In today’s digital workplace, we use the internet constantly. The internet allows us to find information in seconds that otherwise could take weeks of research to procure. It’s opened up a world of virtual communication, allowing remote teams to perform as effectively as collocated teams. But our reliance on the internet also makes us vulnerable. A study from the University of Maryland found that hackers attack computers with internet access every 39 seconds on average.
This almost constant rate of attack is a huge worry for any business, and particularly those with remote workers who communicate over an internet connection. When one connection is compromised, it can take minutes for bad actors to spread malware through a company’s network. We’ve explored the most effective types of web security, and found that the best solutions fall into two categories: web filtering and browser isolation.
There are two main types of web filtering: cloud-based and DNS. Cloud web filtering platforms, or “Secure Web Gateways” (SWGs), protect internet-connected devices by filtering harmful websites and blocking web-based viruses and malware from being downloaded to the user’s machine. They scan for malicious website code, filter harmful URLs and prevent data loss.
DNS (domain name system) web filtering platforms are a type of cloud web filter. They sort internet traffic based on DNS lookups. Every webpage has a unique IP address, which browsers connect to the domain name to be able to load the page. DNS filters sit between the browser and domain so that browsers can’t load malicious sites. Many DNS filtering platforms come with a pre-configured blacklist of harmful domains that can’t be accessed on protected networks.
The second type of web security we’ve explored is browser isolation. Browser isolation platforms protect businesses by isolating users’ online browsing activity in a safe environment that’s detached from the local network. The best browser isolation solutions are cloud-based and execute web-based commands in secure server, or ‘remote desktop’. When using this remote desktop, the user experiences totally normal browsing, but it takes place independent of their local machine. This means that malicious webpages and attachments are contained or sandboxed within the virtual environment and never reach the user’s local system.
In this article, we’ll explore the top ten web security solutions, including a range of cloud-based and DNS filtering solutions as well as browser isolation platforms. We’ll give you some background information on the provider and the key features of each solution, as well as the type of customer that they are most suitable for.
The Top 10 Web Security Solutions includes
- Cisco Umbrella, DNSFilter, iboss, Forcepoint, McAfee, Menlo Security, Palo Alto, Symantec, Trend Micro and ZScaler
Combined Secure Web Gateway and DNS filtering powered by machine learning
Cisco are a global network, infrastructure and security vendor that offer a variety of security solutions to protect digital communications across the world. Their Umbrella solution, launched in 2019, offers flexible, cloud-based security via a Secure Web Gateway. The solution combines multiple functions that admins can monitor from one user-friendly console, making it easy to add and protect devices remotely. Cisco Umbrella is available in three packages, which have been designed to protect any sized organization, from small businesses to multinational enterprises.
Cisco Umbrella offers DNS security, a Secure Web Gateway, firewall as a service (FWaaS) and cloud access security broker (CASB) functionality in a single console called the Umbrella Secure Internet Gateway (SIG). Admins can monitor threats and configure protection across all of these areas from one easy-to-use management portal. Additionally, Umbrella comes with integrated threat response so that security teams can investigate the root cause of security incidents to avoid repeat attacks.
The three Umbrella packages utilize sophisticated machine learning and extensive threat intelligence from Cisco Talos, one of the world’s largest commercial threat teams, to detect and protect against known and zero-day threats. This means that the solution can offer powerful web filtering protection against malware, phishing and DNS tunneling attacks.
Cisco Umbrella has been praised by customers for its quick and easy deployment and user-friendly management portal, that also monitors devices operating remotely from the office. Its quick deployment means that this solution offers almost immediate, reliable security coverage across all ports and protocols. This, combined with the scalable package options, makes Cisco Umbrella a good cloud option for most organizations looking for a solid web security solution.
Real-time, customizable DNS filtering powered by AI with excellent reporting capabilities
DNSFilter’s web security solution does exactly what the name suggests: it filters DNS requests, sorting the safe from the malicious, to secure users’ browsing experiences. The flexible API-driven solution is relatively new to the market, but still manages to offer strong protection and excellent user experience to a wide range of customers, including members of the Fortune 500.
