal checkpoints to deliver advanced security, enforce real-time business policy, eliminate backhaul costs,and improve performance. Select Zscaler over Forcepoint/Websense, so your organization can benefit from: Better security than hybrid or appliance-based security solutions Streamlined performance with near-zero latency Better control over user productivity and compliance violations The simplicity of having no hardware or software to deploy Eliminatiion of the need for branch office appliances and MPLS networks Reduction in traffic backhaul costs by more than 80 percentToday, Zscaler customers include some of the world’s largest organizations and best-known brands,including 50 of the Fortune 500. But one of the great benefits of our multi-tenant architecture is that everyZscaler customer, from those with more than a million users to those with a few hundred, get the exactsame security. Furthermore, if a threat is identified by one of our 15 million users, it is blocked for everysingle one of our users.If you haven’t considered Zscaler yet, we hope this paper has convinced you to take a closer look. Once youunderstand the benefits of the Zscaler architecture—performance, scalability, functionality, and value—youcan see why Websense customers are moving to the Zscaler cloud for a far superior and more cost-effectiveweb security solution.Learn more. Contact a Zscaler sales representative or channel partner today to schedule an evaluation.CONTACT USFOLLOW USZscaler, Inc.110 Rose Orchard WaySan Jose, CA 95134, USA 1 408.533.0288 1 om/zscaleryoutube.com/zscalerZscaler and the Zscaler logo are trademarks of Zscaler, Inc.in the United States. All other trademarks, trade names or service marksused or mentioned herein belong to their respective owners.

Unlike Websense, Zscaler requires no software agents on end-user computing devices, such as PCs, laptops, tablets, smart phones, unless the device is not connected to Active Directory or other LDAP-