What is a Secure Web Gateway (SWG)? A complete guide

A Secure Web Gateway inspects and controls web traffic to protect users from internet-borne threats, enforce policy, and prevent data leaving the organisation. This guide covers how SWGs work, key capabilities, and how they fit into a well architected network.

What is a Secure Web Gateway?

A Secure Web Gateway (SWG) is a security control that sits between users and the internet, inspecting web traffic in both directions and applying security policies in real time. It blocks access to malicious or policy-violating destinations, prevents malware from reaching users via the web, and stops sensitive data from being transmitted to unauthorised locations.

Where traditional firewalls control traffic based on network-level attributes like IP addresses and ports, an SWG operates at the application and content layer. It understands what is being accessed, not just where traffic is going.

SWGs can be deployed as cloud-delivered services, on-premise appliances, or in hybrid configurations. Cloud-delivered SWGs are increasingly standard because they protect users wherever they connect from, regardless of whether they are on the corporate network. For organisations with hybrid workforces or multiple sites, this matters significantly.

How does a Secure Web Gateway work?

An SWG examines all web traffic passing between users and the internet. When a user attempts to visit a website or access a web application, the SWG performs a series of checks before the connection is allowed to proceed.

Traffic is routed to the SWG first. The gateway examines the destination, the content, and the context of the request against configured policy. Threat scanning identifies malware, phishing content, and other harmful material in the traffic. Based on all of these checks, the connection is allowed, blocked, or limited.

For example, if a user attempts to download a file, the SWG scans it before the download completes. If the destination is a known phishing site, access is blocked before the connection is established.

Most modern web traffic is encrypted using HTTPS. An SWG performs SSL/TLS inspection to decrypt this traffic, examine the content, and re-encrypt it before passing it along. This is essential for effective inspection, since encrypted traffic can otherwise conceal threats entirely.

Key capabilities

  • URL filtering controls which websites users can access by categorising destinations based on content and reputation. It blocks known malicious sites, enforces acceptable use policies, and limits access to non-work content where appropriate. URL filtering databases are continuously updated to reflect new threats and newly categorised sites.
  • Malware protection scans web traffic and downloads for malicious code in real time. Modern SWG malware protection typically combines signature-based detection of known threats, behavioural analysis to identify suspicious patterns, and sandboxing to test unknown files in an isolated environment before they reach the user.
  • Data loss prevention (DLP) monitors outbound web traffic for sensitive data patterns. It can identify personal information, financial data, health records, and confidential documents, and block or alert when an attempt is made to transmit that data to an unauthorised destination.
  • Application control provides granular management of web-based application usage. Rather than simply blocking or allowing an entire application, it can permit certain functions while restricting others. A user might be allowed to view cloud storage content but blocked from sharing files externally, or permitted to use a collaboration platform while being prevented from exporting data.
  • SSL/TLS inspection decrypts HTTPS traffic for content examination and re-encrypts it before forwarding. Without this capability, an SWG cannot inspect the majority of modern web traffic. Implementations typically allow exceptions for privacy-sensitive categories such as banking or healthcare sites.

SWG compared to other security controls

Understanding how an SWG relates to other controls clarifies where it fits in the security estate.

A firewall controls network traffic based on IP addresses, ports, and protocols. It operates at the network layer and is less capable of inspecting application-layer content. An SWG focuses specifically on web traffic and applies content-aware inspection that a firewall cannot perform.

A VPN creates encrypted tunnels for secure remote access. It provides connectivity, but does not inspect the content of that traffic or enforce web access policies.

A Cloud Access Security Broker (CASB) secures cloud application usage, providing visibility and control over SaaS platforms specifically. An SWG covers all web traffic, including traffic that does not involve a managed cloud application.

DNS security blocks access to malicious domains at the domain resolution layer. It operates earlier in the request lifecycle than an SWG, and with less visibility into the actual content being accessed.

These controls are often used in combination. In a SASE architecture, SWG, ZTNA, CASB, FWaaS, and DLP are delivered together through a unified cloud platform, with consistent policy applied across all of them from a single management layer.

SWG in a SASE architecture

A Secure Web Gateway is one of the core components of a SASE architecture. In SASE, the SWG works alongside Zero Trust Network Access for application-level access control, CASB for cloud application governance, Firewall as a Service for network-level protection, and DLP for data security across all traffic types.

The advantage of this integrated approach is that security policy is applied consistently regardless of how a user is connecting, what they are accessing, or where the traffic is going. Changes to policy propagate across all components from one place. Telemetry from the SWG feeds into the broader security picture rather than sitting in a separate tool.

For regulated organisations, SASE integration also simplifies the compliance evidence picture. Controls are applied and logged from one platform rather than across separate tools that require individual evidence trails.

Choosing and deploying an SWG

Key factors when evaluating an SWG include deployment model (cloud-delivered for maximum coverage across distributed users), performance (minimal latency through distributed points of presence close to users), integration with existing identity management and SIEM tools, and the granularity of policy controls available.

For regulated organisations, supplier assurance matters as much as technical capability. The provider’s accreditations, data residency posture, and support model are relevant alongside the feature set.

Implementation typically follows a phased approach: begin in monitoring mode to understand current usage patterns, introduce policy for high-risk categories, and expand enforcement progressively while addressing any issues that arise. Clear communication to users about what has changed and why reduces friction and improves adoption.

How Cloud Gateway delivers SWG

Cloud Gateway’s Secure Internet Access (SIA) product includes Secure Web Gateway capability as part of the managed platform. URL filtering, malware protection, SSL inspection, application control, and DLP are delivered together and managed under one operating model alongside the rest of the connected estate.

For regulated organisations, SIA is delivered from UK-based infrastructure with the governance, assurance evidence, and compliance alignment that NHS, government, and policing environments require. The SWG capability sits within the Protect pillar of the platform, alongside Managed Firewall, Secure Private Access (ZTNA), and Secure Application Access (WAF).

For more on how SIA works and how it fits into the platform, see our Secure Internet Access page and our platform page.

Related Articles

Want to know more about how we work?