DNSFilter combines advanced machine learning techniques with antivirus scanning to categorize websites according to their threat level. The sophisticated threat intelligence means that DNSFilter can even detect threats in webpages that the solution has never come into contact with before. The powerful URL filtering tool protects users’ browsing experiences without slowing down the organization’s network. The solution is very user-friendly, an important benefit which extends to its management and reporting dashboard. It’s also highly customizable, so that admins can configure blocked websites according to their organization’s policies.
DNSFilter’s Global Anycast network means that their web filtering solution is highly scalable so that it can protect any sized organization, from SMBs right through to the largest global enterprises. The solution’s protection also extends across devices that are off network, meaning that it can protect users who work remotely. DNSFilter lacks some of the additional features that some other vendors on this list offer, but is nevertheless a great solution for any organization searching for a powerful web filtering platform.
Entirely cloud-based Secure Web Gateway that ensures the highest levels of protection outside the office, as well as within
iboss’ cloud web security solution is founded on node-based technology, which the vendor calls “containerized gateways.” It delivers SaaS network security, with all firewall and proxy capabilities delivered in the cloud, meaning that customers’ networks aren’t drained of resources when running the solution. Organizations can adopt iboss’ public cloud service, implement containerized gateways in their own private cloud, or create a hybrid solution by integrating the two.
The iboss platform delivers all of its features, functions and security as a service in the cloud. This includes web filtering, malware defense and DNS protection. Delivering security in the cloud allows the solution to protect users’ internet access at all time, no matter their location. This makes the product particularly useful for organizations with a lot of remote employees. Security teams can customize filtering policies, as well as configure malware and data loss prevention rules, with these automatically applied to end users.
iboss’ solution deploys easily with 100% API-based integration, and is compatible with Office 365, MS Cloud App Security CASB and Azure. It’s easy set-up and powerful cloud-based protection make this solution ideal for enterprise organizations, who have a high number of remote employees.
Powerful web filtering, with advanced reporting tools, that supports organizations at all stages of cloud migration
Forcepoint, formerly Websense, offer a broad range of cybersecurity products, including Secure Email and Web Gateways, firewalls, and behavioral analytics. Their Secure Web Gateway solution is available as on-premise software, and as a cloud-based service. Users can also choose to create a hybrid service for protection both on-premise and away from the office. This makes it suitable for all organizations, no matter their state of cloud migration. Forcepoint’s management console supports reporting in each of these deployment environments.
Forcepoint’s SWG uses over 10,000 analyses to support their advanced threat detection, including real-time analysis of integrated data theft. Its comprehensive cloud application security allows organizations to monitor users’ cloud app behavior during work hours, as well as their online behavior, to uncover risks and remove security gaps.
The solution includes excellent logs and filters, with custom categories for activity monitoring. These granular controls allow organizations to fine-tune the level of protection to bring it in line with their company policies.
Forcepoint’s admin controls are a little complex, with customers reporting that there’s a learning curve for organizations that invest in this solution. However, the that the solution provides its customers. For this reason, we recommend Forcepoint’s Secure Web Gateway as a strong solution for mid- to enterprise-sized organizations looking for a cloud web filtering platform.
Cloud-based Secure Web Gateway with highly granular policy filtering and in-depth reporting tools
McAfee offer a family of SWG solutions, including an on-premise and a cloud-based platform for web filtering. Their Web Gateway Cloud Service (WGCS) is quick to deploy and easy to manage. The solution is highly customizable, which means that it can take a while to deploy. However, once configured, it provides accurate and sophisticated protection and reporting.
McAfee’s Web Gateway Cloud Service uses embedded browser code emulation and an anti-malware feature to provide strong, customizable protection against malware. The solution’s policy engine is rule-based, which makes it extremely flexible so that organization’s can configure it according to their own policies. The filtering policies are granular, so can take some time for admins to set up, but they allow for enhanced protection and reporting.
