Ask FirstNet about Security

Knowledge Hub

Security questions & answers

Firewalls, managed detection & response, email security, SSE and web protection.

Hosted Firewall & Network Security · 25

About this service →
How does FirstNet size a firewall correctly?

A firewall should be sized on your real peak inspected traffic, not on your internet line speed. FirstNet gathers sizing inputs during discovery before recommending a model or hosted option, because enabled security features and SSL inspection change the answer most.

How does FirstNet handle changes to our managed firewall?

Firewall changes follow approved workflows with testing and rollback plans to keep your network stable. Only your authorised technical contacts can request and approve changes, and FirstNet implements them through its Rapid Response service process.

What is FortiAnalyzer as a Service (FAZaaS) from FirstNet?

FAZaaS is FirstNet's managed FortiAnalyzer service for centralised log analytics, compliance reporting, threat correlation and incident investigation across your Fortinet devices. FirstNet runs a dedicated FortiAnalyzer-VM instance for you on FirstNet-operated infrastructure in South Africa.

What is a VDOM in FirstNet's hosted Fortinet firewall service?

A VDOM (Virtual Domain) is an isolated firewall instance running on shared FortiGate hardware, giving you dedicated policies and logs without a physical device on your premises. FirstNet uses Fortinet VDOMs to deliver its Hosted VDOM firewall service, with a separate security context for each customer or business unit.

What is Sophos Synchronized Security, and does FirstNet include it?

Synchronized Security lets a Sophos firewall and Sophos endpoint protection (Intercept X) share information automatically. Through Security Heartbeat, each device reports a real-time health status, and the firewall can automatically isolate a compromised device from the network. It is included when you run a Sophos firewall alongside another Sophos product.

Can we move our self-hosted FortiAnalyzer to FirstNet's managed FAZaaS?

Yes. If you run FortiAnalyzer-VM yourself under a Fortinet licence, you can move to FirstNet's FAZaaS instead of renewing. You stop handling patching, backups, capacity planning and upgrades, move from a US dollar licence renewal to a monthly rand service, and gain South African hosting.

What is firewall as a service (FWaaS), and how does FirstNet deliver it?

Firewall as a service is a managed firewall service: instead of buying and running the firewall platform yourself, FirstNet provides, configures and supports it for you. FirstNet handles firewall policy, updates, monitoring, change management and incident response within the agreed scope.

Can FirstNet's managed firewall service send logs and alerts to our SIEM?

Yes. FirstNet can export firewall logs and alerts to your SIEM, or provide reporting dashboards instead. The integration approach, retention period and any forwarding are confirmed during solution design, because they depend on the firewall platform and service you choose.

What is the difference between Fortinet Hosted VDOM Lite and Enterprise at FirstNet?

Hosted VDOM Lite is for simpler needs: basic firewalling, NAT, routing and VPN. Hosted VDOM Enterprise adds advanced security and networking, including unified threat management features such as intrusion prevention, antivirus, web filtering and application control, plus SSL inspection and SD-WAN where required.

Can we see our firewall configuration and logs with FirstNet's managed firewall service?

Yes. Read-only visibility is available on request through Sophos Central or a read-only FortiManager ADOM profile. Write access to production is an exception that needs explicit approval, because it changes the managed-service operating model.

How does FortiManager reduce the risk of firewall changes in FirstNet's managed service?

FortiManager lets changes be validated before they reach your firewalls. FirstNet uses install previews, policy package validation, ADOM and device revisions, and one-click rollback to a known-good configuration, and its change process requires an install preview, peer review and a documented rollback step for every policy install.

What is the difference between Fortinet Hosted VDOM and Sophos Shared Firewall at FirstNet?

Hosted VDOM gives you an isolated virtual firewall instance on FirstNet's shared FortiGate platform. Sophos Shared Firewall gives each customer a dedicated Sophos Firewall Virtual machine on FirstNet's hypervisor. Both are hosted and managed by FirstNet; the right choice depends on your preferred platform and feature needs.

