Security vendors that once specialized in secure web gateway (SWG), Cloud Access Security Broker, or zero-trust network access (ZTNA) are converging their offerings in the cloud to provide all three capabilities. 

Cato CMO Yishay Yovel said analyst firm Gartner saw the trend developing, termed it the security services edge (SSE), and developed a framework for the new architecture.

“SSE was created to create flexibility, create a model that allows customers to deploy a security transformation separately from network transformation and still have a coherent environment,” Yovel said in Cato’s latest “Ask Me Anything” webinar on the differences between SSE and secure access service edge (SASE). 

[caption id="attachment_120475" align="aligncenter" width="250"] Yishay Yovel, CMO, Cato.
Source: Cato Networks.[/caption]

Gartner estimates that by 2025, 80% of enterprises will have adopted a strategy to unify web, cloud services, and private Application access using a SASE/SSE architecture, up from 20% in 2021.

According to Yovel, SSE is helpful for organizations that buy networking and security solutions in silos to simplify making decisions within the separate entities. For other organizations that already have SD-WAN solutions, SSE presents the option to be layered on top of existing deployments to achieve better security without changing the network.

“The customer may have an MPLS network, may have a site-to-site VPN network, [may] have SD-WAN deployed in the network. This is kind of immaterial for SSE. SSE is the security pillar that protects access from users to applications and websites, wherever they are,” Yovel explained. 

SSE Snags

SSE ideally provides multiple security capabilities for all users, at all locations, toward any Application on premises, in the cloud, or in a cloud data center. As a result, Yovel termed this concept “security everywhere.”  

Whether or not Gartner's framework for SSE actually addresses all these use cases effectively, he said, is a different question. 

Because the analyst firm's framework for SSE uses a Proxy, the architecture is specifically designed to control access to web-based applications. However, ZTNA cannot be applied only to web-based applications, but needs to support applications of all protocols, like client Server applications.

Yovel explained, “You need a second architecture, the Application connector architecture, which essentially requires a specific configuration for every Application. So we now have two architectures, Proxy and connectors.” 

Additionally, there are use cases that bypass or do not go through any of the SSE engines. “For example, if users come to the office with malware, and this malware goes over the wide area network and tries to hit a data center, then SSE is not involved,” Yovel said. 

IoT devices, servers, and other applications that send and receive traffic from different parties within or outside the Enterprise present another challenge Yovel that calls the “all ports, all protocols challenge.” Because SSE doesn't embrace all applications with full security, another architecture such as next-generation firewall or UTM is needed, he noted.  

“Now, remember, we started [SSE] because we wanted simplicity and we wanted a single engine to manage all of these network security challenges,” Yovel said.

With multiple architectures and engines, and extra solutions for WAN security, Yovel said, “We’re not out of the woods yet,” when it comes streamlining edge security.

A Stopgap Until SASE 

While SSE is useful, SASE, a holistic convergence of networking and security, is still “the destination,” Yovel said. 

However SASE is not SD-WAN plus SSE, because as it stands, the SSE framework has limited traffic visibility and control. “[SSE] can't see all the traffic for all use cases. It's only a subset of what's needed to achieve full SASE,” he said. In addition to a firewall and the SSE and connector architectures, a global backbone to optimize the traffic is also needed. 

Gartner's latest Roadmap for SASE Convergence indicated the majority of Enterprise SASE adoption “will occur over several years, prioritizing areas of greatest opportunity in terms of simplifying network security policy management, eliminating complexity and redundant vendors, and reducing risk through adoption of a zero trust security posture.”

Yovel said that the industry should want to get to a true SASE environment for three simple reasons: It's easier to manage, it's more efficient, and it’s faster. That said, until full SASE is achievable, “security convergence is better than no convergence,” he noted. 

According to Yovel, SSE's purpose is to create a model that allows for security transformation while planning or thinking toward a full SASE deployment.