What is SASE, And Why You Should be Using it

SASE (Secure Access Service Edge) is a cloud-delivered architecture that combines network connectivity with network security in one platform, so traffic is inspected and routed at a nearby point of presence instead of being backhauled to a central data centre. A SASE offering typically brings together SD-WAN with a secure web gateway, firewall-as-a-service, a cloud access security broker and zero trust network access, applied according to user identity rather than network location. Where SASE includes the networking layer, SSE is the security half on its own, which is what most organizations actually need.

JP
John Price
  • 6 min read
Share

What is SASE?

What is SASE? Secure Access Service Edge (SASE) is a network architecture that brings network security closer to the computing edge location via a cloud service model. The SASE model enables flexible, robust security through a single-point offering without the drawbacks of having to reroute traffic through a central mechanism.

Essentially, SASE combines network-as-a-service and network-security-as-a-service. The term “SASE” was coined by the global research and advisory firm Gartner. Gartner noted that network security architecture had to evolve to keep pace with the heightening level of cloud reliance and increase in off-premise applications and workforce. Thus, SASE was devised to combine SD-WAN with a range of security functions to serve the modern, cloud-empowered business.

The core attributes of a SASE offering:

  • Identity driven nature
  • Cloud-native processing
  • Support for all edges
  • Globally distributed PoPs (Points of Presence)

The Need For SASE

Traditionally, corporate applications and data were hosted within the enterprise premises. This centralized, hardware-focused landscape led to the rise of hub-and-spoke network architecture. In the traditional model, traffic is routed to a central hub via a VPN or a secure line. Then at which point, security controls are implemented and users can access data and applications.  

But, cloud-based computing, SaaS reliance and remote working have resulted in applications and users no longer residing within the enterprise premises. As the modern landscape evolved to be increasingly-cloud based and distributed, the traditional model could no longer keep up. The hub-and-spoke model presented two main drawbacks in this regard: latency issues and increased complexity.

Whenever a large part of the enterprise workforce accessed the central hub via a VPN, latency issues arose. This latency posed a severe hindrance to remote working, affecting both employee workflow and business operations. And, due to cloud-based applications and data, the enterprise premises were no longer the only point requiring network security controls. This was the second drawback - more complex and layered network security. With shifting computing edges and off-premise hosting increasingly prevalent in the enterprise space, a more flexible and scalable network security architecture was the need of the hour.

SASE components

As mentioned previously, SASE offerings combine SD-WAN with a range of security controls. At a conceptual level, the components of SASE are split into three main parts - the core security components, recommended components and optional components.

Core

  • Secure Web Gateways (SWG)
  • Firewall-as-a-Service (FWaaS)
  • Cloud Access Security Broker (CASB)
  • Zero Trust Network Access (ZTNA)

Recommended

  • Sandboxing
  • Browser isolation
  • Web Application Firewall (WAF)
  • Network Access Control (NAC)
  • Next-Generation Antivirus (NGAV) and Endpoint detection and response (EDR)

Optional

  • Wireless local area network (WLAN) security
  • Virtual Private Network (VPN)

The numerous benefits of SASE

Cost reduction

By combining multiple point solutions and vendor offerings into a single platform, implementing and running SASE presents incredible cost savings for organizations. As opposed to regular maintenance of various siloed components and their infrastructure, a SASE platform will be less expensive to maintain as well.

Efficiency and simplicity

Many aspects of enterprise network security can be made more efficient and simpler with SASE. The one-platform approach reduces the overall workload of the IT staff and frees them up to focus more on other areas. All operations from control to maintenance to scaling are simplified manifold compared to the traditional model of running multiple point solutions. And, in place of numerous security policies and complicated frameworks, the use of a single platform enables a streamlined approach.

Robust adaptability and agility

Due to being cloud-based, SASE architecture is incredibly flexible. It provides robust security while enabling anywhere, anytime access to data and applications. As enterprise workloads and users’ are getting increasingly cloud-reliant, SASE offerings have a clear edge when it comes to data flow and network performance as well. Latency and scaling issues that arise from traditional models are no longer bottleneck factors that limit efficiency.

SASE vs SSE: what the difference actually is

SSE, or Security Service Edge, is the security half of SASE on its own. It covers the cloud-delivered security controls (secure web gateway, CASB, zero trust network access, and usually firewall-as-a-service) without the networking layer.

SASE is SSE plus SD-WAN. That networking component is what lets a single platform make routing decisions as well as security decisions, so traffic takes an efficient path to its destination instead of being backhauled to a data centre for inspection.

The practical consequence is which problem you are solving:

  • Choose SSE when your networking is settled and the problem is securing access to cloud applications and the internet for a distributed workforce. Most organizations that think they need SASE need SSE.
  • Choose SASE when you are also replacing branch networking, retiring MPLS circuits, or consolidating an SD-WAN contract at the same time. The combined purchase only pays off if you were going to buy both anyway.

Vendors blur this deliberately, because SASE is the larger contract. Establishing which of the two you actually need is the single most useful thing to do before taking a demo.

Deciding between SASE, SSE, and neither?

We do not resell SASE platforms, so the recommendation is not tied to a licence sale. Get an assessment of what your traffic and users actually need first.

