McAfee expanded its secure access service edge (SASE) platform with homegrown zero-trust network access (ZTNA) technology that, in addition to securing access to private applications from any location or device, also integrates with its data loss prevention (DLP) capabilities.

The new Mvision Private Access covers managed and unmanaged devices and continually analyzes risk using data from McAfee’s 1-billion-sensor-strong endpoint security network.

It also comes about four months after McAfee announced integrations with three ZTNA vendors, Appgate, Axis Security, and TransientX, so it could add this key technology to its SASE platform, called Mvision Unified Cloud Edge (UCE). At the time, McAfee VP of Product Management Sadik Al-Abdulla said the vendor wanted to promote an open-provider approach to ZTNA.

UCE already provided SASE’s other security capabilities, including secure web gateway (SWG), cloud access security broker (CASB), remote browser isolation (RBI) and DLP technologies. But at the time, Al-Abdulla said McAfee decided to partner with third-party vendors for the SD-WAN and ZTNA components.

That preference has now changed, and rather than acquiring a ZTNA provider to fill that gap in its SASE stack, McAfee decided to build the technology itself, said Naveen Palavalli, VP of enterprise product marketing.

“In the case of ZTNA, there was a very stark recognition that this entire UCE fabric that we’ve built only becomes the best when you have the ZTNA solution fully integrated into that architecture,” Palavalli said.

McAfee’s integrated DLP, which unifies data protection policies and enables threat protection across clouds, web, endpoints, and now private applications via ZTNA, differentiates its zero-trust strategy — and its entire SASE architecture — from its competitors, Palavalli added.

“If we bought an inorganic solution, that would have required us to do that much more work to ensure you configure the data protection policy just once, and it works seamlessly,” he said. “Whether you use our endpoints, our secure web gateway, or our CASB, that unified DLP is extremely effective in lowering the total operational costs for our customers.”

As part of McAfee’s UCE SASE offering, the new ZTNA also feeds into its extended detection and response (XDR) platform, which correlates all of the telemetry that its SASE technologies collect to find more threats, and thus boost its automated investigation and response.

First ZTNA, Now McAfee SD-WAN?

Another reason for building ZTNA in house: providing SASE via a single, unified platform lowers customers’ operating and implementation costs, Palavalli said.

“The whole point of SASE, as described by Gartner, is to help lower your operating costs and your implementation costs of direct-to-internet and direct-to-cloud architecture,” he explained. “And Gartner recommends that you try to procure and deploy this from the same vendor — otherwise if you’re trying to source a secure web gateway from a different vendor, a CASB from a different vendor, a ZTNA solution from a different vendor, and DLP from a different vendor, you, the customer, now has the burden of putting all these things together and that increases implementation and operating costs. One of the key things of Mvision is that we brought all of these together under a single architecture to solve the data security problem.”

However, this doesn’t mean that the company plans to acquire an SD-WAN vendor any time soon to bring the networking piece of SASE in house. “We are an exclusively security-focused company. That’s our DNA,” Palavalli said. “There are other parts of the puzzle where we choose to partner with others, and where we are focusing right now is to strengthen the integrations so that it becomes a seamless experience for our customers.”