Secure access service edge (SASE) is the Taylor Swift of enterprise technologies. IT audiences can’t seem to get enough of it. Seizing the enthusiasm surrounding the architecture, technology analysts, consultants and, yes, the media are jumping on the topic and keeping IT professionals immersed in news, analysis and best practices for it. Naturally, tech vendors from the giants to startups are ready with an offering.

Of course, like any pop star, what you see on the surface doesn’t always reflect what’s happening behind the scenes. SASE brings challenges. Mike Anderson, Netskope’s chief digital and information officer, told SDxCentral that SASE brings cost and complexity.

It calls for change management, the need for assurances that performance won’t suffer — noting that users won’t accept trading it for security — and a new approach that calls for network and security teams to collaborate. And as with any security platform, he said, the “weakest link is sitting in a chair.”

This week is SASE Week for Netskope, and Anderson took on some of the questions surrounding SASE in his “Unlocking the full financial and technical Value of SASE” session.

Before buying into SASE, answer these 3 questions

Before committing to a SASE environment, you need to answer these why questions, according to Anderson:

  1. Why change? What is the pain that needs to be addressed with SASE?
  2. Why now? What is the near-term positive impact of addressing that pain? What are the negative impacts of not making the change?
  3. Why SASE? How will SASE uniquely solve that pain?

After answering those questions, Anderson said align your company’s top-level strategy and objectives throughout the organization to the critical capabilities that you need to have in order to be successful with that initiative. Look at the strategy you're trying to follow, and the challenges that stand in the way of accomplishing the goals and objectives.

“What are the value streams that align to that? What are the things that we can be doing from an IT standpoint, in this case SASE? Examine how it will help your company accomplish its overall objectives?” Anderson said.

It’s complex out there

Complexity is a major factor to consider when looking at SASE solutions. “We see complexity rooted in a hardware-centric network security model,” Anderson said. However, he added that the complexity has expanded into a software-as-a-service model. “The average organization has over 76 discrete tools today that they're using to protect users.”

Anderson said enterprise IT leaders are also looking to reduce complexity and cost savings by consolidating vendors – “whether it's direct savings from consolidation of vendor agreements themselves, or from the operational efficiencies they get from doing the same."

[caption id="attachment_134657" align="alignnone" width="780"] For all its promise, SASE faces challenges. Source: Netskope.[/caption]

Why customer experience matters

Given that 70% of the workforce will be hybrid in the future, according to Anderson, creating a seamless employee experience – whether they are working at home, in a coffee shop or in the office – is a priority. “We don't want them to have more access when they're at home than they have when they're in the office or vice versa.”

Another issue IT decision makers need to address is replacing legacy VPNs. Anderson said that when an employee connects, they gain network access. If that user is working at home and is compromised, the attacker also has access and can go where the user can go. “If companies have flat networks, you can quickly see a security breach, or malware, spread across an entire organization in minutes.”

Anderson said it was easier to create a good employee experience when workers were in the office. “We could optimize the offices because we controlled them and created a great employee experience.”

But with a remote and hybrid workforce, both employee experience and security can suffer. “Now I'm backhauling traffic from that person's home back through my corporate network and then out many times directly to the internet. In fact, we see that 70% of traffic from individual employees is actually going to a destination that's not within the four walls of the enterprise.”

Backhauling traffic just to inspect it doesn’t make for a great experience for employees. And, Anderson adds, the more running through those networks, the more cost and complexity it creates for your organizations.

SASE architecture and people who live it

Anderson said that when you look at the security service edge (SSE) side, the discrete offerings that enterprises use today solve point-security problems. “As they converge, each one of these things is a speed bump that sits between our users and the destination that they're trying to access.”

This results in a mix of hardware and software that wasn’t designed to work together and a lack of the operational efficiency that enterprise IT needs in order to get value from its technology investments.

“It really boils down to people, process and technology. Building and buying technology is really the easiest part,” Anderson said. The hard part is the change that our organizations have to go through to adopt and use that technology. And this often results in the company organizing teams around the IT, network and security tools.

