In the year since Gartner coined secure access service edge (SASE) — a product category that ties together SD-WAN, managed security, and edge computing — the technology has rapidly gone from relative obscurity to limelight.
Today, nearly every major SD-WAN and security vendor has adopted a SASE strategy.
Building a SASE isn't easy and buying one can be an even more expensive prospect. But that hasn't stopped many larger SD-WAN and security vendors from throwing money at the problem in order to speed the roll out of a SASE platform.
With that in mind, here are the six biggest SASE acquisitions of 2020, at least so far.
Palo Alto Networks Snaps Up CloudGenix for $420MIn one of the biggest mergers yet, in March, Palo Alto Networks announced it would acquire SD-WAN vendor CloudGenix for $420 million to bolster its SASE standing.
Palo Alto Networks was among the first major security vendors to throw its weight behind SASE by integrating SD-WAN and data loss prevention into its Prisma Access platform late last summer.
While the platform initially featured rudimentary SD-WAN, it was delivered via an agent running on end-user hardware and didn't directly address the branch office. The acquisition of CloudGenix filled this gap, enabling Palo Alto Networks to deploy its SASE platform to remote workers and more traditional enterprise footprints or retail locations.
“The acquisition will really accelerate our vision for secure, cloud-delivered SD-WAN via a secure access service edge model,” said Anand Oswal, SVP of product management and engineering for Palo Alto Networks’ firewall division, shortly after the deal closed. “Now with the addition of SD-WAN from CloudGenix, we have the branch and the retail use cases completely covered because now we have the CloudGenix devices.”
Following the acquisition, Palo Alto Networks has reported a jump in Prisma Access billings in response to pandemic-related work-from-home orders.
Fortinet Gets SASE With Opaq AcquisitionFortinet is among the latest security and SD-WAN vendors to adopt a SASE architecture. In late July, the company announced its intention to acquire SASE startup Opaq (pronounced "opaque").
While the security vendor didn't disclose how much it will pay for Opaq, the startup raised $43.5 million in two funding rounds since its founding in 2017.
In addition to a cloud-based, zero-trust network access platform, Fortinet also inherits Opaq's service edge.
The company's move to adopt SASE, which is a predominantly cloud-based architecture, puzzled some analysts during the company's earnings call earlier this month. Prior to the acquisition, Fortinet has largely been a hardware-based security and SD-WAN vendor, leaning heavily on custom ASICs.
However, in an interview with SDxCentral, Fortinet CMO John Maddison explained that the acquisition of Opaq has enabled the company to more effectively deploy SD-WAN and security functions anywhere the customer needs them.
Maddison added that ASICs will continue to play a role in the vendor's emerging SASE strategy moving forward.
VMware Roll's Nyansa's AIOps Into SASE PlatformVMware gave its VeloCloud-based SASE platform an artificial intelligence (AI) boost with the acquisition of AIOps vendor Nyansa for an undisclosed sum in January.
Nyansa's technology is designed to provide greater network visibility, monitoring, and remediation, which VMware claims will make it easier for customers to operate and troubleshoot branch deployments.
At the core of the acquisition is Nyansa’s vendor-agnostic AIOps platform, which can consolidate network telemetry from a variety of hardware vendors into a single dashboard, eliminating the need for proprietary monitoring tools like Cisco Prime, Aruba Airwave, or SolarWinds.
This enables VMware to provide visibility down to individual users, regardless of what switching hardware or wireless access points are being used.
While VMware was among the first SD-WAN vendors to adopt a SASE architecture, the vendor has largely focused its efforts on branch routing. In June, the vendor added support for remote workers through a zero-trust network access integration with its popular Workspace One client.
VMware still has some gaps to fill in its SASE offering. The company is currently partnering with vendors like Zscaler for secure web gateway (SWG), cloud access security broker (CASB), and remote browser isolation (RBI).
Cloudflare Touts Next-Gen RBI With S2 System AcquisitionCloudflare quietly waded into the SASE market in January with the launch of its Cloudflare for Teams remote access platform and the acquisition of S2 Systems.
S2 Systems' technology will form the basis for Cloudflare's upcoming RBI offering, expected to launch later this year.
RBI works by loading web traffic remotely and sending a finished page to the end user, significantly reducing the attack surface in the process.
Historically, RBI has gotten a bad rap for being slow and poorly implemented, Cloudflare CTO John Graham-Cumming said in an earlier interview with SDxCentral.
By combining S2 Systems' technology with Cloudflare's massive network of data centers, the company will be able to deliver higher performance than a native browser, he claimed.
“We’re pretty confident in the technology we have being a game changer,” he said. “The performance we’re getting out of it is very, very good compared to some of the other browsers.”
Rather than attempting to roll out a complete SASE stack, Cloudflare has focused its efforts on addressing problems faced by remote workers and partnering for branch connectivity. Cloudflare for Teams can also tie into existing SD-WAN deployments.
McAfee Rolls Light Point RBI Into SASE OfferingCloudflare isn't the only vendor investing in RBI. In February, McAfee acquired Light Point Security for an undisclosed sum in a bid to bolster its newly launched SASE offering.
McAfee plans to integrate Light Point's RBI into its secure web gateway.
“We have our heritage [technology] on the device, and now with Skyhigh and Unified Cloud Edge, we protect the cloud and data moving in and out of the cloud, but there’s still one area where malware can come down onto the device, which is the browser,” McAfee CMO Vittorio Viarengo said in an interview with SDxCentral. “Light Point lets us run that browser on a sandbox in the cloud so nothing can ever come down on to the device. Now we have really airtight security from the device onto the cloud.”
McAfee also unveiled its SASE ambitions with the launch of its Unified Cloud Edge, which it claims can fuse CASB, SWG, and data loss prevention (DLP) together into a single cloud-delivered package.
However, like Cloudflare and Zscaler, Mcafee lacks SD-WAN capabilities and is instead designed to integrate with existing deployments.
Zscaler Microsegments Security With Edgewise BuyZscaler snapped up 4-year-old security startup Edgewise Networks for an undisclosed sum in May. The security-turned-SASE vendor plans to integrate Edgewise's application micro-segmentation and zero-trust networking capabilities into its offering.
Edgewise’s technology is designed to identify applications and their legitimate communication patterns using AI and machine learning algorithms. Based on those patterns, the service can create and enforce policies, provide application segmentation, and prevent attacks from moving throughout the network, according to the company.
While Zscaler plans to continue offering Edgewise as a standalone product, it is also integrating it into Zscaler Private Access, the company's SASE offering.
“We have two high-potential products. What we certainly don’t want to do is try and integrate them and slow them down by any stretch," Punit Minocha, SVP of business and corporate development at Zscaler, told SDxCentral. "The mindset is: let’s keep selling them. And let’s build a plan to start doing integration.”
Zscaler's SASE offering has seen explosive growth since the onset of the pandemic. Prior to the COVID-19 crisis, the platform processed more than 100 billion transactions a day, and that traffic has increased tenfold since March, according to Minocha.
Comments