5G and 4G LTE enterprise wireless WANs offer organizations unprecedented opportunity to reach more customers and move services closer to them.
But at the same time, this complicates security, because more and more unmanaged devices (including for IoT) are accessing the network.
This demands new platforms that can secure sprawling environments beyond just fixed sites. Secure access service edge (SASE) has emerged as a valuable tool to help secure sprawling environments with many different footprints, moving fleets, IoT devices and employee devices located anywhere.
Cradlepoint, part of Ericsson, is aiming to be a leader in this market and today announced NetCloud SASE. The 5G-optimized platform allows IT teams to deploy zero-trust networks at scale — and Cradlepoint says this can be done in as few as six minutes.
“Zero trust is seen by experts as a modern way to secure a much more complex cybersecurity landscape,” Camille Campbell, senior product marketing manager for NetCloud at Cradlepoint, told SDxCentral. “What we’re really trying to do is make zero trust easy.”
Building on strategic Ericom acquisitionAccording to IDC, worldwide revenues for the 5G and 4G/LTE enterprise WAN will reach $5.5 billion in 2027, representing a compound annual growth rate of nearly 24% from 2023. Along with this, the SASE market is projected to grow from $1.9 billion in 2023 to nearly $6 billion by 2028, representing a 25% CAGR.
Many market leaders and emerging startups offer SASE tools — including Fortinet, Cloudflare, Palo Alto Networks, Cato Networks, Netskope and Versa Networks.
Cradlepoint’s new SASE offering builds upon the company’s April 2023 acquisition of Ericom, a strategic move to integrate SASE, zero trust and cloud security across wireless and 5G networks. It is a one-platform, one-policy engine featuring cellular optimization, built-in zero trust, isolation technology to help block zero-day exploits and strong security for unmanaged devices (IoT), according to the company.
“SASE represents the convergence of WAN networking and security,” said Campbell. “The vision of SASE is to bring everything together into one unified policy engine.”
Campbell emphasized that Cradlepoint is “not trying to be SASE for everybody.” The company serves organizations with numerous small footprint locations (retail, fast food, financial services, for instance) and remote fleets and those that are managing numerous IoT devices.
“They are very highly distributed, highly scalable,” Campbell noted.
Zero trust and ‘deny all’ by defaultWith Cradlepoint, the network-creation process is based on zero trust and is “deny all” by default.
“We say it’s built in as opposed to bolted on top of the SD-WAN,” said Campbell. “You’re basically starting from that very secure foundation.”
Many organizations struggle with zero trust, she noted — they know they need it, but they don’t know how to implement it. The goal is to provide simplicity and enable zero trust that can be set up in minutes once an admin defines resources and sets up policies.
Zero trust only authenticates users to the resources they are requesting access to at a specific point in time. They are not able to access or see anything else or move laterally.
For instance, a marketing person logging into a network will only be granted access to Salesforce, as opposed to financial systems. If they log in from a different location than usual — such as from a mobile phone or laptop — their abilities may be further restricted. And, in IoT, communications are locked down so that different devices don’t access each other without permission, Campbell explained.
Remote browser isolation that ‘air gaps’ usersCradlepoint is also applying zero trust to web and email security through remote browser isolation, which can help companies protect against malware and phishing attempts.
“Phishing attacks are another big problem,” said Campbell. “We’re trying to get customers to think beyond just threat detection.”
Remote browser isolation “air gaps” users from malicious web activity. This means that they are physically isolated from unsecure networks. When they are accessing a website, that session is activated in its own cloud container. Cradlepoint’s platform also obscures all IP addresses and blocks east west traffic for containment purposes.
Campbell noted that this technique isn’t new, but it has improved. Previously, there were issues when it came to latency. But Ericom has “nailed down how to do remote browser isolation. They can do it in a way that’s completely transparent to the user browser experience.”
Even if a user clicks on a link, “nothing is going to reach her machine,” said Campbell.
“It’s protecting organizations from anything that could be a zero-day exploit that slips through threat intelligence systems,” she said. Zero day exploits target unknown or as yet unaddressed security flaws and are “the most damaging exploits there are.”
The importance of cellular optimizationIn addition to its security capabilities, NetCloud SASE provides wireless WAN optimization to help preserve bandwidth and improve performance. It also provides a 5G standalone slicing-ready option.
“5G WANs operate a lot differently than wired WANs,” Campbell said.
Mobile traffic isn’t just at fixed sites, she noted. Also, in 5G, bandwidth fluctuates based on signal strength and quality from nearest towers. Organizations must be able to measure available bandwidth at any given time, while also measuring data plan usage and operating cost-effectively over cellular networks.
Campbell pointed out that organizations deploy cellular because of its agility. When looking at 5G security, that ability is “absolutely key for our customers.”
Comments