Software-enabled servers have allowed networking teams to do more with less, leading to a burst of agility across the industry. But new networking approaches have also led to tool sprawl and a lack of governance over servers everywhere, Tony Garcia, director of security evangelism at Versa Networks, said in a webinar. 

Garcia added the emergence of virtual networking and multi-cloud environments has created networking and security complexity that enterprises “really want to get ahead of and start designing, or it can quickly cause complications.”

As more enterprises and vendors react to the changing landscape by pursuing secure access service edge (SASE) – Gartner’s term for a converged networking and security architecture – Garcia says organizations with “good governance and structure” will be better able to manage this convergence. 

He said many organizations have scrambled to jump on the SASE wave without the proper thought and time, adding “It's kind of like a child with a new toy, you go create all these environments, and they're maybe not being managed the way they should be.”  

Don’t Forget About the Network

Garcia explained that identity focused SASE technologies are great from a security and visibility perspective, because security teams don’t “have to do so much looking at IP addresses and MAC addresses and users and correlating all that.” 

Although, Garcia added the identity context also leads teams to forget about the network side of things. “The networking tends to be assumed it's taken care of. And I think it does require more planning, and probably more design and structure to get it right at the software layer,” he said. 

Beth Cohen, cloud technology strategist at Verizon, said during the webinar that “applications teams and, to a certain extent, security teams, tend to think of networks as transport.”

“But of course, they're vastly more than that. And I think that the move to the cloud has really driven a different way that networks are actually consumed,” she said. 

Cohen noted the industry is seeing more hub-and-spoke type network traffic than ever before, because as applications move into the cloud, the need for security and where the security is in the network has changed. 

While Cohen conceded there is “no such thing” as a 100% secure network, she said operations teams can work to identify risks and decide how much they are willing to spend to mitigate each potential threat. 

“That's so important for the SSE and the SASE which is that you need to make sure that you're protecting the assets we have,” she said. “It’s a balancing act.” 

Stop Siloed Thinking

Cohen said traditionally, security and networking technology “really grew up separately, and the organizations grew up separately as well.” 

In the past, so many companies had networking teams and then added security teams, but frequently each team reported into different parts of the organization, which Cohen explained leads to problematic siloed thinking. 

“They tend to not particularly talk to each other and their skill sets are not 100% in alignment,” she said. “So that can lead to challenges when you're trying to merge these two very important components of your IT infrastructure stack.”

Cohen suggested network operations and security teams work together to figure out what and where the problems are by using the same platforms and tools as they build out a SASE portal. 

She noted Verizon has started “a lot of cross training” between not only its security and networking teams but sales and other teams as well, adding “you need to be able to talk the language, because you're going to be talking to the security people, you're going to be talking to networking people and you need the context to switch between the two.”

Making sure that everybody's “on the same team” and knowing who is responsible for what, Garcia added, enables true multi-tenancy across security and network operations organizations. 

“Between the networking security you’ve got to keep those lines of communication open and not build those walls, or that split starts to happen,” he said. 

Consolidate SASE Technology

The industry is at “an inflection point where there’s a real recognition that you can’t continue doing business the way we've been doing it for the last 25 years,” Cohen said. She added that in the past, technology like zero-trust network access (ZTNA), virtual private networks (VPN), and cloud access security broker (CASB) have also been siloed. 

Cohen said that because they're all aspects of the SASE “elephant in the room,” it makes sense to consolidate the integration of these tools. “A single vendor approach to SASE really simplifies things,” she added. 

Companies that offered these services separately add cost management and administrative overhead for enterprises pursuing SASE, according to Cohen. 

“We do have some integration points there, but I think this is a place as an industry [where] we could do a lot better,” Garcia said. “I think we do have a lot of innovation in this space, but not necessarily a lot of standardization at this point.”

SASE is a fairly new technology, Garcia said, adding, “These things take a while to kind of be sorted out with the baseline standard set.” Still, he added “I think we should push the vendors to have more integration points, more API awareness. I think certainly moving forward that's important.”