What is the difference between Sophos Standard Protection and Xstream Protection at FirstNet?

At FirstNet, Sophos Standard Protection covers core firewall needs. Xstream Protection adds zero-day protection, SD-WAN orchestration, DNS Protection, NDR Essentials and advanced reporting, with 30-day cloud log retention.

Should our firewall be on site or hosted by FirstNet?

An on-site firewall suits organisations with data sovereignty or latency requirements, local internet breakout, or high WAN throughput, because the appliance sits on your premises. A hosted firewall suits organisations that want managed protection without owning or maintaining an appliance, prefer a monthly operating expense, or are rolling out many sites where a centrally hosted service is simpler to operate.

Does FirstNet's FortiAnalyzer as a Service replace our SIEM?

No. FortiAnalyzer is the Fortinet-native analytics and reporting layer, sitting closer to your FortiGates and providing out-of-the-box compliance reports. If you already use Splunk or Sentinel, keep it; FirstNet can scope log forwarding to your SIEM separately.

How much FortiAnalyzer storage do we need with FirstNet's FAZaaS?

FAZaaS is sold in storage bundles starting at 50 GB and increasing in 50 GB steps. As a rule of thumb, 100 GB holds about 90 days of logs at 1 GB per day, measured before compression. FirstNet sizes the bundle from your device count, daily log volume and retention needs.

When does an organisation need FortiManager, and how does FirstNet run it?

FortiManager becomes valuable once you run around five or more FortiGates, because managing each device by hand leads to configuration drift and inconsistent policy. It is also a fit when an auditor asks how firewall changes are approved, evidenced and rolled back, or when you need clean separation between business units or managed customers.

What happens if our logs outgrow our FirstNet FortiAnalyzer storage bundle?

Your storage bundle is a hard ceiling, but FirstNet monitors ingestion trends and alerts you before you reach it so the bundle can be stepped up. There are no silent overage charges.

What happens to our Fortinet firewalls if FirstNet's FortiManager goes down?

Your FortiGates keep enforcing policy locally during a management-plane outage, so traffic is not dropped. FortiManager only configures and orchestrates devices; it does not inspect traffic itself.

How long are Sophos firewall logs kept in FirstNet's managed firewall service?

With Standard Protection, logs are kept on the firewall for seven days with basic reporting in Sophos Central. Xstream Protection adds Central Firewall Reporting Advanced, with 30-day cloud log retention and multi-firewall reporting.

What happens to our firewall data and configuration when a FirstNet contract ends?

You retain ownership of your data and configurations. FirstNet supports an agreed handover and deprovisioning process, and FortiAnalyzer logs are exportable on exit. Migration work outside the standard service is scoped separately.

How do FortiManager and FortiAnalyzer work together in FirstNet's Fortinet service?

In FirstNet's Fortinet service, FortiManager sets up your devices and FortiAnalyzer analyses what they see. With FirstNet running both, devices register once, logs flow automatically, and you can match FortiAnalyzer reports to FortiManager policy changes.

Is FirstNet's FortiAnalyzer as a Service the same as Fortinet's FortiAnalyzer Cloud?

No. FortiAnalyzer Cloud is Fortinet's own service, typically hosted in US or EU regions and billed in US dollars. FirstNet's FortiAnalyzer as a Service (FAZaaS) is hosted in South Africa, billed in rands and operated by FirstNet, so log data stays in South Africa during normal operation.

Do FortiAnalyzer logs stay in South Africa with FirstNet, and who is responsible under POPIA?

Yes. With FirstNet's FortiAnalyzer as a Service (FAZaaS), logs are held on FirstNet-run systems in South Africa and, in normal service, stay there. FirstNet carries the job of running the platform, but under POPIA you remain the responsible party.

With a FirstNet managed firewall, what does FirstNet manage and what remains our responsibility?

FirstNet manages the firewall itself, from setup and policy to updates, monitoring, approved changes and incident response. You stay responsible for your internal LAN, endpoints, cabling, ISP handoffs and apps, and for giving accurate inputs.

