Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In a June 13, 2013, interview with SecurityWeek, SkyHigh Networks CEO and co-founder Rajiv Gupta described a startup built to help organizations see and manage employees’ use of cloud services. He outlined a three-part approach—discover cloud services in use, assess service and user risk, and apply controls—and reported early traction of about 15 customers. Those are historical statements from the interview, not a description of SkyHigh’s current products or corporate status.

Why Gupta started SkyHigh Networks

Gupta told SecurityWeek that his interest in cloud computing began during his work at HP Labs. He also recounted earlier startup experience: Confluent Software became part of Oracle, and Securent was acquired by Cisco, according to his account in the interview.

When considering what to build next, Gupta said the team evaluated five potential breakthrough ideas in areas including storage, mobile and service management. It spoke with 120 companies. In those conversations, he said, organizations repeatedly raised both the promise of cloud adoption and concerns about security, compliance and privacy. The team chose cloud security as the problem to address.

Gupta framed the opportunity as helping businesses use cloud services while meeting those requirements. This is his explanation of the company’s rationale in 2013, rather than an independent assessment of the cloud-security market.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What SkyHigh said its service did

Gupta described the service as three connected functions: discovery, analysis and control. The distinction matters: discovery was about identifying cloud usage, analysis considered the risk of the service and how people used it, and control meant applying measures to manage that exposure.

Discovery: identify cloud services in use

SkyHigh said it identified services employees were using by analyzing logs from an organization’s egress devices. The goal was to reveal cloud exposure that an organization might not otherwise have a clear view of. The interview describes the company’s stated method at the time; it is not an independently audited account of product performance.

Analysis: assess service risk and usage risk

Gupta said SkyHigh maintained a registry of more than 2,000 cloud services and assessed each using 30 parameters. He cited factors such as multi-tenancy, data commingling, encryption at rest, key handling, breach history, penetration testing and single sign-on.

He distinguished the risk of a cloud service from the risk of how a person used it. As examples of usage patterns the product concept might flag, Gupta described a salesperson accessing far more opportunities than usual or an employee accessing a service from an unfamiliar location. These were his examples in 2013, not verified claims about current detection features.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Control: apply safeguards

The third function was to act on the exposure identified through discovery and analysis. Gupta named access control and data encryption as examples of controls. The interview does not establish which specific controls were available in every deployment.

How the interview’s model relates to CASB

McAfee later described Skyhigh Networks as a cloud access security broker (CASB) company. In McAfee’s acquisition-era explanation, CASB tools give businesses insight into and control over data and users moving in and out of cloud resources, including access and data movement. That provides category context for Gupta’s 2013 description; it should not be read as a current product specification or as a statement made by Gupta in the interview.

What SkyHigh reported about its early stage

Gupta reported about 15 customers and 44 employees. He said customer organizations ranged from 600 to 350,000 employees. These figures describe the company and its customers as discussed in the 2013 interview; they are not current figures or market-wide statistics.

SecurityWeek’s article also added an editorial update that SkyHigh had announced a $20 million Series B after the interview was conducted. The update therefore concerns a later event than Gupta’s interview answers, rather than a funding announcement already reflected in those answers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Business model and competition as Gupta described them

Gupta called SkyHigh’s business model subscription-based. On competition, he named Symantec as a company with a similar vision and contrasted SkyHigh’s service approach with an on-premises appliance approach. Those were his competitive views in 2013, not a current market comparison or an objective evaluation of either approach.

What this interview does—and does not—establish

The interview is useful as a snapshot of how an early cloud-security startup explained its problem, product concept and business at the time. It documents Gupta’s rationale, the three functions he described, and the company and customer figures he reported. The cited material does not establish SkyHigh Networks’ present ownership, branding, product availability or Gupta’s current role.

Sources: SecurityWeek’s June 13, 2013 interview with Rajiv Gupta and McAfee’s acquisition-era explanation of CASB.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.