The trend of cloud transition is the primary driver of the zero-trust edge adoption, Forrester Senior Analyst Heath Mullins noted during his keynote address at this week’s Forrester Security and Risk event.

Mullins defines zero-trust edge as a solution that securely connects and transports traffic, which is based on the cloud but can be in hybrid-cloud environments while using zero-trust access principles. It is “in and out of remote sites leveraging mostly cloud-based security and networking services.”

The components for zero-trust edge include secure web gateway (SWG), SD-WAN, cloud access security broker (CASB), and zero-trust network access (ZTNA). Mullins noted some vendors in the market already offer “full-service” solutions that have all those elements.

The concept is similar to another analysis firm Gartner’s definition of secure access service edge (SASE). The firm noted that SASE offers converged network and security as-a-service through SWG, SD-WAN, ZTNA, and next-generation firewalls. And SASE can support on-premise, remote worker, and branch office use cases.

Both firms find organizations are increasingly adopting this kind of solution. And Mullins pointed out that the shift to the cloud is driving the trend. A recent Forrester report showed that 84% of the surveyed respondents are adopting the public cloud.

He said organizations are putting their infrastructure into the cloud for ease of use and simplicity, which is in line with the common use cases of zero-trust edge, such as securing the hybrid workforce, enabling a cloud-first migration strategy, and reducing the complexity of the network.

“Everybody has a cloud property, whether it's hosted internally, externally, public cloud, private cloud,” Mullins said. “By reducing the complexity of the network, with these ease-of-use technologies, you're actually providing your analysts, your professionals with the ability to more effectively defend your network with a very small subset of tools that cover an awful lot of ground.”

Zero-Trust Edge Benefits

Mullins noted there are a number of benefits to adopting zero-trust edge technologies into enterprises.

First of all, one of the core benefits of implementing zero trust is to knock down the internal pillars and bring teams together to ensure everybody is on the same page, he said.

Additionally, it can empower security analysts and strengthen organizations’ security posture. It improves the incident response capabilities and makes troubleshooting easier for analysts, according to Mullins.

And the zero-trust edge also can help reduce the security vendor numbers. “It's an enabling group of technologies. It can be a single vendor, [and] you can get these technologies from multiple vendors,” Mullins said.

Before choosing zero-trust edge vendors, “I highly suggest that you make sure that their integration story is very tight and they can clearly and explicitly define how it works, why it works, and any caveats that may come up,” he added.