Netskope chief strategy officer Jason Clark spends a lot of time talking to chief information security officers (CISOs) and CIOs to better understand how to protect their businesses.
“Every day I talk to at least two CISOs and CIOs. If I haven’t talked to two CISOs and CIOs by the end of the day, I will find someone to talk to and work till seven,” he boasted in an interview with SDxCentral.
The insights from these conversations, he argues, give Netskope the edge among the growing pack of security services edge (SSE) and secure access service edge (SASE) vendors, and offer a glimpse into the real-world challenges customers are grappling with.
Ready or not, SSE’s benefits are real
One of the biggest misconceptions about SSE is what makes it valuable, Clark explained.
The real value of SSE isn’t that it’s cloud-based or that, because it’s cloud-native it’s more scalable – though these factors do help, he said. It’s that “you’ve created one brain” for security intelligence.
He describes SSE as being much like the human nervous system, complete with five different senses: smell, hearing, seeing, touch, and taste.
These senses are analogous to the litany of security functionality wrapped up in Gartner’s SSE product category, including Cloud Access Security Broker, zero trust network access (ZTNA), secure web gateway (SWG), and data loss prevention (DLP), among others.
“If there’s a fire and I can only hear, I hear crackling. I’ve got one system that listens to crackling, and I’ve got another system that feels for temperature, and another system that smells smoke, and I have another sense that sees [light],” he said. On their own, these senses only provide part of the picture, but when those contexts are shared, you know there’s a fire.
SASE and SSE barriers to entry
But while SSE manages to tie together many of SASE’s more desirable security features, Clark argues that few vendors manage to link them back to a single brain, and even fewer manage to incorporate networking without significant compromise.
“Most vendors are either really good at security or really good at networking,” he said. “Then there’s some people trying to do a little bit of both in the middle, of which nobody does them that good and nobody is good at it all.”
Clark singled out Palo Alto Networks as a prime example. The company combined its Prisma Access and Prisma SD-WAN services into a single service late last fall. He argues, the integration isn’t particularly tight.
“If you want an unintegrated solution that is really focused on firewall rules, which means basically it’s looking at the port protocol, not looking at the data … then that’s the solution for you,” Clark said of Prisma SASE.
By his estimate, single-vendor SASE is at least five years away and probably closer to 10 years away from practicality.
Driving some of this is that building the security stack necessary to offer a single-vendor SASE platform is substantially more costly than networking, Clark said. “The SSE barrier to entry and [research and development] costs is through the roof.”
Internal politics are complicating SSE adoption
As a result, Netskope expects the vast majority of businesses will prefer a two-vendor SASE architecture, but even this isn’t without challenges. SSE faces cultural challenges within organizations as well, Clark notes.
“Almost every company I talk to has a different VPN solution, a different secure web gateway, and a different CASB. Almost 80% of companies have three different solutions still,” Clark said, adding that this is further complicated by the fact that the budgets for these tools are spread between the respective networking and security teams.
“A hundred percent of the CASB budget is security; 30% of the SWG budget is security, and 70% was in networking; and I’d say 90% of VPN was in networking and 10% in security,” Clark said, describing the average customer.
With SSE, these budgets have to be consolidated to support a single product touching both teams, and this means asking difficult questions.
“What do we do? Who owns this? Who makes the decision? These are the political challenges happening inside every company right now,” Clark said. “This has to be a joint project because it’s a networking thing as well.”
Comments