Part 2 of a three-part series
Hybrid cloud systems and enterprises’ adoption of edge computing has solved a number of modern problems, from the latency demands of real-time applications to the regulatory demands of data privacy in a global economy. But the point at which on-premises, cloud, and edge computing meet has created challenges in securing diverse systems under the same roof (part 1).
Secure access service edge (SASE) addresses this fragmentation. It integrates software-defined networking, threat prevention, access control, and application security into a unified, cloud-delivered platform accessed through a single management interface.
SASE’s operational foundation rests on globally distributed points of presence (PoPs) positioned to place security and networking enforcement as close as possible to users and data sources. This distributed fabric, often managed by SASE providers, eliminates the operational burden of provisioning and maintaining complex network infrastructure, while guaranteeing low-latency access to cloud applications through direct-to-cloud routing.
The convergence begins with a software-defined wide area network (SD-WAN), which intelligently routes traffic across multiple transport links, including Multiprotocol Label Switching (MPLS), broadband, LTE, and 5G. Rather than relying on expensive, static MPLS circuits, SD-WAN dynamically selects optimal paths based on application requirements, link quality, and business priorities. This intelligent routing ensures branch offices, remote workers, and edge devices achieve consistent application performance without capacity constraints.
“The software-defined networking is where we see most customers start with their SASE deployments,” says Ben Radcliff, VP of cybersecurity and managed security services at Ensono.
The second phase for most organizations is to overlay security onto the SD-WAN, with zero trust as the prevailing theme, adds Dave Shackleford, founder and CEO at Voodoo Security.
“Over time, SASE converges the security Web gateway and provides firewall-as-a-service (FWaaS) in the cloud fabric. Standalone proxies go away when everyone goes through this system,” he explains.
SASE Integrates Critical Functions
Essentially, a SASE architecture integrates four critical security functions that previously required separate appliances and licenses:
-
FWaaS delivers next-generation firewall capabilities — stateful inspection, application control, intrusion prevention, and threat intelligence — through a cloud platform, eliminating the need for hardware firewall deployments at each location.
-
Secure Web gateway (SWG) protects users accessing Internet resources by filtering malicious websites, inspecting Web traffic, and enforcing acceptable use policies regardless of user location. With direct Internet access from remote sites, it bypasses inefficient traffic hair-pinning through central data centers.
-
Cloud access security broker (CASB) provides visibility and control over software-as-a-service (SaaS), discovers unsanctioned cloud services, and enforces data loss prevention policies to prevent sensitive information from leaking to unauthorized repositories.
-
Zero-trust network access (ZTNA) replaces traditional VPNs with identity-driven, application-level access controls that continuously verify users.
Experts agree that the unified policy engine is a key advantage over legacy security architectures. Security administrators can define policies once in the SASE console and enforce them consistently across all edges, cloud workloads, and remote users, rather than maintaining separate policy frameworks for firewalls, VPN appliances, Web proxies, and cloud security tools.
These policies can incorporate contextual data, including user identity, device posture, geographic location, behavioral patterns, and risk scores, to apply adaptive controls in real time. When organizational requirements change, policy updates propagate automatically across the entire platform, eliminating the need for manual reconfiguration at individual sites.
“This centralization eliminates the policy inconsistencies associated with multivendor security stacks and may even reduce the staff required,” says John Grady, principal analyst at Omdia.
SASE eliminates VPN bottlenecks for remote workers and secures the Internet of Things (IoT). In IoT environments, SASE enforces zero-trust policies at the device level, identifying and mitigating risks early through granular access controls while protecting diverse, often resource-constrained endpoints that lack built-in security capabilities.
The operational simplification also extends to deployment and infrastructure provisioning. New branch locations can connect to SASE platforms within hours using lightweight edge devices, rather than the weeks required for hardware procurement and configuration. Organizations can also add thousands of edge nodes without proportional increases in staff or infrastructure costs; the SASE provider handles scaling, updates, and availability across the distributed fabric.
In addition, unified logging and analytics provide end-to-end visibility across users, devices, applications, and threats. This enables faster anomaly detection, more thorough incident investigation, and more precise threat response compared to correlating logs across multiple disparate tools.
Challenges in Replacing Legacy Security
This architectural shift requires organizations to fundamentally rethink security governance. It means “shifting from device-centric controls to identity-centric and application-centric policies, retraining IT teams to operate cloud-native services rather than managing appliances, and establishing new relationships with cloud service providers who become responsible for infrastructure security that organizations previously controlled directly,” Grady says.
Regardless of SASE’s effectiveness at securing the edge, there is the practical reality that security teams must replace entrenched legacy infrastructure. This transformation can create significant organizational, technical, and operational challenges that organizations frequently underestimate. Many scenarios often necessitate the continued use of legacy firewalls and VPN infrastructure, such as on-premises databases accessed only by internal applications, legacy systems that cannot connect via SASE, or third-party vendor relationships that require direct network access.
“It’s a big undertaking, and only a small percentage of enterprises are far down the path to mature SASE, let alone have fully mature SASE capabilities in place,” Grady said.
Rather than simply translating legacy rules into SASE syntax, organizations need to redesign policies from first principles, applying least-privilege principles so that users and devices receive only the access necessary for their specific roles and applications. This redesign process requires understanding the business rationale behind each rule, validating that the redesigned policies don’t break legitimate business workflows, and conducting extensive testing before production deployment.
The transition period, which frequently extends six to 18 months or longer, requires maintaining security across both legacy and SASE-protected environments simultaneously. During this phase, organizations must ensure that users, devices, and applications cannot bypass SASE controls by routing traffic through remaining legacy infrastructure.
In part 3 we discuss the six stages to successfully execute this transformation.

No responses yet