With the rise of secure access service edge (SASE), many SD-WAN and security companies have started to look more like service providers.

This is in part because the Gartner defined product category ties together elements of SD-WAN, managed security, and edge compute under a single, cloud-delivered offering that's usually delivered as a service and from a single vendor.

Cato and Open Systems have specifically touted their position as both the software vendor and the service provider as an advantage over other vendors in the space. However, this poses a problem for telecommunications companies and managed service providers, which have traditionally been the ones to piece together the various software and hardware needed to address particular clients requirements.

While vendors have moved quickly to bring SASE platforms to market, BT Global's Director of Global Solutions Andrew Small and Senior Manager of SD-WAN Services Anne-Gaëlle Santos question whether customers actually want what the vendors are selling. “SASE is a very new concept,” Santos said. “Whether SASE coming from a single provider is the answer today, personally, I’m a little bit doubtful.”

What’s more, no one vendor on the market today has the capability to deliver everything the customer needs, she added. “We have to remember that a lot of our customers have made choices already around their security vendor and solution in place, and they cannot throw the entire thing from one day to the next.”

Beyond the immaturity of most SASE offerings, many customers have become wary of getting locked into one vendor’s walled garden, Small said. “[SASE vendors] want to lock customers into their ecosystem. They want their SD-WAN solution, their SASE solution, their LAN solution,” he explained. “I think increasingly customers are wary of getting locked into any one of those domains, never mind all of them.”

Customers Still Want SASE

Customers may not want to get locked into a single vendor ecosystem, but that’s not to say that SASE isn’t the right choice for some.

According to Santos, SASE can be particularly attractive thanks to its relatively low cost compared to more conventional hardware-based security technologies.

“There is definitely a need in the market, and this is where it would probably make a difference when the price point is being hit,” she said, adding that it's just not going to be the right choice across the board.

What’s more, adopting a SASE architecture doesn’t necessarily mean committing to a single vendor. Many SD-WAN vendors, like Nuage Networks and VMware VeloCloud, offer deep integrations with security vendors like Zscaler to achieve a complete SASE architecture.

In an earlier interview with SDxCentral, Lindsay Newell, head of marketing at Nuage, argued that the enterprise market was too diverse to build a one-size-fits-all SASE platform. “This idea that with SASE, it all has to come from one vendor, and it’s all got to be in the cloud, I think we’re a decade away from that in the majority of markets,” he said.

For this reason, Nuage has taken a similar route as Zscaler, integrating with other vendors to provide customers and service providers more choices.

Other vendors, like Cisco, have taken an a la carte approach to SD-WAN and cloud security, in recognition that enterprises are at all stages of their WAN transformations. Cisco is positioning its Umbrella- and Duo-backed SASE offering as an add on to its Viptela SD-WAN platform. This means that enterprises can deploy Viptela as a standalone SD-WAN and add other SASE features later.

Customers Care About Flexibility

According to Small, customers want the flexibility to mix and match networking and security vendors the same way they can mix and match overlays using SD-WAN.

This is especially true in the wake of the pandemic, he said. “They’re uncertain about the shape of their business, and how many branches or how many offices they’ll have, or how big they’ll be, or where their employees will be, or what their business model will be.”

Santos agreed, adding that since most enterprises have existing networking or security infrastructure, they are rarely in a position to rip and replace one platform for another.