McAfee’s SWG uses their global threat intelligence to carry out powerful web filtering based on a profile of secure web pages and keywords. This makes it impossible for employees to access restricted content, allowing for increased productivity as well as security.
Finally, McAfee’s SWG works outside the company network, which allows it to secure remote users as well as those on-premise. McAfee’s Web Gateway Cloud Service is a strong web filtering solution for enterprise organizations, particularly those that already use McAfee’s ePolicy Orchestrator, as these companies will be familiar with the granularity of the filtering policies. It’s keyword filtering capabilities also make it a strong solution for those in educational settings, where the restrictive access controls can help protect vulnerable users.
Market-leading browser isolation that ensures complete protection with zero impact on users’ browsing experience
Menlo Security are a market leader in offering web security through isolation. Their technology helps to eliminate the risk of email and web-based threats by isolating all content and executing it on secure servers. This protects users comprehensively against malicious content, without having any adverse effects on the system’s performance or changing the way that users browse. Menlo’s platform is fully cloud-based and is fully compatible with platforms like Office 365.
Menlo’s Security Isolation Platform (MSIP) is founded on their Isolation Core technology. Their secure cloud proxy creates a digital barrier between the user and any potential sources of attack. Users carry out all of their work in a remote web browser within the cloud, and Menlo make sure that only safe information can pass through the gateway to the user’s endpoint device. This means that users can’t interact with phishing pages, and admins can configure settings to block additional websites, adverts and even popups. Additionally, the solution’s protection extends to cover Software as a Service (SaaS) applications. This means that any SaaS apps you use, such as Office 365, will run at full speed on a direct-to-internet connection, without the risk of compromising your security.
Menlo’s approach is built “in the cloud for the cloud”, and this cloud-first isolation strategy is what allows them to ensure security with zero compromise. Their solution is scalable to be able to support organizations of any size, but customers typically range from mid-sized to large enterprises.
Palo Alto Networks
Cloud-based URL filtering with machine learning technology to protect against known and emerging web-based threats
Palo Alto Networks are a global cybersecurity leader offering enterprise-level security through AI, analytics, automation and orchestration. URL Filtering for Web Security is Palo Alto’s internet security solution, providing users with secure web access through a powerful URL filter with PAN-DB. The solution offers protection against phishing sites, HTTP-based command and control, malicious sites and pages that carry exploit kits.
Palo Alto’s URL Filtering uses a combination of static analysis and machine learning through PAN-DB to identify threats and protect users from them. PAN-DB is Palo Alto’s cloud-based URL database. This global threat intelligence allows for automated, real-time protection that blocks newly discovered malware and exploit sites.
Palo Alto’s solution offers multiple URL categories as well as a risk rating for each site, which allows admins to create more insightful policies at a granular level. The solution also features credential phishing protection that analyzes suspicious URLs for malicious content. Finally, Palo Alto’s URL Filtering includes firewall integration, which helps to simplify policy configuration and administration without affecting the speed of any web-based applications.
Customers praise Palo Alto’s URL Filtering for Web Security solution for its effective protection and clear visibility into their networks’ URL traffic. All of Palo Alto’s solutions are delivered via their integrated platform, which enable the protection of mobile devices as well as clouds and networks. We recommend this solution for any large enterprises looking for a powerful URL filtering tool, and particularly those with a number of remote employees working from different locations around the world.
Gartner Magic Quadrant leading solution combining Secure Web Gateway and browser isolation technologies
Symantec are a Gartner Magic Quadrant leader in appliance- and cloud-based web security solutions, holding the largest market share amongst SWG vendors. Their Web Security Service is an all-encompassing web security solution that offers a Secure Web Gateway and browser isolation. The service is compatible with Microsoft Office 365, and admins can configure separate policies for different Office 365 applications.
