Hybrid networking and security models, like secure access service edge (SASE), aren’t making networking teams’ lives easier, Tag Cyber CEO Ed Amoroso said during a Netskope panel discussion this week. Instead, he argued, IT teams are now forced to pull double duty to implement these new architectures, while also maintaining traditional network and security perimeters.
“Take the Fortune 100, there isn’t a single damn one of them that really has no perimeter. Every one of them has a perimeter,” he said.
However, these are the same companies whose CISOs are the first to get up and proclaim “the perimeter is dead,” he added. “But when they’re honest with you, there’s no near-term plan to retire it.”
Amoroso — who was joined on the panel by Netskope CMO and CSO Jason Clark and Sumo Logic CSO George Gerchow —claimed network teams aren’t abandoning their MPLS networks overnight and instead are being forced to support emerging technologies, like the cloud or 5G networks.
“So the network teams have twice the work and they have to endure everyone saying 'oh my god, why do we need network teams anymore,'” he said. “Being a network engineer is a tough thing to do in 2022.”
It's Not a Matter of If But WhenAccording to Clark, large enterprises, especially Fortune 200 and Fortune 500 companies are going to have traditional networking and security perimeters for a long time. The driving force behind how fast they adopt technologies like SASE, he said, is “how fast is the majority of my data going to be in the cloud.”
This transition was supercharged by the pandemic as enterprises took the opportunity to accelerate their cloud migrations and adopt software-as-a-service (SaaS) apps, he claimed, adding that in the past two years, the Global 2000 used, on average, 100 SaaS apps.
Over the past year, that number has increased exponentially, with the Global 2000 now deploying upwards of 2,000 SaaS apps, Clark said, adding that with this shift, the mix of cloud traffic had increased from 15% two years ago to between 75% and 85% today.
But while Amoroso doesn’t see the largest enterprises doing away with their on-premises security and WAN networks any time soon, he believes technologies like SASE still have a future and a role to play.
“I’m just saying my observation is they’re not going as fast as we in the analyst, and vendor, and tech community,” he said. “We know where the movie ends, it’s just how long until we get there.”
“A lot of companies are really laggards right now, and they don’t like to talk about it,” he added.
For this reason, Gerchow argued anyone who is working in the networking space today, needs to start learning about the cloud now. “I would get to understand what VPCs are, what security groups are for, how those things work, and get away from traditional network infrastructure.”
Are MSPs the Key?According to Amoroso, one of the easiest ways to address this challenge is by letting the big networking and security service providers do what they do best so IT teams can focus on growing the business.
“I think that businesses shouldn’t be doing this. I think they’re better served by letting service providers like Microsoft or Google or even network providers …” do what they’re good at, he said. “You engage with an expert team to do what they do well, and then you focus, locally, on making shoes or on doing business consulting, or whatever you do, and not try to parlay your way into also doing app sec.”
Amoroso tempered this assessment somewhat arguing that the very largest enterprises are big enough that economically it will make more sense to do everything internally.
“If you’re Bank of America, the economics are all skewed. The top 20, 30 companies, set them aside. They can build their own stuff, but everyone else, like here on planet earth, you’re better off using a service provider.”
Comments