Enterprises are increasingly adopting 5G, citing its low latency, high capacity and increased bandwidth.
But as the technology expands and alters network perimeters and architectures, it increases breach risks. Dispersed networks can be difficult to secure, and the diversity of IoT devices pose their own security and authentication challenges.
This, some say, makes 5G and the emerging technology known as secure access service edge (SASE) a strong pairing.
“IoT opens up a lot more vectors that have to be secure that didn’t have to be prior to 5G,” Donna Johnson, chief marketing officer for Cradlepoint, told SDxCentral. “With increasing use of 5G, secure access service edge (SASE) is only going to become more important.”
How 5G and SASE complement each otherAccording to IDC, investment in the IoT ecosystem — from sensors to cams to automation systems — is expected to surpass $1 trillion by 2026, and worldwide spending on IoT in 2023 was $805.7 billion, an increase of 10.6% over 2022.
“There is a dramatic rise in the use of IoT in enterprises,” said Johnson. “IoT is the fastest growing area of connected devices.”
In tandem with this, the 5G network security market is projected to reach $21 billion by 2027. Similarly, the SASE market will hit close to $6 billion in 2028, representing a compound annual growth rate (CAGR) of 25%.
SASE, which was coined in 2019 by Gartner analysts, combines WAN and SD-WAN functions with network security tools, delivered as a cloud-based service. The capability automatically applies firewalls, zero trust and other types of security policies, and is touted for its scalability, simplicity, ease of use and cost savings. SASE is also said to improve network reliability, enhance network visibility, ensure consistent policy enforcement and remove the need for traditional VPNs.
“It’s really a recognition of a trend in the market of consolidation of networking and security,” said Johnson, who also serves as head of marketing for Ericsson’s business area enterprise wireless solutions. “Those used to be two very separate systems. It’s typically saying that network and security are intertwined.”
Cradlepoint is a leader in 5G SASE, along with Netskope, Versa Networks, Fortinet, NordLayer, Exium, Open Systems and others.
SASE and 5G are naturally complementary, Steve Foster, manager for solutions engineering in EMEA for Netskope, wrote in a blog post.
Their union provides users “direct, unhindered, secure and controlled access” to software-as-a-service (SaaS), web and zero-trust network access (ZTNA) applications, he said.
“5G and SASE have the promise to disrupt the traditional networking and cybersecurity space,” Foster asserted.
Securing an expanding perimeterIn a traditional office setting, known devices are connected to a secure network, traveling across protected WANs to data centers and the cloud, Johnson explained. The perimeter of that network is controlled within the premises of the business.
“5G has opened up the ability for the business to expand beyond that perimeter,” she said. “The enterprise's boundary through 5G is expanding.”
The concern with the increased adoption of both public and private 5G — and one of the biggest issues with IoT — is that of user connections outside the corporate environment. For example, interactive devices such as digital signage connect to 5G without going through a firewall or router. Also, employees are increasingly logging on to networks from home, coffee shops and other pop-up locations.
“These devices are connecting in the wild,” said Johnson. “SASE becomes more important. You have to have cloud security, you can’t just have on-prem security or data center security.”
Security policies must be enforced no matter where a connection occurs, she noted. Facilitating this, 5G SASE doesn’t just recognize people, but things, too, and applies security policies accordingly.
“You start with the presumption that you have devices and people outside the network perimeter,” said Johnson. The technology is geared to a “new type of enterprise that is wildly distributed.”
Zero trust at the core of enterprise 5GAt the heart of enterprise 5G is the continuous, identity-based ZTNA authentication method. Other key components include secure web gateways (SWGs), which protect against web-based threats; cloud access security brokers (CASBs), which provide visibility and control over cloud-based apps and data; and firewalls-as-a-service (FWaaS).
Of the ZTNA capability, Johnson emphasized that users should not have carte blanche access once they have been granted access in one particular area. Zero trust restricts access at the network level and helps prevent horizontal attacks.
For example, if an attacker does successfully access an email, they aren’t able to move sideways, say, into an ERP or financial system, because that requires another level of authentication.
“Conceptually, the assumption is that just because you can access one thing in the network, you shouldn’t be able to access other things in the network,” said Johnson. With ZTNA, enterprises can be much more restrictive about where people can go.
“The ‘zero trust’ name implies that there’s no implicit trust,” said Johnson. “You have to be known, you have to be given explicit authorization.”
Is 5G SASE right for your business?When looking at 5G SASE as an option, enterprises should first consider whether their workers — or anyone connecting to the network — are outside the office, roaming in vehicles or using IoT devices. The next logical question is, how are they securing that remote access?
SASE helps reduce complexity by simplifying the number of places that enterprises have to do configurations, Johnson said. Due to its cloud-based nature, the technology simplifies the network and reduces the hardware to be managed, and policies are automatically pushed out across the network.
Ultimately, “you have a lot of agility, a lot of ability to move operations where you need to,” said Johnson.
Comments