The cloud-based Web Security Service uses strong SSL inspection to detect malware hidden in encrypted web traffic, and block this from reaching users’ end devices. Symantec’s advanced proxy architecture allows the solution to deliver a Secure Web Gateway that controls and inspects web and cloud traffic, terminating advanced threats and securing user’s data no matter their location. The solution also offers a cloud firewall service as an add-on, which covers all ports and protocols and ensures that consistent policies are applied across on-premise and remote devices. Finally, the solution features browser isolation capabilities, which direct uncategorized URLs to an isolated environment. From here, the pages are sent safely as images to the user’s browser for viewing.
In the web portal, admins can view reports and manage the service, but customer reviews find reporting and configuration capabilities to be limited. Symantec do offer an enhanced reporting and management console, but this isn’t included in their web security solution; customers must purchase it as an add-on.
Symantec’s Web Security Service’s protection extends across mobile devices as well as desktops, making it an attractive solution for organizations with workers that regularly access company data remotely, e.g. by checking emails on a personal cell phone. We’d recommend this solution for enterprise organizations looking to invest in a powerful hybrid (cloud and on-premise) web security solution.
On-premise and cloud-based Secure Web Gateway to protect against advanced malware threats, with real-time reporting
Trend Micro have over 30 years of experience in producing simple, safe and trustworthy cybersecurity solutions. InterScan Web Security (IWS) is their software-only Secure Web Gateway that customers can deploy on-premise, in the cloud, or as a hybrid combination of the two. This is supported by the synchronization of policies for cloud and on-premise users.
The InterScan Web Security solution uses anti-malware, URL filtering, sandboxing and botnet detection to protect users against advanced threats such as malware and zero day exploits, as well as to protect cloud-based applications. Users that choose to deploy the cloud-based service also benefit from machine learning technology, leveraging the real-time protection of Trend Micro’s Smart Protection Network to defend the system against new and emerging threats. Admins can configure protection settings for over 1,000 applications at a granular level, which makes it easy to enforce company acceptable use policies. The management console also enables admins to view reports that allow complete visibility into web usage. These reports include real-time monitoring so that you can see web use as it happens, allowing for on-the-spot remediation.
Trend Micro’s InterScan Web Security is a powerful solution for SMBs looking for a SWG that’s particularly good at protecting mobile endpoints. Customers have reported that it’s easy to deploy and manage and are generally satisfied with Trend Micro’s support services. However, it’s usually sold as a part the vendor’s Smart Protection Complete Suite. For this reason, we recommend it particularly for those who want a SWG to fit into a broader security suite, or those who already have a strategic relationship with Trend Micro. Trend Micro also have a mature channel partner platform, with a number of partnership opportunities on offer, so this solution is also available for MSPs to leverage.
Gartner Magic Quadrant leading, FedRAMP Authorized Secure Web Gateway solution that offers advanced threat protection across the globe
ZScaler are market leaders in providing powerful cloud-based web security that grows with the customer’s organization. Their Internet Access (ZIA) solution is a Secure Web Gateway that proxies and filters web traffic from head offices, branch locations and mobile devices. Customers can also purchase optional features, such as a firewall and cloud-based sandboxing, to further enhance their web protection. The lack of hardware means that ZIA is quick and easy to deploy, so that customers are protected within minutes of investing in the solution.
The ZScaler Internet Access SWG offers advanced malware detection across all web content, including SSL and TLS traffic, regardless of the website’s reputation. Because it’s a cloud-based application, ZIA is able to utilize powerful machine learning technology to protect against emerging zero-day exploits. The solution also includes a basic firewall, DNS filtering and CASB functionality, which protect cloud-based applications as well as actual web browsing. Customers have the option to add and upgrade features for an additional cost. The solution features an easy-to-use management platform, where admins can access real-time reporting and analytics, with per-user views to enable enhanced protection for each user.
Quick to deploy and with instant Office 365 integration, ZScaler’s solution is ideal for mid- to large-sized enterprises looking for a purely cloud-based Secure Web Gateway. ZScaler hold a large market share in the US, but their large cloud footprint means that they’re also able to offer this solution in locations that competitors tend to be unable to serve, such as the Middle East, Russia and Africa. This makes ZIA a particularly strong solution for global organizations with offices in these areas.