Catapulted to the forefront of the security and networking conversation, SASE has officially reached “adolescence” according to Garter’s 2021 Hype Cycle report for network security.
Analysts report SASE has reached 5% to 20% market penetration among its target audience in the nearly two years since its inception.
In case you’ve had your head buried in the sand since COVID-19 hit, SASE stitches together zero-trust network access (ZTNA), cloud access security broker (CASB), secure web gateway (SWG), cloud-based firewalls, and SD-WAN into a single cloud-delivered service. The combined service enables identity-based access to workloads running anywhere in the network based on real-time context, security, and compliance policies.
Since it was first announced in summer 2019, the SASE product category has seen broad adoption among security and networking vendors alike, setting off a flurry of mergers and acquisitions as they wrestled for a leadership position.
While nearly every SD-WAN and security vendor has announced a SASE offering of some kind, Gartner cited Cato Networks, Fortinet, Palo Alto Networks, Versa Networks, VMware, and Zscaler as sample vendors in its latest report.
Cloud, Zero Trust Drive SASE AdoptionGartner notes several factors contributing to SASE’s meteoric growth. While the nearly overnight shift to remote work in the wake of the COVID-19 pandemic played an undeniable role, the report found cloud adoption, an appetite for zero-trust architectures, and reduced complexity have driven SASE deployments.
“Network security models based on data center perimeter security are ill-suited to address the dynamic needs of a modern digital business and its distributed digital workforce,” the report reads. “Keeping complexity manageable is a significant factor for the adoption of SASE.”
By 2024, Gartner expects 30% of enterprises will have transitioned away from this model to “cloud-delivered SWG, CASB, ZTNA, and branch office firewall-as-a-service capabilities” from a single vendor.
Complexity Threatens SASE GrowthThe SASE market isn’t without its obstacles. Gartner calls out several, including existing investments and skills gaps; organizational preferences; coverage; and security service maturity.
“A full SASE implementation requires a coordinated and cohesive approach across network, security, and networking teams,” the report reads.
SASE spans several traditional IT domains, including network and security operations teams, which are often segmented in large enterprises. These silos, Gartner argues, introduce challenges for enterprises as they look to adopt a SASE architecture.
Analysts also called out vendor biases and regulatory requirements as a key obstacle to cloud deployments and ultimately SASE adoption.
For highly distributed enterprises, especially those with presences in parts of China, Russia, and the Middle East, some SASE vendors will struggle to provide coverage, the report warns.
SASE architectures are dependent on cloud delivery. Much of the architecture’s networking and security stack runs on a distributed network of interconnected points of presence (PoPs).
Finally, Gartner points to the relative immaturity of many vendor’s SASE capabilities. “Your preferred vendor may lack the capabilities you require, but two-vendor partnerships can be a viable approach,” the authors wrote.
Gartner’s SASE Implementation TipsAs enterprises look to adopt SASE architectures, Gartner recommends involving both the CISO and network architect when evaluating vendors to identify required capabilities including latency, throughput, geographic coverage, and endpoint types to ensure an integrated approach.
The report also warns against relying on more than two vendors for the full SASE software stack to minimize complexity and improve performance.
For enterprises that need data-loss prevention (DLP), Gartner recommends working with a SASE vendor with a well-established CASB offering as they “have the most experience in this area.”
Finally, the report recommends enterprises take advantage of planned WAN, firewall, VPN, or SD-WAN refreshes or deployments to implement a SASE architecture for networking and security services.
Comments