Email Security & Threat Protection · 19

About this service →
What is BIMI, and how can FirstNet get our logo shown in email inboxes?

BIMI (Brand Indicators for Message Identification) displays your verified brand logo next to your emails in supporting mailbox clients such as Gmail, Apple Mail and Yahoo. It only works once your DMARC policy is enforced at p=quarantine or p=reject, and most mailbox providers also require a Verified Mark Certificate (VMC), which is backed by a registered trade mark.

What is DMARC email authentication, and why does it matter for our domain?

DMARC (Domain-based Message Authentication, Reporting and Conformance) is the email standard that lets you tell receiving mail servers what to do with messages that falsely claim to come from your domain. Without DMARC enforcement, anyone can put your domain in the From line of an email, which is how most business email compromise, invoice fraud and executive-impersonation attacks work.

Can FirstNet run phishing awareness training and simulations for our staff?

Yes. FirstNet can provide or integrate security awareness training and phishing simulations as part of its managed Mimecast email security service, so users learn to spot the attacks that get past technical filters.

Which email platforms does FirstNet's managed Mimecast email security support?

FirstNet's managed Mimecast service works with Microsoft 365 and Exchange Online, Google Workspace, hybrid Exchange and standalone SMTP mail environments. Mimecast sits in front of your mail platform as a secure email gateway, so you keep your existing mailboxes.

Can we keep sending and receiving email with Mimecast if Microsoft 365 is down?

Yes, if Mimecast email continuity is included in your contracted service. Continuity gives users a failover email experience so they can keep sending and receiving during a Microsoft 365 outage, through Outlook for Windows and Mac, a web interface or mobile apps.

What is the difference between Mimecast and SendMarc in FirstNet's email security?

Mimecast is inbound protection: it stops phishing and malware reaching your users. SendMarc is outbound brand protection: it stops anyone spoofing your domain to attack your customers and suppliers. Most organisations need both, and FirstNet runs both as managed services.

Is Mimecast email archiving the same as a Microsoft 365 backup?

No. An email archive captures every inbound and outbound message under enforced retention, indexed for eDiscovery and legal hold. A backup is a point-in-time copy for restoring lost mailboxes or data. Most regulated organisations need both, and FirstNet offers each as a separate service.

Is an SPF record enough to stop attackers spoofing our email domain?

No. SPF only declares which mail servers are allowed to send for your domain, and attackers can still spoof the address your recipients actually see. DMARC is needed to enforce the check: it requires the visible From domain to align with an authenticated SPF or DKIM domain, and tells receiving mail providers to quarantine or reject mail that fails.

How much work does our IT team need to do for a FirstNet DMARC project?

Less than a do-it-yourself project, but some. FirstNet engineers identify every sending source and specify the SPF and DKIM changes needed, your administrators make those DNS and platform changes under FirstNet's guidance, and FirstNet validates them.

How are email archives protected in FirstNet's managed Mimecast service?

Email archives in FirstNet's managed Mimecast service are encrypted, and access is controlled by roles and audit trails, so only authorised people can search or export archived mail and their activity is recorded.

Does DMARC protect our business against look-alike and typo-squat domains?

No. DMARC protects only your real domain, stopping attackers from sending email that uses your exact address. It does not stop criminals registering look-alike or typo-squat domains that resemble yours, because those domains have their own DNS records that you do not control.

Is email data in FirstNet's managed Mimecast service kept in South Africa?

FirstNet delivers its managed Mimecast service from South Africa, and the Mimecast platform supports South African data residency preferences. If you need specific residency wording in your contract, or a mapping to regulatory controls, FirstNet's product and legal teams review it before any commitment.

Will adding Mimecast email security through FirstNet block legitimate email?

FirstNet reduces this risk by starting with a safe baseline policy, monitoring results and continuously tuning allow and block rules to cut false positives. Clear quarantine and release workflows let users and administrators recover legitimate messages quickly.

