A pop-up clinic is set up at noon, and within minutes, clinicians are securely charting, printers are humming, and tablets check insurance – without the network configuration complexities or security ramifications of extending the private enterprise network. Identity, device posture, and a cloud proxy do the heavy lifting.

This article launches a three-part series on “café networking” and sets the foundation for what it is, why it matters now, and how to start.

Café networking, defined

Café networking is a proxy-first branch architecture that treats the internet as the default underlay and the cloud as the control and inspection plane. There is no default enterprise network extension to the branch, such as private IP ranges and VLANs.

As a result, if a user or device in a branch is compromised, ransomware and other malware cannot laterally move into the data center or cloud app. The blast radius is contained, and each site is automatically segmented.

Identity and device posture form the control plane, policy, and inspection live in the cloud, and most traffic is evaluated through a cloud proxy. Secure access service edge (SASE) serves as the framework. Security service edge (SSE) provides the security envelope. SD-WAN is used sparingly for deterministic, time-boxed exceptions rather than as the day-one path for all traffic.

Core tenets are straightforward and pragmatic: keep on-premises lean (broadband or LTE/5G uplink, a small customer-premises equipment device for cloud access, and a Wi-Fi access point). Make proxy-first nonnegotiable. Segment the users, devices, and IoT endpoints with a least-privilege policy, enforced by identity and posture. Capture full-fidelity telemetry –user, device, application, and policy decisions – to drive operations, assurance, and compliance. When legacy or tightly specified flows require it, allow a narrow set of routed tunnels, each recorded in an exception register with an owner, a reason, and a kill date.

Why now and where it fits

Our recent SASE market research data underscores the shift to cloud-delivered security and access: 2024 SASE revenue was nearly $10 billion, representing a compounded annual growth rate (CAGR) of 30% between 2019 and 2024.

The five-year outlook for SSE is equally telling: 2024 SSE revenue was $6 billion, and the 2029 outlook is $11 billion.

Dell'Oro Group SASE
– Dell'Oro Group

Meanwhile, the hardware-centric edge is contracting: Access router revenue was below $2 billion in 2024, down 22% year-over-year, and is projected to trend to $1 billion by 2029.

In short, the network operating model now needs to prioritize security – specifically, identity-first authorization, policy agility, and cloud inspection – rather than focusing on boxes and wires.

Café networking excels where repeatability, speed, and cost-to-serve take precedence over deep east-west optimization, such as in pop-ups, retail “micros,” clinics, sales offices, field sites, distributed rooms, and co-working spaces. It can also complement campuses by making proxy-first the norm and keeping local segments minimalist.

Challenges are real, but pairable with clear mitigations:

  • Source-IP constraints: IP anchoring that egresses from approved ranges
  • Voice/session initiation protocol (SIP) and other real-time media: scoped SD-WAN for deterministic flows with tight loss and jitter guarantees
  • Multicast/broadcast dependencies: a small, segmented local domain plus refactoring to unicast when feasible
  • Operational technology and some IoT stacks that assume local adjacency: local micro-segments with agentless, behavior-based posture checks, with only deterministic flows routed
  • Data sovereignty and residency: region/private edges to keep inspection and logs in-region
  • Offline operations from fiber cuts or power events: cellular failover and degraded-mode runbooks that specify what works, what does not, and who decides when to switch modes

Start here: 30/60/90, exceptions, and KPIs

Day zero to day 30:

  • Pick a micro-branch pilot
  • Establish identity and posture baselines
  • Stand up a cloud proxy for top private apps
  • Keep the on-premises footprint to broadband or LTE/5G, small CPE/NAT, and Wi-Fi
  • Create an exception register with owner, reason, and kill date
  • Define initial key performance indicators (KPIs) and an inspection service-level objective (SLO)

Day 31 to 60:

  • Expand to between five and 10 sites
  • Classify IoT and apply least-privilege segmentation
  • Introduce region-specific or private edges if sovereignty applies
  • Add scoped SD-WAN only for verified deterministic flows, measured against latency, loss, and jitter targets
  • Exercise cellular failover and rehearse degraded-mode runbooks
  • Prune or renew exceptions strictly by their kill dates

Day 61 to 90:

  • Roll to additional branches
  • Remove expired exceptions
  • Automate policy propagation and measure time to policy change across the fleet
  • Begin campus-adjacent planning with the same proxy-first stance, adding local segments only where clearly required

Measure what matters and makes it visible: percentage of proxy-first sites, percentage of traffic inspected via proxy versus routed, exception count and dwell time, time-to-policy change (P50/P95), inspection SLO attainment, and cost-to-serve per site.

Tie these KPIs to operational reviews so that exceptions decline over time, policy moves faster, and inspection quality holds steady as the footprint grows.

Conclusion

In this first article, we introduced café networking as a proxy-first access model, ideal for micro branches, with identity and device posture serving as the control plane, and cloud inspection enforcing policy, with no default network extension. Expected benefits include:

  • Improved agility to stand up sites faster
  • Reduced cyber risk by eliminating lateral movement
  • Reduced attack surface due to branches no longer being jump points to attack core applications
  • Lower cost and complexity because of simpler network design (no routing) and infrastructure (separate network and security appliances)

In the next article, we will delve deeper into unpacking design patterns for a zero-trust, no-network-extension branch, and then conclude with how to scale the model from micro-sites to campus without reverting to legacy complexity. Start small, measure relentlessly, and scale with discipline.