Lookout CTO of SASE Products Sundaram Lakshmanan said he thinks clarity around secure access service edge (SASE) is “now actually settling in,” and the industry is beginning to see an extensive movement toward security digital transformation. 

“Instead of moving all these point security products to the cloud one at a time, people are looking for platforms that can solve vendor consolidation, improve the bottom line, and deliver the whole security as a service,” he told SDxCentral. 

[caption id="attachment_120716" align="aligncenter" width="225"] Sundaram Lakshmanan, CTO of SASE Products, Lookout[/caption]

The SASE architecture, Lakshmanan noted, ideally brings together networking-as-a-service (NaaS) and security-as-a-service under one umbrella. He added the industry is experiencing consolidation of security point products into single platforms, like security services edge (SSE), but has not yet hit networking and security from single vendors.

“That’s why this SSE is still somewhat of a best-of-breed market,” Lakshmanan explained. “So customers can choose a best-of-breed NaaS from some SD-WAN player, SSE standalone, and then pull together this whole hybrid workforce solution.”

Multi-Vendor SASE Strategy Is Still Best-of-Breed

In what some have called a “confused” SASE and SSE market, Lakshmanan said customers need critical thinking to stay focused on their problems and not get distracted by how vendors market solutions.

According to Dell’Oro, single-vendor – or “unified” – SASE will be significantly more popular than multi-vendor SASE.

“Like any single-vendor solution, there are tangible customer benefits — less operational burden, no finger pointing between vendors, tighter integration of components, clearer [service level agreements],” Dell’Oro research director Mauricio Sanchez told SDxCentral in an earlier interview. “I expect that the unified portion will grow faster than disaggregated for this reason.” 

However, Lakshmanan said the two-vendor strategy is still best-of-breed when it comes to converging networking and security. It’s what customers are “playing for and preferring,” he added, with some organizations even opting for three or four vendors. 

Gartner predicts that through 2024, more than 60% of organizations will still opt for a dual-vendor approach to their SASE initiatives, although that number will have gone down from more than 80% in early 2022.

Lakshmanan conceded the single-vendor strategy is emerging, but said “to do the single-vendor strategy, you have to sacrifice on security efficacy, because most of the single-vendor strategy is emerging from the networking vendors, not from the security vendors.”

This is an important distinction, because for networking vendors “there's no more room to grow until you offer security,” Lakshmanan said, adding that networking vendors are making the jump first, but their security solutions are not best-of-breed and they have a long bridge to gap to get to a seamless single-vendor SASE.

“They don't have to go into a single-vendor strategy. They don't have to push themselves toward that because they're not going to get much benefit,” he added. “And it may take five years or it may take a decade for the single vendor to evolve.” 

The ‘String of Pearls Approach’ Will Fail

Lakshmanan said that though market players like Palo Alto Networks, Cisco, and Juniper claim to provide single-vendor SASE, their solutions still come from two different platforms – a networking platform and a security platform – and products are often integrated through acquisition.

Big companies that started with inorganic growth years ago by acquiring pieces of SSE, like Cloud Access Security Broker, secure web gateway (SWG), or zero-trust network access (ZTNA), have struggled to beat pure-play SSE vendors like Netskope and – conveniently – Lookout, Lakshmanan said. 

“The string of pearls approach with inorganic growth, where you buy small competence and then integrate, that's going to fail,” Lakshmanan said. “Cisco and Forcepoint, the companies that started doing piecemeal, they're failing.”

For companies that set out to build a complete SASE without major SSE components – especially the CASB and a data loss prevention (DLP) components, which Lakshmanan said are the hardest to build – it's going to be “extremely challenging to be a formidable SSE player.”

Lakshmanan said alternatively, if an SD-WAN vendor acquires an SSE vendor or vice versa, that inorganic growth is “bound for a lot of success,” because customers are afforded the integration of best-of-breed security and networking. 

“That strategy is going to play out more in the next few years and I'm already seeing that,” he said. “But one single console for everything? I think that is still a ways out.”