How can FirstNet show us every system that is sending email using our domain?

A baseline DMARC report shows every system sending email as your domain. FirstNet publishes a monitoring-only DMARC record (or uses your existing one) and collects the reports that receiving mail providers send back, usually over two reporting cycles.

Will enforcing DMARC with FirstNet's SendMarc service break our marketing email?

Not with a phased approach. FirstNet identifies and authenticates every legitimate sending source before enforcement, moves your policy through quarantine with rollback guardrails, and only then reaches reject, so legitimate marketing and transactional email keeps flowing.

Who do we call when FirstNet's Mimecast or SendMarc email security has a problem?

Call FirstNet's Rapid Response desk, which operates 24/7 and takes tickets by email, phone or portal. Platform issues are escalated to Mimecast or SendMarc by FirstNet, so you never deal with the vendor directly.

What Mimecast email security tiers does FirstNet offer, and what does each include?

FirstNet offers Mimecast email security in three tiers: Essentials, Resilience and Complete. FirstNet runs each one as a managed service, with onboarding, policy tuning, threat triage and escalation to Mimecast.

We already have Microsoft Defender for Office 365. Why add Mimecast through FirstNet?

Mimecast adds an independent, specialist email security layer in front of Microsoft 365, with its own threat intelligence, sandboxing and URL rewriting, plus continuity if Microsoft 365 itself is down. FirstNet also runs the tuning, threat workflows and DMARC programme for you.

How long does it take to reach DMARC p=reject with FirstNet's managed SendMarc service?

It depends on how many sending sources you have and how quickly your platform owners can make authentication changes. FirstNet scopes the journey during discovery rather than committing to a date upfront.

Managed Cybersecurity Services · 13

About this service →
What is the difference between XDR, MDR and next-generation SIEM?

XDR (extended detection and response) correlates security telemetry across endpoints, firewalls, identity, cloud and email so threats are easier to spot. MDR (managed detection and response) adds people: Sophos analysts monitor, hunt and alert 24/7, with FirstNet's Incident Response team helping you remediate. Next-generation SIEM ingests telemetry at enterprise scale for compliance reporting and log retention.

Can we add Sophos MDR to our FirstNet Sophos Firewall as a Service?

Yes. Sophos MDR is a separate service that attaches to Sophos Firewall as a Service on the same monthly bill. With Sophos endpoints, Synchronized Security can also isolate compromised devices automatically.

Can FirstNet combine Sophos MDR with backup for ransomware recovery?

Yes. FirstNet pairs Sophos MDR with Druva cloud backup, so you have 24/7 detection and response alongside an independent backup copy for recovery. MDR helps detect and contain a ransomware attack, while backup gives you clean data to restore if systems or files are encrypted.

How does FirstNet help secure staff use of AI tools like Copilot and ChatGPT?

FirstNet uses Sophos Secure AI to give you visibility of shadow AI use, policy and role-based controls with prompt monitoring, and protection through input sanitisation, output interception and AI data loss prevention, with AI risk monitored by Sophos MDR.

Will FirstNet's managed security controls slow our users down?

FirstNet prioritises controls that add protection with minimal friction, and phases changes with clear communication, so users are not hit by a sudden wall of blocks and prompts.

Does FirstNet help with security compliance reports and audit evidence?

Yes. FirstNet sets up reports and dashboards that support audits and checks by regulators. Compliance reporting is part of the managed service FirstNet wraps around its Sophos deployments.

Does FirstNet's managed security help meet cyber-insurance requirements?

Yes, it helps. Sophos MDR, XDR, NG-SIEM and Secure AI map to the controls most cyber insurers ask for, and FirstNet provides audit-grade reporting to evidence them. Compliance and insurance outcomes remain a shared responsibility.

What managed security support tiers does FirstNet offer with Sophos MDR?

FirstNet offers its Sophos-based managed security in three tiers: Standard, Enhanced and Premium. All three include Sophos MDR's 24/7 monitoring, and FirstNet's Incident Response team acts on Sophos alerts.