Book an architecture review

SASE security: what the platform secures, and what it does not

When people search for SASE security they usually mean the protective half of the architecture, and it is worth being precise about what that half covers. The security stack inside a SASE platform, the secure web gateway, firewall-as-a-service, CASB, and zero trust network access, governs how your users reach the internet, SaaS applications, and private resources: traffic is inspected in the cloud, access decisions follow identity and device posture, and policy applies the same way in the office and on hotel Wi-Fi.

What SASE does not do is watch the rest of your estate. It is an access-control and traffic-inspection layer, not a detection and response program: a compromised mailbox, an attacker inside a SaaS tenant with valid credentials, or malware on an endpoint that never crosses the SASE edge all fall to other layers, endpoint detection, identity monitoring, and someone investigating the alerts those tools raise. Treat SASE as one control plane in the architecture, feed its logs into your detection stack, and keep the monitoring question, who investigates at 3am, answered separately; SubRosa's Managed SOC exists for exactly that layer.

How to evaluate SASE vendors

Every SASE platform demonstrates well. The differences show up in operation, not in the demo, so the questions worth asking are the awkward ones:

  • Was this built or bought? Several platforms are acquisitions stitched together behind one portal. Ask whether policy is genuinely unified or whether you will configure the same rule twice in two consoles.
  • Where are the points of presence? A globally distributed PoP footprint is a core attribute of SASE. If your staff are somewhere the vendor is thin, the latency problem you bought SASE to solve simply moves.
  • What happens when the PoP is unreachable? Failure behaviour matters more than uptime figures. Does traffic fail open, fail closed, or fall back to a local path, and can you choose per policy?
  • How is inspection handled for traffic you cannot decrypt? Certificate pinning and privacy obligations mean some traffic will never be inspected. How the platform treats it is a real security decision.
  • What does the exit look like? Single-vendor consolidation is the selling point and the risk. Understand how policy and configuration come back out before it goes in.

SubRosa does not resell SASE platforms, so we have no position to defend on which vendor wins. That is deliberate: the assessment work is more useful when the outcome is not tied to a licence sale.

Migrating to SASE without breaking anything

SASE replaces the network path everything travels on, which makes a flag-day cutover a poor idea. Migrations that go well tend to share a shape:

  • Start with remote users. They are already the least well served by a hub-and-spoke VPN, so the improvement is immediate and the blast radius is contained.
  • Run in monitor mode first. Let the platform see traffic and produce policy recommendations before it starts enforcing them. The gap between assumed and actual traffic is always larger than expected.
  • Move branches last. Site networking carries the hardest dependencies: legacy applications, local breakout requirements, circuits under contract.
  • Decide what happens to the VPN. Leaving it running "just in case" is how organizations end up paying for both indefinitely and leaving an unmonitored path into the network.

All in all, SASE represents a milestone step in the evolution of network security architecture. The one-point, one-vendor nature of SASE platforms presents incredible ease of implementation and use for enterprises. Furthermore, the utility of SASE is also cemented further by the rise and proliferation of cloud-based computing and remote working. SASE can effectively cater to the modern enterprise space. It can seamlessly combine network and security while lowering overall cost and complexity. With these numerous advantages, SASE will assuredly transform the future of digital business and boost organizational capabilities across the board.

Frequently asked questions

What is SASE?

SASE, or Secure Access Service Edge, is a network architecture that delivers connectivity and security together from the cloud. Rather than routing traffic back to a central data centre for inspection, a SASE platform inspects and forwards it at a distributed point of presence close to the user. Access decisions are based on verified identity and device posture instead of on which network someone happens to be connected to. The term was coined by Gartner.

What is the difference between SASE and SSE?

SSE (Security Service Edge) is the security half of SASE delivered on its own: secure web gateway, CASB, zero trust network access and usually firewall-as-a-service. SASE is SSE plus SD-WAN, adding the networking layer so the same platform makes routing decisions as well as security ones. Choose SSE when your networking is settled and you are securing access to cloud applications; choose SASE when you are also replacing branch networking or retiring MPLS at the same time.

What are the core components of a SASE platform?

The core security components are a secure web gateway, firewall-as-a-service, a cloud access security broker and zero trust network access, combined with SD-WAN for connectivity. Commonly included but not definitional are sandboxing, browser isolation, a web application firewall, network access control, and next-generation antivirus or endpoint detection and response. Wireless LAN security and traditional VPN are sometimes bundled but are not part of the model.

How do I choose a SASE vendor?

Ask whether the platform was built or assembled from acquisitions, because that determines whether policy is genuinely unified or duplicated across consoles. Check the point-of-presence footprint against where your people actually work, since thin coverage recreates the latency problem SASE is meant to remove. Establish what happens when a PoP is unreachable, how traffic that cannot be decrypted is treated, and how configuration comes back out if you leave. Demos rarely differentiate these platforms; operational behaviour does.

How long does a SASE migration take?

It varies with how much networking is in scope, but the sequence matters more than the calendar. Start with remote users, who benefit most and carry the least dependency risk, and run the platform in monitor mode so it can observe real traffic before enforcing policy. Branch sites move last because they carry legacy applications, local breakout requirements and circuits under contract. Decide early what happens to the existing VPN, since leaving it running indefinitely means paying twice and leaving an unmonitored path into the network.

Ready to strengthen your security posture?

Have questions about this article or need expert cybersecurity guidance? Connect with our team to discuss your security needs.