Traditional enterprise networks are failing to keep up with the demands placed on them by both fast-growth technologies, such as artificial intelligence (AI), big data, and IoT, and by the need to deliver secure connectivity to branch offices, partner sites, and a workforce that keeps venturing further and farther away from the office.
Many enterprises deployed a combination of MPLS and cloud-based WAN technologies to address these challenges, typically SD-WANs. However, this approach eventually poses additional challenges as security has yet to be integrated into the core networking stack, which forces enterprises to introduce a patchwork of tools and services from different vendors. The maintenance and management burdens alone put these solutions out of reach for many organizations.
Gartner In a 2019 report, “The Future of Network Security is in the Cloud,” outlined its vision for a simpler, converged, cloud-native networking and security service that it called secure access service edge (SASE). Gartner analysts Lawrence Orans, Joe Skorupa, and Neil MacDonald argued that “the legacy ‘data center as the center of the universe’ network and network security architecture is obsolete and has become an inhibitor to the needs of digital business.”
The Gartner analysts then laid out a new vision for WAN-security integration, positing that what is needed to serve the modern, digital enterprise is a cloud-delivered service that combines “comprehensive WAN capabilities with comprehensive network security functions,” such as secure web gateway (SWG), cloud access security broker (CASB), firewall-as-a-service (FWaaS), and zero-trust network access (ZTNA).
In the years since Gartner’s report defined the space, COVID-19, the persistence of work from anywhere, and the expanding enterprise edge have accelerated the need for a networking-security redesign that focuses on modern enterprise challenges. As the service best situated to meet those challenges, SASE has exploded into a multi-billion-dollar market that Gartner predicts will grow at a 29% compound annual growth rate (CAGR) through 2026, to reach $25 billion in 2027.
Are SASE vendors missing bigger transformational opportunities?Today, most vendors sell SASE (and pretty much every security product) through fear. If you don’t modernize your enterprise WAN and security services, they argue, your organization will be at risk. They’re not wrong. The rise of ransomware, advanced persistent threats, and AI-created malware threaten to take advantage of the expanding attack surface of the distributed, digital enterprise, and without modern defenses, organizations risk falling victim to distributed denial of service (DDoS) attacks, ransomware, and IP theft.
This fear is rational and focused on real threats, but what is often overlooked when discussing the threat landscape is the fact that SASE is not simply another security layer. When deployed strategically, SASE can serve as the foundation for bigger transformations.
In a globally connected world, security threats are not the only threats to the enterprise bottom line. Rising labor costs, a shrinking IT labor market, and many outdated manual processes that mire IT specialists in grunt work all negatively impact the bottom line.
What that means is that SASE, to be truly transformational, must deliver more than just consolidation.
SASE and the evolving global threat landscapeThe traditional patchwork of MPLS, Internet Protocol Security (IPSEC) VPNs, and SD-WAN was designed for a different era when resources were on-premises and WAN connectivity was primarily for branch offices. Today, more assets are in the cloud than within the corporate perimeter, and traditional architectures are simply not up to the task of securely connecting them through a vanishing perimeter.
While the traditional corporate perimeter fractures, the threat landscape continues to worsen. State-sponsored attacks, advanced persistent threats, and AI-powered malware all pose new threats. At the same time, enterprises must support multiple public and private clouds; remote and mobile workers; and IoT networks.
Zero-day attacks are also on the rise, with Google finding zero-day exploits increased 50% in 2023. Attackers are also increasingly targeting critical infrastructure, launching attacks against appliances from Barracuda, Cisco, and Trend Micro in the past year. Worse, Google researchers found that state-sponsored groups were behind zero-day exploits.
While the threat landscape becomes increasingly complex and dangerous, the enterprise perimeter must now expand to include remote and mobile workers, partners, branches, multiple clouds, and IoT networks. Add it all up and there is a severe mismatch between legacy networking and security architectures and the need to deliver digital assets.
SASE and strategic transformationIn the rush to plug security gaps, many organizations fail to take a longer view. One of the main problems with legacy architectures is that security has always been bolted onto networking as a separate layer. With security tightly integrated into the core of WAN infrastructure, however, SASE can serve as the foundation for larger business transformations.
With many mission-critical assets now in the cloud, traditional hub-and-spoke networks with perimeter protections don’t meet modern requirements. Legacy architectures undermine the goals of digital transformation initiatives, while siloed networking and security from different vendors increase costs, complexity, and ongoing management and maintenance demands.
Consolidating networking and security functions into a single, unified, cloud-native service represents a major transformation in how enterprises deliver secure access to critical resources.
SASE leverages zero-trust principles so end users and devices can authenticate from beyond the traditional perimeter, gaining secure access to resources they are authorized to reach in a secure, compliant way. As a consolidated service, SASE also eliminates numerous siloes, replaces dated technologies like VPNs, and automates numerous manual networking and security tasks.
A strategic SASE approach goes beyond security and network convergence. It unlocks a transformative power for the entire business.
Four steps to a secure, speedy, and reliable networkFocus on technologies that simply work
Even with multiple security layers, attackers still get through traditional perimeter protections. To keep up with the current threat landscape, enterprises need a converged networking and security solution that just works. Vendors will customize their offerings to meet your needs, but every custom step creates another potential point of failure that your IT team must manage.
In a cut-throat, rapidly evolving market, enterprises need fewer one-off customizations in favor of solutions that simply work. Enterprises need security tools that prevent attacks before they damage the business while delivering consistent, reliable connectivity.
Streamline operations
As SASE has matured, advanced features help organizations automate manual tasks. By automating repetitive tasks and outsourcing others to your SASE provider, your IT team will be freed up to pursue value-added projects, rather than simply trudging through grunt-work to-do lists.
Refocus on the business of your business
The divide between the business side of the organization and the IT side seems wider than the Grand Canyon. Tech leaders often speak about this as the convenience vs. security tradeoff, and most business leaders emphasize convenience, which more directly maps to positive business outcomes. With networking and security converged into a managed service, organizations are better able to align business and IT goals, pursuing more strategic business outcomes.
Unleash the true talents of your workforce
No IT pro enjoys the constant grunt work of ongoing maintenance. Whether it’s having to patch hundreds of vulnerabilities in a huge set of firewall appliances, needing to replace a box that has maxed out, or spending a weekend testing high availability in a maintenance window, IT is better served if they can offload these table stakes activities. These essential, yet easy-to-forget and dismiss chores, are ideal for automation, which frees up IT professionals and executives to focus on higher-value projects.
Comments