| CPC H04L 63/1416 (2013.01) | 17 Claims |

|
1. A method, comprising:
receiving, from a cloud-based security system, information about a device that is coupled to a public network and decoupled from a private network, wherein the information is generated based on network traffic from the device over the public network;
detecting, based on the information, risky activity associated with the device;
determining that the information indicates an application installed on the device is performing the risky activity on the device; and
sending, by a processing device, instructions to a remote agent executing on the device to perform one or more security measures that protect a resource of the device, wherein the instructions instruct the remote agent to prohibit the application installed on the device from accessing the resource on the device.
|