Is the 24/7 SOC in FirstNet's managed cybersecurity service run by FirstNet?

No. Sophos MDR runs the 24/7 SOC (security operations centre) layer that monitors, hunts and alerts around the clock. FirstNet's Incident Response team acts on those alerts with you, and FirstNet also handles onboarding, reporting and escalation.

We already have a SIEM. Where do FirstNet's Sophos XDR and MDR services fit?

If your SIEM is working well, Sophos XDR and MDR can complement it. If it is expensive to operate, slow to deploy or weak on response, Sophos NG-SIEM can replace it as part of a planned transformation run by FirstNet.

What happens when Sophos MDR detects a threat in a FirstNet-managed environment?

Sophos MDR analysts spot the threat and send an alert to FirstNet's support desk. FirstNet's Incident Response team then works with you to contain the threat, fix the cause and recover.

How long does it take FirstNet to onboard Sophos managed detection and response (MDR)?

Standard Sophos MDR onboarding with FirstNet typically takes two to four weeks. Integrating XDR or next-generation SIEM telemetry usually takes four to eight weeks, depending on how many data sources are connected, and a full next-generation SIEM transformation that replaces a legacy SIEM typically takes eight to 16 weeks.

We already use Microsoft Defender. Do we have to replace it to use Sophos MDR from FirstNet?

No. Sophos XDR and MDR can ingest Microsoft Defender telemetry, so you can consolidate it into analyst-led detection and response rather than rip it out.

Can FirstNet guarantee POPIA compliance for our cybersecurity services?

No. No provider can guarantee POPIA compliance on its own. FirstNet aligns each security service to your privacy, retention and audit requirements, but compliance remains a shared responsibility that depends on your configuration and governance.

What are managed cybersecurity services, and how does FirstNet deliver them?

Managed cybersecurity services are security controls that a provider deploys, monitors and runs for you on an ongoing basis, instead of your team buying and operating each tool. FirstNet delivers managed cybersecurity across your network, cloud platforms, users and devices to reduce cyber risk and improve resilience.

Which organisations need managed cybersecurity services from a provider like FirstNet?

Any small, medium or large business that relies on cloud apps, the internet and digital communication needs consistent security controls. Managed cybersecurity from FirstNet is the practical way to apply them across all users and sites, without a large in-house security team.

Does FirstNet operate its own security operations centre (SOC)?

No. FirstNet does not run its own SOC (security operations centre). Sophos MDR delivers the 24/7 SOC layer, including threat hunting and analyst-led detection, and FirstNet's Incident Response team acts on its alerts with you.

How do FirstNet's managed cybersecurity services reduce business risk?

Managed cybersecurity reduces business risk by combining preventive controls, continuous monitoring and rapid response, which lowers both the likelihood and the impact of ransomware, phishing, data breaches and unauthorised access. FirstNet delivers this as layered services that work together.

Does FirstNet's managed cybersecurity protect remote and hybrid workers?

Yes. FirstNet's managed security controls follow users wherever they work, so staff at home, in branches or on the road get the same protection as those at head office, without relying on a traditional network perimeter.

How do FirstNet's security services fit together into a layered defence?

FirstNet's security services each cover a different part of the attack surface, so most organisations combine several. Every layer runs as a managed service under one FirstNet contract, with one support desk.

Does FirstNet's managed cybersecurity cover cloud and hybrid environments?

Yes. FirstNet's managed cybersecurity protects on-premises, cloud and hybrid environments with consistent visibility and control, so cloud workloads and SaaS users are not treated as a separate security problem.

Where should we start with FirstNet if we have several cybersecurity gaps?

Start with the risk that is costing you most today, whether that is phishing, an ageing firewall or VPN pain. FirstNet runs a discovery session, proposes the first service, then expands into adjacent layers once the first one is proving its value.

What certifications and security partner accreditations does FirstNet hold?

