Google's new enterprise security architecture now hosts its internal apps on the Internet, shifting to device-level instead of network-level trust for security
Google Moves Its Corporate Applications to the Internet — Google Inc., taking a new approach to enterprise security …
Context & Ripple Effects
This WSJ report is the origin point of what later became Google's BeyondCorp playbook: instead of guarding a corporate network, Google puts its own internal applications on the public Internet and makes the verified state of each employee's device the security boundary. The related coverage shows how deliberately this was built out — Google documented the architecture in a published paper on its cloud security strategy two years later, then began turning the internal system into sellable infrastructure.
The commercialization is visible step by step: Google offered the cloud identity technology from G Suite as a standalone developer service, shipped BeyondCorp Remote Access so employees could reach internal web apps without a VPN, layered zero-trust and data-loss-prevention controls into Workspace, and finally consolidated everything under Google Cloud Unified Security. The 2015 move matters because every one of those products descends from it.
First-order effects
- Google employees lose the corporate VPN as their access mechanism — reaching an internal app now depends on device posture checks rather than being inside the perimeter.
Second-order effects
- Security vendors whose business rests on network-perimeter appliances face a reference customer of Google's scale arguing the perimeter is obsolete, pressuring rivals like Microsoft and Cisco to build equivalent identity- and device-trust offerings.
Third-order effects
- If the pattern holds, enterprise security spending migrates from firewalls and VPNs toward device attestation and identity services sold as cloud subscriptions — exactly the trajectory Google's later Workspace and Cloud security launches trace.
The trend: Enterprise security is moving from trusted networks to trusted devices and identities, with Google converting its internal architecture into a product line that defines the category.