Secure access service edge (SASE) is a networking and security architecture that converges SD-WAN with security features — such as secure web gateway (SWG), cloud access security broker (CASB), firewall-as-a-service (FWaaS) and zero-trust network access (ZTNA) — into a single cloud-native service.
It has rapidly grown from a niche, security-first SD-WAN alternative into a top WAN market sector. In Gartner’s December 2023 report “2024 Strategic Roadmap for SASE Convergence,” the firm notes that since 2019, “industry and client interest in SASE has exploded, primarily driven by existing enterprise needs not being met by existing vendors.” Gartner predicts that the market will continue to expand, growing at a 29 percent compound annual growth rate from 2021 through 2026 to reach $25 billion in 2027.
Research firm the Dell’Oro Group is also bullish on the SASE market. According to Dell’Oro Group’s latest research, the SASE market jumped 31 percent in 2023 to record annual revenues of $8.4 billion. However, for businesses investigating their WAN options, confusion abounds. MPLS, SD-WAN, SASE, SSE, business broadband and 5G are all options, and many enterprises end up deploying different WAN services for different use cases.
The guide below will walk you through the SASE buying process. We’ll help you understand the table stakes, who the main players are, what questions to ask and what pitfalls you must avoid.
Why you need SASEWhen SASE emerged as an alternative to SD-WAN, the focus was on bringing enhanced security features to the WAN. With many business-critical assets now in the cloud, enterprises needed cloud-based security alongside their cloud-based WAN networks. COVID-19 and the rise (and persistence) of work from homeWFH (work from home) accelerated the need to not only expand the WAN, but also secure it in a way that didn’t add excessive management overhead for already overworked IT teams.
Enterprises that must provide secure WAN connectivity to branches, new sites from M&A, public clouds, remote workers, partners, IoT networks, OT networks, etc. stand to benefit from the convergence of networking and security into a single cloud-native service.
Key featuresNetworking features include WAN optimization, SD-WAN, SaaS acceleration, caching, content delivery network (CDN) and bandwidth aggregation. These features are converged with a range of security features, including encryption, multifactor authentication (MFA), CASB, data leak prevention (DLP), DNS, FWaaS, secure web gateway and ZTNA.
Features will vary, and vendors are already investing in advanced capabilities, such as AIOps and AI networking, support for 5G-based WAN links and behavior- and context-based security capabilities.
Implementation and supportAccording to Gartner, at least 80 percent of enterprises will have concrete strategies and timelines in place for SASE adoption by 2025. This is up from just 20 percent in 2021.
For many enterprises, the adoption of SASE will be part of larger digital transformation efforts, and since many vendors offer tiered service plans, adoption is often best timed with the expiration of WAN contracts and legacy firewall, VPN and other security licenses.
A big selling point of SaaS is its simplicity. This is true of SASE, which as a cloud-native service is much simpler to deploy and manage than multiple physical networking and security appliances. One of SD-WANs original selling points versus legacy WAN services, such as MPLS, was the short deployment cycle, days or weeks versus months. Even with consolidated services under its hood, SASE’s adoption timelines are similar to SD-WAN.
Connecting to the service is also straightforward. Some vendors offer hardware appliances to connect edge users and devices to nearby PoPs to join their SASE networks, but most vendors handle the connections through software clients or virtual appliances.
SASE is typically consumed as a single service, but some features may come from partners.
Ongoing support is built into SASE, but service levels vary. A large part of SASE’s appeal is the ability to transfer maintenance and management burdens over to service providers.
Alternatives to SASEAlternatives to SASE run the gamut from MPLS to SD-WAN to 5G on the networking side and standalone firewalls, VNPs, DLP solutions, etc. on the security side. Today, it’s not uncommon for an enterprise to have a complicated mixture of services, with MPLS from one vendor, SD-WAN from another, and VPNs from yet another and that’s just on the connectivity side.
The goal for most SASE and SD-WAN vendors is to build out an all-in-one platform, although most currently rely on partnerships or white labeling to fill out their SASE stacks.
Notable SASE vendorsAccording to such research firms as Gartner and Dell’Oro Group, the leading SASE vendors include Cato Networks, Cisco, Cloudflare, Forcepoint, Fortinet, HPE, Juniper, Netskope, Palo Alto Networks, Versa Networks and Zscaler.
5 questions to ask SASE vendors- What is your company’s core expertise — networking or security? That is, if the vendor started as a networking company, investigate how they developed the security side of their stack or if they got it from a partner.
- How flexible is your service? That is, can you expand to new sites, more bandwidth and additional services as needed? Just as importantly, are we able to throttle down without incurring penalties?
- How well does your footprint of PoPs correspond to our locations and the location of key cloud and SaaS providers?
- Have you integrated AIOps and automation capabilities into your platform?
- How do your SLAs and service guarantees compare to competitors
- Taking shortcuts in the pilot phase. Testing the service with real-world sites and end users/applications is critical. Skimping on the pilot may lead you into other pitfalls listed below.
- Failing to account for legacy applications. Specialized mission-critical applications may not function well in a SASE environment.
- Adopting the wrong model. SASE comes in three basic models: single vendor, multivendor and managed SASE. While SASE isn’t as complicated as hardware-based networking and security, managing SASE still requires skill. For instance, if your organization has limited internal IT capabilities, managed SASE is probably your best bet.
- Poor integration. The SASE space is all about convergence, and this is true of not just the service, but also the vendors in the space. Some started as networking companies, while others launched as cybersecurity ones. Thus, many vendors arrived at SASE by acquiring, partnering, or white-labeling the side of the stack that falls outside of their expertise. Investigate how well other features have been integrated into the core service.
- Cloud lock. One of the advantages of SaaS was supposed to be the shattering of silos and vendor-lock. The reality has been less rosy. Investigate how easy it is to change service providers, integrate best-in-breed services from other vendors and throttle down or even turn off features you no longer need.
Comments