FirstNet runs ISO 27001 (information security) and ISO 9001 (quality) management systems, and holds ECS and ECNS licences from ICASA. It is also a Sophos Titanium Partner, a Mimecast Elite partner, and a Fortinet, Cloudflare and Netskope partner.

Who do we contact at FirstNet when there is a problem with a security service?

You contact FirstNet's Rapid Response support desk, whichever security platform the issue involves. Rapid Response is the single entry point for incidents, service requests and escalations, so you do not need to manage vendor support queues yourself.

Does FirstNet resell security licences, or does it run the security service for you?

FirstNet runs the service. It deploys each security platform, sets and tunes policies, monitors it and handles changes through its Rapid Response support desk. Where a customer specifically needs hardware or licences only, FirstNet can supply them, but that is quoted separately from its managed services.

Web Application & DDoS Protection · 11

About this service →
What is Cloudflare Magic Transit, and who needs it?

Magic Transit provides always-on DDoS protection for an entire IP range. Cloudflare advertises your IP prefixes from its global network using BGP, filters malicious traffic at the edge and tunnels clean traffic back to you.

Can Cloudflare Access from FirstNet replace our VPN?

Yes. Cloudflare Access provides zero trust network access: users reach specific private applications through Cloudflare's edge after identity checks such as single sign-on, MFA and device posture, without a traditional VPN concentrator or inbound listeners on your network.

How does Cloudflare, managed by FirstNet, stop bad bots and protect APIs?

Cloudflare Bot Management uses machine-learning bot scoring, JavaScript challenges and mobile signals to stop automated abuse such as credential stuffing, scraping, inventory hoarding and fake sign-ups. API Shield protects APIs with schema validation, mutual TLS, JWT validation, sequence analytics and abuse detection, covering risks a traditional web application firewall can miss.

Can we use Cloudflare from FirstNet alongside Zscaler or our existing WAF?

Yes. Many customers run Zscaler for outbound users and Cloudflare for inbound apps. Where you have an existing WAF, FirstNet plans a phased migration rather than a rip-and-replace.

Is Cloudflare just a CDN, or a full security platform?

Cloudflare started as a CDN, but today it covers application security, Zero Trust access, network services and edge compute on one platform, and often replaces three or four separate security and delivery contracts. FirstNet designs, deploys and tunes it for South African organisations.

What happens to our website if Cloudflare has a problem?

Cloudflare publishes its operational status, and FirstNet designs your deployment around your risk tolerance. Depending on the service, that can include documented DNS fallback procedures, BGP failover for Magic Transit, and alternate paths for business-critical applications.

What do we need to provide to onboard Cloudflare with FirstNet?

You need control of DNS for the domains being protected, plus proof of domain ownership. For Zero Trust, FirstNet needs your identity provider details and a catalogue of the applications in scope with their owners. For Magic Transit, FirstNet needs your public IP ranges and ASN.

Does Cloudflare inspect our website and app traffic in South Africa?

Yes, for South African users. Cloudflare operates points of presence in Johannesburg and Cape Town, so South African traffic is cached and inspected locally. Specific data residency or POPIA commitments are reviewed against Cloudflare's published data localisation options.

Is Cloudflare a SOC or managed detection and response (MDR) service?

No. Cloudflare is a security platform, not a 24/7 security operations centre. For managed detection and response, FirstNet offers Sophos MDR with FirstNet Incident Response.

Why buy Cloudflare through FirstNet rather than directly from Cloudflare?

Buying Cloudflare through FirstNet gives you local engineers in South African business hours, plus policy hardening, ongoing tuning and SIEM integration. You also get partner-tier escalation into Cloudflare, and one contract that joins Cloudflare up with FirstNet SD-WAN, DIA, Colocation, Private Cloud and IP Transit.

Will turning on Cloudflare's WAF through FirstNet break our applications?

Not if it is staged properly. FirstNet stages the Cloudflare WAF in detection mode first and tunes it against your real traffic before enforcement. It documents a rollback path with your application team, and cutover stays reversible until enforcement.

