A Secure Web Gateway inspects and controls web traffic to protect users from internet-borne threats, enforce policy, and prevent data leaving the organisation. This guide covers how SWGs work, key capabilities, and how they fit into a well architected network.
A Secure Web Gateway (SWG) is a security control that sits between users and the internet, inspecting web traffic in both directions and applying security policies in real time. It blocks access to malicious or policy-violating destinations, prevents malware from reaching users via the web, and stops sensitive data from being transmitted to unauthorised locations.
Where traditional firewalls control traffic based on network-level attributes like IP addresses and ports, an SWG operates at the application and content layer. It understands what is being accessed, not just where traffic is going.
SWGs can be deployed as cloud-delivered services, on-premise appliances, or in hybrid configurations. Cloud-delivered SWGs are increasingly standard because they protect users wherever they connect from, regardless of whether they are on the corporate network. For organisations with hybrid workforces or multiple sites, this matters significantly.
An SWG examines all web traffic passing between users and the internet. When a user attempts to visit a website or access a web application, the SWG performs a series of checks before the connection is allowed to proceed.
Traffic is routed to the SWG first. The gateway examines the destination, the content, and the context of the request against configured policy. Threat scanning identifies malware, phishing content, and other harmful material in the traffic. Based on all of these checks, the connection is allowed, blocked, or limited.
For example, if a user attempts to download a file, the SWG scans it before the download completes. If the destination is a known phishing site, access is blocked before the connection is established.
Most modern web traffic is encrypted using HTTPS. An SWG performs SSL/TLS inspection to decrypt this traffic, examine the content, and re-encrypt it before passing it along. This is essential for effective inspection, since encrypted traffic can otherwise conceal threats entirely.
Understanding how an SWG relates to other controls clarifies where it fits in the security estate.
A firewall controls network traffic based on IP addresses, ports, and protocols. It operates at the network layer and is less capable of inspecting application-layer content. An SWG focuses specifically on web traffic and applies content-aware inspection that a firewall cannot perform.
A VPN creates encrypted tunnels for secure remote access. It provides connectivity, but does not inspect the content of that traffic or enforce web access policies.
A Cloud Access Security Broker (CASB) secures cloud application usage, providing visibility and control over SaaS platforms specifically. An SWG covers all web traffic, including traffic that does not involve a managed cloud application.
DNS security blocks access to malicious domains at the domain resolution layer. It operates earlier in the request lifecycle than an SWG, and with less visibility into the actual content being accessed.
These controls are often used in combination. In a SASE architecture, SWG, ZTNA, CASB, FWaaS, and DLP are delivered together through a unified cloud platform, with consistent policy applied across all of them from a single management layer.
A Secure Web Gateway is one of the core components of a SASE architecture. In SASE, the SWG works alongside Zero Trust Network Access for application-level access control, CASB for cloud application governance, Firewall as a Service for network-level protection, and DLP for data security across all traffic types.
The advantage of this integrated approach is that security policy is applied consistently regardless of how a user is connecting, what they are accessing, or where the traffic is going. Changes to policy propagate across all components from one place. Telemetry from the SWG feeds into the broader security picture rather than sitting in a separate tool.
For regulated organisations, SASE integration also simplifies the compliance evidence picture. Controls are applied and logged from one platform rather than across separate tools that require individual evidence trails.
Key factors when evaluating an SWG include deployment model (cloud-delivered for maximum coverage across distributed users), performance (minimal latency through distributed points of presence close to users), integration with existing identity management and SIEM tools, and the granularity of policy controls available.
For regulated organisations, supplier assurance matters as much as technical capability. The provider’s accreditations, data residency posture, and support model are relevant alongside the feature set.
Implementation typically follows a phased approach: begin in monitoring mode to understand current usage patterns, introduce policy for high-risk categories, and expand enforcement progressively while addressing any issues that arise. Clear communication to users about what has changed and why reduces friction and improves adoption.
Cloud Gateway’s Secure Internet Access (SIA) product includes Secure Web Gateway capability as part of the managed platform. URL filtering, malware protection, SSL inspection, application control, and DLP are delivered together and managed under one operating model alongside the rest of the connected estate.
For regulated organisations, SIA is delivered from UK-based infrastructure with the governance, assurance evidence, and compliance alignment that NHS, government, and policing environments require. The SWG capability sits within the Protect pillar of the platform, alongside Managed Firewall, Secure Private Access (ZTNA), and Secure Application Access (WAF).
For more on how SIA works and how it fits into the platform, see our Secure Internet Access page and our platform page.