Coined by Gartner in 2019, secure access service edge (SASE) is a new approach to security and networking. The shift to remote work has expedited the current SASE market and continues to drive innovation. Check out this episode to learn about SASE from what it is, to the current market landscape, and the gray areas in between.
Hello, and welcome to 7 Layers. Where every episode we look at a technology that connects our world. From literal wires in the ground to switches and routers, and all the way up to the exploding amounts of smart devices around us.
Happy New Year and for those of you who are new around here, I’m your host, Connor Craven, associate studios editor at SDxCentral.
Subscribe to 7 Layers so you never miss an episode and tune into our next episode where we will talk all things SASE with an industry expert. And as always, you can learn more about the current state of technology over on SDxCentral.com.
Today we’re talking about SASE. No, not being sassy. But S-A-S-E, which stands for SASE edge. I promise to hold back on the sassy word play this episode but I do encourage you to read What’s So Sassy About SASE by Tobias Mann over on the SDxCentral website.
In this episode we will look at what makes SASE so sassy but we will also cover:
- What SASE is
- Key components of SASE
- Industry standardization
- SASE offering options
- Remote work shift
- Industry growth
- Future of SASE
Gartner coined the term SASE in the 2019 Hype Cycle Cloud Security Report. Deemed the future of network and security functions, at the time SASE was just an emerging technology and there was barely a SASE product on the market.
SASE, as defined by Gartner:
“Combines network security functions with WAN capabilities to support the dynamic secure access needs of organizations. These capabilities are delivered primarily as a service and based upon the identity of the entity, real time context and security/compliance policies.
So essentially, SASE is a new package of technologies including SD-WAN, secure web gateways, Cloud Access Security Broker, zero trust network access, and firewall-as-a-service as core abilities, with the ability to identity sensitive data or malware and the ability to decrypt content at line speed, with continuous monitoring of sessions for risk and trust levels.”
Despite being new to the industry, by summer 2020 multiple SASE offerings were on the market and thanks to the flexible definition of SASE — more on that later — the offerings varied widely.
The shift to SASE was here and it could not have come at a more urgent time. The COVID-19 pandemic and shift to remote work highlighted the need for infrastructure that supports flexible work options with secure remote access.
And SASE does just this. SASE enables enterprises to deliver secure networking and security in a consistent way in a remote environment.
But of course, SASE is more complex than that.
SASE is a network architecture that merges WAN capabilities with cloud-native security functions. These functions are provided as a service by SASE providers.
Though an emerging technology, SASE isn’t necessarily a new technology at all.
Instead, it is the convergence of existing network and security technologies built around a single pass architecture. This allows for an efficient network that has the ability to inspect traffic while in transit.
As the name suggests, SASE has two core components:
- Secure access
- And service edge
The service edge refers to the edge principle, where network functions are optimized by moving access and computing resources closer to individual users through the use of wide area networking, or WAN.
The edge is typically delivered through PoPs, or points of presence, close to the endpoints. PoPs may be owned by SASE vendors, public clouds, or a third party.
Secure access refers to the use of cloud-native security functions. There are four security functions commonly used in SASE. These are:
- Secure web gateways, or SWG
- cloud access security broker (CASB), or CASB
- Zero trust network access, or zero-trust network access (ZTNA)
- And firewall-as-a-service, or FWaaS
Let’s dive a little deeper into each of these functions.
A secure web gateway prevents data breaches and cyber attacks by protecting data and enforcing security policies. They filter out unsafe content from network traffic and can block unauthorized user behavior. They can be deployed from anywhere, making them a great option for remote workforces.
CASB performs various security functions from cloud-hosted services. It’s not a single technology, instead many technologies fall under the CASB umbrella. Technologies under CASB include shadow IT discovery, data loss prevention (DLP), access control, and others.
Zero trust network access is a security model that has strict, real-time identification requirements for every individual trying to access resources within a private network — whether they are in or outside the network perimeter. Several different principles and technologies are used for zero trust architecture.
And finally, firewall-as-a-service. FWaaS refers to firewalls delivered from the cloud as, you guessed it, a service. Cloud firewalls block cyber attacks directed at cloud assets through various security capabilities like URL filtering, intrusion prevention, and uniform policy management. This creates a virtual barrier around cloud platforms, infrastructures, and applications.
With these functions at its core, SASE can identify malware or sensitive data, and decrypt content, while continuously monitoring the session and assessing trust levels – all in real time.
Since SASE, in many cases, utilizes SD-WAN. It is important to make the distinction between the two clear.
SD-WAN’s primary responsibility is to connect geographically distant offices and headquarters to each other. Security tools are usually located at offices in customer premises equipment and not on individual devices
SASE, on the other hand focuses on connecting individual endpoints efficiently and securely — with an emphasis on the cloud.
As Neil MacDonald,distinguished VP analyst at Gartner said in an interview with SDxCentral, “The heavy lifting of SASE is performed in the cloud.”
Part of the reason why the line between SASE and SD-WAN gets muddled is because of inconsistencies within the industry.