Secure Access & SSE · 10

About this service →
Can we trial Netskope SSE with FirstNet before we commit?

Yes. FirstNet can run a structured Proof of Value (POV) that tests your main Netskope use case with a small group of users in your own environment, against success criteria agreed upfront, so you can make a confident decision and build an internal business case.

Can Netskope Private Access from FirstNet replace our VPN?

Yes. Netskope Private Access replaces traditional VPN access with app-level zero trust access, so users reach only the applications they are allowed to use, rather than being placed on the network as a whole.

Can Netskope from FirstNet control how our staff use AI tools?

Yes. Netskope, delivered by FirstNet, can identify and control AI app usage and help prevent sensitive data being exposed through AI interactions, such as prompts containing confidential information.

What is remote browser isolation (RBI), and how does Netskope use it?

Remote browser isolation (RBI) opens risky or uncategorised websites in an isolated session away from the user's device, so potentially malicious code never runs on the endpoint. Users can still view the content, which means security teams can reduce risk without blocking large categories of websites outright.

What is the difference between SSE and SASE, and where does Netskope fit?

Security Service Edge (SSE) is a group of cloud-delivered security services that protect users and their access, such as a secure web gateway, cloud access security broker, data loss prevention and zero trust network access. Secure Access Service Edge (SASE) combines those security services with networking, such as SD-WAN, in one cloud model.

How does Netskope compare with Zscaler for secure access and data protection?

Both are strong cloud security platforms. Netskope is usually the better fit when your priorities are SaaS visibility, data protection, control over AI tool use, and a single platform with one policy model and one console. Zscaler is well known for zero trust access and web security at large scale.

Is Netskope from FirstNet just a web proxy replacement?

No. A secure web gateway is often the entry point, but Netskope also covers CASB, DLP, Private Access, remote browser isolation, analytics and wider SSE and SASE capabilities on the same platform, delivered and optionally managed by FirstNet.

Does Netskope guarantee compliance with POPIA or other regulations?

No solution guarantees compliance on its own. Netskope, delivered by FirstNet, strengthens control, visibility and reporting, which supports your compliance goals, but outcomes depend on your setup, governance and operation.

Do we have to replace all our security tools at once to move to Netskope?

No. Most organisations start with one urgent use case, such as replacing a web proxy, controlling SaaS and AI tool use, protecting sensitive data or replacing a VPN. Once that use case has proved its value, they expand into adjacent controls on the same platform.

Is a managed service included by default when we buy Netskope from FirstNet?

No. Managed and co-managed services are optional and scoped clearly. You can buy licensing only, deployment support, co-management or a full managed service from FirstNet, and the split of responsibilities is agreed upfront so ownership is clear after go-live.

Microsoft 365 Security & Compliance · 3

About this service →
How can we see risky sharing and unsanctioned apps in Microsoft 365 with FirstNet?

A cloud access security broker (CASB) gives visibility into how your Microsoft 365 or Google Workspace estate is being used. It can scan for misconfigurations, public file shares, risky OAuth grants and third-party app sprawl, and show which SaaS and AI tools staff are using. FirstNet delivers CASB through Netskope or Cloudflare.

How can FirstNet stop sensitive data leaving through Microsoft 365, email and AI tools?

Data loss prevention (DLP) controls detect and block sensitive information, such as personal information covered by POPIA, payment data or credentials, as it moves through web, SaaS, email, endpoints and AI interactions. Netskope DLP, delivered by FirstNet, applies these controls from one policy engine, including prompts sent to AI tools.

Does DMARC work with Microsoft 365 and Google Workspace email, and can FirstNet set it up?

Yes. DMARC applies to any domain sending email, including mail sent from Microsoft 365 and Google Workspace. For DMARC to be enforced safely, every legitimate sender must pass SPF or DKIM alignment, including Microsoft 365 itself, marketing platforms and finance or ERP systems that send as your domain.

Call