“Then on top of that, our processes have to change because our current processes were built to work within the technology landscape and with the solutions that we have within our environments today.”

While technology has a cost attributable to it, Anderson said the bigger lift is getting people to change and adopt engineering process changes.

“What we get with SASE is the ability to consolidate and be able to train people on one set of tools to allow them to operate across the entire spectrum of everything in the network security landscape,” Anderson said.

Providing visibility

In looking at SASE’s value proposition, the first item Anderson looks at is discovering, protecting and providing visibility into your organization’s sensitive information.

“The challenge we have today is data is everywhere and we have more processes and more sensors creating more data than we ever have before and it's only getting greater by the day. And so how do we discover that information and protect it to make sure it's not going places that we don't want it to go?”

[ Related: How to use Gartner’s Hype Cycle for your zero-trust and SASE strategies ]

That visibility goes beyond the SASE applications you use in your environment and controlling those. Anderson said if you think about your network teams, it's all about mean-time-to-innocence. “The first thing we say, well, it must be the network. And so network teams have to prove innocence.” Giving visibility into why a user might have a bad experience is critical to choosing the right SASE architecture to make sure we pick the right solution.

The SASE journey

When looking at moving to a SASE architecture and selecting a SASE provider, Anderson breaks the journey into two parts: SSE and the WAN edge.

Starting with SSE, Anderson said, the first questions to ask are these:

  1. How and what do I integrate within my environment?
  2. What do I eliminate in my environment?
  3.  What do I reduce in my environment?

You can also “choose your own adventure,” Anderson said. You can start with your web and cloud applications. Or you can start with private apps. And you can start with both of those equally. From there, you go to the other that you didn't pick first.”

The final step from an SSE perspective is expanding into data loss prevention (DLP) – for example, getting DLP into your email and endpoint environments.

Moving to WAN edge service side, Anderson said, you have the same conversation regarding how to integrate, what to eliminate and what to reduce in your environments.

“Again, you can choose your own adventure,” Anderson said. "I recommend you start with your remote users. How do you bring those WAN edge capabilities down to your users working from their endpoint machine or from their home office?”

From there, Anderson said, you move into your branch office environments. And then lastly, you look at factories or manufacturing facilities as “there's more nuance when we get into those environments.”

Balancing agility, risk and cost

“Business value is optimized by finding the right balance between agility, risk and cost,” Anderson said.

SASE can help reduce the risk by improving the security and digital hygiene preventing data leakage to trusted apps you use today. “It allows us to reduce third-party risk, not just by consultants and contractors working in our organizations, but all of our extended suppliers we work with today. It also increases the security posture of our environments internally.”

Financially, the cost of reducing risk doesn’t tie to a specific budget item. “It's the cost that's going to come up in the future if you don't take the right actions. It's the fine you're going to face if you don't do the things you're supposed to do from a regulatory standpoint.”

Vendor consolidation is another way to simplify your landscape and reduce complexity and simplify operations. “If I don't have as many tools in my environment, I may not need as many people operating these tools from a run standpoint, so I can get efficiency with the tools that I've implemented and redeploy my people towards higher value items that are more critical to my organization as you move forward.”

And, finally, Anderson said he’s often asked about how SASE helps with an organization’s agility.

“If my users are happy and they can do the work seamlessly and safely from anywhere, that drives better productivity. Because at the end of the day, I have people who want to come to work and just get their job done, and they want to do it safely.”

SASE value takeaways

Besides latching on to a hot new IT architecture, what are the outcomes SASE delivers to your organization? Anderson summed up the value SASE can deliver.

  • Better visibility and control.
  • Reduced cost and complexity in our environments.
  • Enabling innovation so you can take advantage of things like generative artificial intelligence in a safe and secure way.
  • Providing a secure and seamless employee experience so people have the same access and the same level of security, whether they're working from home or in an office.
  • Reducing attack surface so that the attackers can't take you down,
  • Improving the speed and resilience in our organization.