As mentioned at the top of the episode, SASE, defined by Gartner, is:
“A new package of technologies including SD-WAN, SWG, CASB, ZTNA, and FWaaS as core abilities, with the ability to identity sensitive data or malware and the ability to decrypt content at line speed, with continuous monitoring of sessions for risk and trust levels.”
Other definitions out there highlight the fact that SASE is cloud based and is at its core a cloud-based approach to securing a WAN.
And others center around the idea that SASE puts the cloud at the center of the network versus having the network centered around a data center.
But, standardization and a precise definition are on the way. MEF, a non-profit global industry forum for network and cloud providers, has set out to clearly define SASE — much like they once did with SD-WAN.
In August 2020, MEF released a whitepaper titled MEF SASE Services Framework. The 17 page document builds upon previously established concepts of converged networking and security to propose and outline a framework for the standardization of SASE. This whitepaper will be used as the basis for the final SASE definition.
The official definition of SASE being fuzzy hasn’t stopped SASE from becoming a widely adopted model. And it makes sense why.
Organizations have been shifting to cloud-native Application and Software-as-a-Service, or SaaS, for some time now. And at the same time, networks are expanding into coffee shops or homes, and SASE can secure isolated users within a network.
These capabilities are what set SASE apart. Other benefits of SASE include:
Streamlined implementation and management: Since SASE merges multiple solutions into one service, enterprises can efficiently interact with vendors and spend less resources on maintenance.
Simplified management: SASE allows organizations to set, monitor, and enforce access policies across all locations, devices, users, and applications from a single portal.
Latency-optimized routing: SASE can reduce latency by routing network traffic across a global edge network. This is particularly important during remote work when video conferencing or steaming is prevalent.
Despite these benefits, as an emerging technology, SASE still has some drawbacks. Gartner advises early adopters sign short-term contracts and head of product for cloud security at Cisco, Raviv Levi warns enterprises about the three biggest mistakes to avoid when deploying SASE.
The three mistakes to avoid, according to Levi are:
- building a solution from too many building blocks
- relying on a complex infrastructure
- purchasing a solution that doesn’t fit individual business needs.
One of the biggest conversations in the SASE landscape is whether enterprises should opt for managed SASE or DIY SASE.
DIY SASE, is exactly as it sounds. This SASE model is built by acquiring the necessary services to have a SASE architecture, and deploying and managing them in-house.
This approach is common in the SD-WAN space. For example, many enterprises in North America currently have their security functions delivered as a service, but deploy SD-WAN themselves.
However, when it comes to SASE, this may not be the best approach.
Managed SASE relies on a managed service provider for SASE deployment and maintenance. Managed SASE is more efficient, scalable, and secure because it ensures experts can maintain, troubleshoot, and manage the various SASE services.
For example, just because a security function or SD-WAN is delivered as a service doesn’t mean the Enterprise has the knowledge to troubleshoot or manage it. Though, this may not be a day to day issue, it does pose a threat to security.
Gartner has gone so far as to call SASE “transformational.”
In the Hype Cycle report, Gartner reckoned “SASE will be as disruptive to network and network security architectures as [Infrastructure-as-a-Service] was to the architecture for data center design.”
In an interview with SDxCentral, Paul Kohler, principal consultant at Silicon Valley Technologies, said, “SASE is here to stay.”
More on that later. For now, a word from our sponsor.
As discussed before the break, SASE is made up of several different technologies. To offer a fully integrated SASE product, companies must take one of three approaches to building their product.
Approach one: SD-WAN vendors adding security features to its SD-WAN technology
Cisco took this approach with their SASE platform. Cisco integrates technology from Umbrella, Viptela, and Duo Security for its SASE platform. Umbrella contains most of the security features, Viptela is the large network that connects users to the SASE services, and Duo Security provides the cloud based zero-trust technology.
Approach two: Security vendors offer SASE services
Palo Alto offers SASE through Prisma Access service. Following the release of Gartner’s SASE definition, Palo Alto integrated its security and network services in a cloud-native software stack that closely aligned with the definition. Palo Alto’s SASE service has several security functions and leverages the networking technologies of CloudGenix’s SD-WAN, virtual private network connections, and quality of service policies.
Approach three: Vendors that had cloud-based SD-WAN infrastructures with integrated security elements then transitioned into SASE with the reveal of Gartner’s SASE description.
Cato Networks took this approach, before Gartner even coined the term SASE, Cato Networks had an SD-WAN product that mirrored SASE’s core functions. Cato was offering an SD-WAN product that was converged with security and delivered through PoPs — this was aligned almost perfectly with Gartner’s definition of SASE. Cato Networks SASE platform is described by the vendor as the first implementation of the SASE framework, as defined by Gartner.
As evidenced by Cisco’s and Palo Alto’s SASE products, integrating other company’s technologies is a common approach to building a SASE platform. These integrations can occur in one of two ways.
