Extended detection and response (XDR) and secure access service edge (SASE) were two of the hottest security trends last year, and they don’t show any sign of slowing down in 2021. If anything, they’re speeding up — and they’re not just running on parallel paths.

XDR and SASE, when used in tandem, can provide organizations a more comprehensive view of their risks and a more holistic approach to securing against and remediating threats. Vendors including Palo Alto Networks, Cisco, and VMware are already making moves to integrate the two so that XDR and SASE will work together in customers’ security environments.

“An orchestrated SASE can be a very good complement to the journey to XDR,” IDC Research VP Micheal Suby said.

XDR combines elements of security information and event management (SIEM), security orchestration, automation, and response (SOAR), endpoint detection and response (EDR), and network traffic analysis (NTA) in a software-as-a-service (SaaS) platform to centralize security data and incident response.

Meanwhile, SASE blends networking, several security capabilities, and edge compute into a single cloud-delivered service.

The 2020 Perfect Storm

Both are relatively new sectors that became increasingly important in 2020, thanks, in part, to COVID-19 and the related explosion in remote workers. As employees worked from home — or the new branch office of one — they needed the type of distributed networking and security architecture that SASE provides.

Additionally, as workers moved outside of the traditional perimeter and accessed corporate systems and data from their home networks and personal devices, this expanded organizations’ threat surface and potential places for attackers to hack into companies’ networks. XDR, which correlates threat detection and response across endpoints and the network, provides the holy grail of threat hunting and auto remediation.

“XDR, as an ultimate consumer of telemetry, is going to be trying to grab intelligence from wherever it can, including SASE solutions,” said Mauricio Sanchez, research director for network security and data center at Dell’Oro Group. “I do see that integration happening, beyond a shadow of a doubt, as these SASE solutions mature.”

In other words: the pandemic provided a perfect storm for these two buzzy security sectors to collide.

XDR and SASE: Telemetry, Enforcement, and Orchestration

“XDR runs on three trajectories,” Suby said. “One is telemetry — what is the volume, what is the diversity, what is the value of the telemetry being gathered. Because that forms the basis to reach a conclusion. So telemetry is crucial.”

SASE sees all of this network traffic and feeds this telemetry to XDR.

Once the system reaches a conclusion, for example, my environment is under attack, then the XDR needs to stop the attack from advancing, Suby added. “The next question is: where is that containment going to occur? What are the control points where that containment can be enforced?”

This is another place where SASE compliments XDR because it can contain the threat at various points across the network and the edge. “SASE becomes not only a very important source of diverse telemetry, but it can also be a point where containment is enacted,” he said.

And finally, the third part of XDR is orchestration and automation, Suby added. “How do you do containment in a way that produces assurances that we actually contained the threat when we’re working across multiple control points? And how to we orchestrate it across all of that? Again, that’s where SASE folds in where you have one control plane across many control points,” Suby said.

Several vendors that jumped on the SASE and XDR trains are now taking steps to integrate the two.

Palo Alto Networks Integrates Cortex XDR With Prisma Access

Palo Alto Networks, which is arguably furthest along in both its XDR and SASE capabilities, integrates its Cortex XDR with its Prisma Access logs to apply behavioral analytics to detect anomalies that likely indicate attacks.

“What’s driving a lot of the SASE business is the fact that people are working remotely,” said Kasey Cross, senior product marketing manager for Cortex XDR. “And that is causing organizations around the world to deploy products that can help secure all their remote users and distributed networks.”

Meanwhile, companies adopt XDR “for similar but different reasons,” she said. Remote work is the similar reason, “so they need to suddenly protect a bunch of new users and people’s home laptops.”

Plus, companies don’t want a bunch of siloed security tools. In pre-pandemic times, companies likely managed security products on premises and enforces policies across employees and devices that all connected to the same network. In 2021, however, “they are suddenly realizing that it would make a lot more sense if they could have one, single solution covering all of their employees and all of their networks, and have it all delivered from the cloud rather than then managed on premise.”

These concerns drive demand for Cortex XDR and extended detection and response in general, she said.

Cisco Gets SASE With SecureX

Cisco is taking a similar approach. Its SASE product combines SD-WAN with cloud security from Cisco Umbrella. And in June, the vendor rolled out its consolidated security platform with XDR capabilities, SecureX, which is included with every Cisco security product.

“A key component of SASE is vendor consolidation,” Cisco’s VP of Security Marketing Gene Hall wrote in an October 2020 blog. This includes Cisco’s newly consolidated SecureX platform, which includes XDR capabilities and is included with every Cisco security product. “Through SecureX, customers get unified access to security, networking, and IT applications from both Cisco and many third parties to streamline and strengthen security.”

This means customers can use SecureX to “progress along your journey to SASE while taking advantage of comprehensive security capabilities that extend beyond SASE use cases,” Hall wrote.

VMware SASE, XDR Strategy Centers Around Integrations

VMware announced its SASE platform over the summer and plans to make it generally available in the second half of the year. A few months later, at VMworld 2020, it unveiled its XDR strategy in addition to planned SASE integrations across its workload and network security products with Carbon Black endpoint security integrations to follow.

As it’s built out its security portfolio, VMware has taken steps to integrate its platforms, said Tom Corn, VMware’s SVP and GM of security products. “And the nature of those integrations really fall into two camps," he explained. "It’s about sharing context, so I can send workload or endpoint context to [networking platform] NSX, or I can send network contact to Carbon Black,” which provides endpoint and cloud security.

Some of these integrations are focused heavily on enforcement, he added. “Even though I might detect on one [platform], I can actually trigger an action to happen on the other.”

The vendor plans to follow a similar strategy as it introduces XDR threat detection and response capabilities, he said.

“For us, the strategy around XDR is really about integrations across these major platforms in endpoint, workload, network security, and access management, in terms of sharing context and sharing control,” Corn said. “The point is that once we start connecting the dots and blurring the lines between a network, endpoint, workload, and user it opens up the possibilities to detect better, to understand a campaign better, and to be more surgical in our response. And that’s really what XDR is about.”

Netskope Pushes Open APIs, Best of Breed

While the larger security and infrastructure vendors push a platform approach to integrate SASE and XDR, others including Netskope that don’t have a full SASE and XDR stack advocate for best of breed products instead of a converged approach along the lines of Cisco.

Netskope built out a distributed networking and security architecture with centralized visibility, management, and policy enforcement. It provides SASE and cloud security, but partners with vendors for its missing pieces like SD-WAN and EDR.

SASE and XDR should integrate, but via open APIs, Netskope CEO Sanjay Beri said. “That way you have a great XDR solution, and you can also have a great secure access cloud solutions,” he said. “And the industry is mature enough to know that we need to play nice together and integrate,” he added, noting Netskope’s Cloud Threat Exchange, which is launched last year. This allows enterprises to automate threat intelligence from multiple vendors and across security enforcement points.

While its initial partner ecosystem primarily includes EDR and email security vendors — VMware Carbon Black, CrowdStrike, Cybereason, Mimecast, SentinelOne, Cylance, and ThreatQuotient, among others — Netskope plans to certify other vendors and integrate additional threat intelligence sources over time.

“I do think that should be integrated, but I don’t mean that they should all be one vendor or one platform,” Beri said. “That will never work in the sense of it’s not going to be the best — or great — at any of them, because each of these are huge areas in and of themselves.”