- Partnerships
- Or Acquisitions
Partnerships often occur between network and security vendors, allowing them to provide an integrated SASE offering. Both Zscaler and Netskope are well known for partnering with SD-WAN vendors.
Global Director Of Solutions Architects at Netskope, Joe Green even referred to partnerships as “a strategy that can deliver a much better SASE user experience,” at a Cybersecurity Insiders webinar.
The race to release SASE products also drove acquisitions. These acquisitions were made to build or improve existing SASE products. Some of the biggest SASE acquisitions in 2020 were:
- Palo Alto Networks’ $420 million acquisition of CloudGenix in March
- Fortinet’s acquisition of Opaq in July
- And VMware’s numerous acquisitions, most notably the Nyansa acquisition in January
As companies frantically built SASE products, the COVID-19 pandemic shifted workforces to remote-work environments. This shift expedited both the need and the adoption of SASE.
Kohler said:
“It’s going to be a massive sort of migration. The COVID, working from home dynamic has only accelerated this move to the cloud. It’s amplified by the fact that there’s actually going to be this migration from on-premise networking and security solutions to solutions that are cloud based.”
Or, in the words of Gartner, the cloud is finally being accepted by enterprises.
And that appears to be true. Global Director of Solutions Architects at Netskope Joe Green said to Cybersecurity Insiders that he has found over 85% of all Enterprise web traffic currently goes to the cloud.
Much like the cloud, remote work has been accepted as fate by many enterprises. And it doesn’t appear to be going anywhere.
In reference to both the cloud migration and remote work, VMware CEO Pat Gelsinger said, “This is a permanent change. We’re not going back.”
And it seems he is onto something. In December 2020, Google announced it wouldn’t return to the office until September 2021 and will do a flexible, remote work and in-person hybrid upon its return to the office.
Meanwhile Facebook, Twitter, and Microsoft have announced an indefinite work-from-home policy.
A Gartner survey of 229 human resources leaders from April showed that nearly 50% of organizations shifted at least 80% of their employees to remote work. Global Workplace Analytics predicts between 25% and 30% of those people will continue to work from home permanently.
And the impact of remote work on emerging technologies, like SASE, is clear.
Versa CMO, Mike Wood said the pandemic drove a 100-fold increase in its SD-WAN or SASE platforms from the beginning of 2020 to December 2020. More than 200 Tb/s of traffic now flows from home offices through its SASE PoPs, he added.
Aryaka experienced similar growth this year when it came to their SD-WAN and security combination offerings. Aryaka CEO, Matt Carter said:
“We thought it would take a few years before SASE would become more mainstream. But we think that it is fast-tracked because of the pandemic, and we’re seeing more and more customers looking for this combination of SD-WAN and security.”
Gartner’s 2020 Magic Quadrant WAN Edge Infrastructure report from September 2020 shows the SD-WAN and SASE market is hotter than ever. The report highlights no fewer than six industry leaders in the space, up from a mere two the year before.
VMware and Silver Peak, 2019’s two leaders, were joined this year by Versa and Palo Alto, and Cisco and Fortinet. Vera and Palo Alto ascended from visionary status to leaders in 2020, while Fortinet and Cisco made the jump from challenger to leader.
This growth is indicative of the success industry leaders are experiencing. Palo Alto Networks’ CEO Nikesh Arora praised the success of its SASE offering, Prisma Access SASE platform. Arora said Prisma Access achieved a reported $90 million in billing during the fourth fiscal quarter of 2020.
All this to say, SASE does not appear to be going anywhere.
Come year end of 2020, even Forbes dubbed SASE the future of network security. Stating that SASE serves the modern workforce in ways other technologies are unable to — SASE is able to converge network and security functions in an elastic and scalable way that is ideal for distributed workforces.
Dell’Oro Group, a telecommunication market research firm, echoes both of these experiences. The firm expects the SASE market will grow at a Compound Annual Growth Rate of 116%, achieving a market value of $5.1 billion by the year 2024.
Dell’Oro Group Research Director Mauricio Sanchez claims this growth is driven, at least in the short term, by the small to mid-sized business market.
While Gartner anticipates that by 2024, at least 40% of enterprises will have explicit strategies to adopt SASE — up from less than 1% at the end of 2018.
The SASE market continues to grow and the technologies continue to evolve, creating space for a fully integrated SASE platform to be built. As dependance on the cloud increases and enterprises adjust to distributed workforces, SASE will continue to become a mainstream networking and security option.
And now, a quick word from our sponsor.
Thanks for joining us on this week’s episode of Seven Layers. Special thanks to SDxCentral Studios Editor Ashley Wiesner for writing our script.
Before you go let’s do a brief overview of what we discussed today:
- What SASE is
- Key components of SASE
- Industry standardization
- SASE offering options
- Remote work shift
- Industry growth
- Future of SASE
I’ve been your host, Connor Craven, associate studio editor at SDxCentral. Subscribe to 7 Layers so you never miss an episode and tune into our next episode where I will be interviewing an expert on SASE. And as always, you can learn more about the current state of technology over on SDxCentral.com.
Comments