Managed security

SASE

Security that travels.

SASE, secure access service edge, usually said as “sassy”, moves network security out of the office and into the cloud, so somebody working from a kitchen table gets the same filtering and the same access rules as somebody at a desk. It commonly replaces a VPN first and some of the hardware in the comms cupboard later. It suits organizations whose people are no longer mostly in one building.

Who it's for

Your security is in a building your staff have stopped visiting.

Most networks were designed when everybody was inside them. Four consequences of that show up in almost every conversation we have about this.

The VPN is both the bottleneck and the complaint. A virtual private network sends remote traffic back through the office before it goes anywhere else, which was fine when three people worked from home. Now it is slow, it drops, and people quietly stop connecting to it, which removes the protection it existed to provide.

Protection stops at the front door. The filtering and inspection live on a firewall in the office. Anyone working elsewhere is browsing with none of it, which nobody decided and everybody has come to accept.

Once someone is connected, they can reach everything. Most VPNs put a device on the network rather than granting access to specific applications. A contractor who needs one system gets a route to all of them, and that route outlives the project.

Nobody knows which cloud applications are in use. Teams sign up for tools with a company card and a work email. It is usually reasonable behaviour solving a real problem, and it is invisible until somebody asks where a particular set of files lives.

SASE is a direction, not a purchase

Nobody needs the whole architecture on day one, and buying it that way is how a project becomes an eighteen-month migration with a bad first quarter.

The usual sensible order is: replace the VPN, add filtering for people outside the office, then move firewall functions to the cloud as hardware comes up for renewal. Each step is useful on its own and can be the last one.

What's included

The parts, and what each one is actually for.

SASE is an umbrella term covering several distinct products. Here is what sits under it, in plain English, with the acronyms unpacked.

  • Zero trust network access, replacing the VPN

    ZTNA grants a person access to a named application rather than putting their device on your whole network. A contractor who needs one system gets one system. It is the single change that does most of the work here, and usually the one to do first.

  • Secure web gateway

    SWG is filtering and inspection of web traffic, blocking known-bad destinations, checking downloads, applying your acceptable-use policy, applied wherever the person is working rather than only when they are in the building.

  • DNS filtering

    DNS is the internet’s address book: the service that turns a name like example.com into a numeric address. Filtering at that layer stops a device reaching a known-bad destination before any connection is made. It is cheap, it is quick to deploy, and it is often the first useful step.

  • Cloud access security broker

    CASB gives you visibility of which cloud applications your organization actually uses, which of them hold company data, and which ones a risk assessment would fail. The output is usually a conversation with a team rather than a block.

  • Firewall as a service

    Firewall functions delivered from the cloud instead of a box in the comms cupboard, so branch offices and home workers get the same policy without hardware at each location. Usually adopted as existing hardware reaches end of support rather than all at once.

  • Device posture checks

    Before access is granted, the platform checks that the device is what it claims to be: managed, patched, encrypted, running endpoint protection. An unmanaged personal laptop can be allowed limited access rather than being either fully trusted or fully blocked.

  • Identity as the control point

    Access decisions are made on who the person is, verified with MFA, multi-factor authentication, a second check such as a prompt on a phone before a login is accepted, rather than on which network they happen to be connected to.

  • One policy set, and logs into the SOC

    The practical benefit under all of it: one place where the rules live instead of five, and one log stream feeding our security operations centre so access decisions are visible alongside everything else we watch.

How it works

Three stages, each useful on its own.

We do not start with an architecture diagram. We start with who works where, and what they actually need to reach.

  1. Map who works where, and what they reach

    A short piece of work listing your locations, your remote and hybrid patterns, the applications people genuinely need, and who currently has a route to something they no longer use. That list is usually the most useful document produced in the whole project.

  2. Replace the VPN first

    Zero trust access for the applications people use daily, rolled out to a pilot group, then more widely. Most people notice that connecting got simpler and faster before they notice anything about security, which is the sign it was done properly.

  3. Then filtering, then the hardware

    Web and DNS filtering extended to everyone wherever they work, cloud application visibility switched on, and firewall functions moved to the cloud as existing hardware reaches renewal. Staged deliberately so nothing is thrown away early.

What it costs

Per user, per month, plus the migration work.

The subscription is predictable. The design and cutover is a project, and quoting it as though it were not is how these go wrong.

Three things move the ongoing number: how many users, how many applications need individual access policies, and whether you are also moving firewall functions to the cloud or keeping hardware in place.

Against that, some existing costs stop. VPN appliances and their support contracts, separate web filtering subscriptions, and in time some firewall hardware refresh. We will put the comparison in writing with your current renewal dates on it, because that is the only version of this comparison worth reading. Platform we deploy: Netskope.

Do not scrap the firewall yet

If you have people, servers or printers in a building, you still need something at that edge. SASE changes where policy is enforced for people; it does not make a site with equipment in it disappear.

The sensible pattern is SASE for people and cloud access, with managed firewall continuing at any site that still has things plugged into it. Anyone proposing you remove both at once is not describing your building.

Why us for this

The design is the deliverable. The platform is a means.

SASE is one of the noisiest categories in this industry. Every vendor defines the boundary differently, most of the marketing describes an end state very few organizations of 15 to 200 people actually reach, and it is easy to spend a year on a migration that delivers its real value in the first six weeks.

What happier IT contributes is not access to a platform, plenty of providers have that. It is the design discipline: deciding which applications warrant individual access policies and which do not, sequencing the work so each stage stands alone, and writing the policy set in a way somebody can still understand in two years. A policy nobody understands is how you end up with an access rule from 2019 that grants more than anybody realises.

The access logs then feed our own security operations centre in Canada, staffed by happier IT employees, so who reached what is visible next to everything else we watch rather than in a separate portal. Staffed hours: 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific.

Go deeper

Questions

What people ask before they sign anything.

What is SASE?

SASE stands for secure access service edge, and it is said as “sassy”. It means delivering network security from the cloud rather than from hardware in your office, so the protection follows the person instead of the building. In practice it bundles several things: access control for applications, web and DNS filtering, visibility of cloud application use, and firewall functions delivered as a service. Most organizations adopt the pieces in stages rather than all at once.

Does SASE replace our VPN?

Yes, and that is usually the first and most worthwhile step. A VPN puts a device onto your network and then trusts it. Zero trust network access grants a person access to named applications and nothing else, checked each time against who they are and what device they are on. Users generally find it faster, because traffic no longer detours through the office, and you stop maintaining an appliance whose capacity dictates how many people can work remotely.

What is zero trust network access?

ZTNA is an access model that grants access per application rather than per network. Instead of “you are connected, so you can see everything”, each request is checked against who the person is, whether they passed multi-factor authentication, and whether their device meets your standards. The practical effect is that a contractor who needs one system gets one system, and access ends when the project does. There is a fuller explanation in our glossary entry on zero trust.

Do we still need a firewall in the office?

If there is equipment in the building, servers, printers, cameras, machinery, guest wifi, then yes. SASE governs how people reach applications. It does not remove the need for something controlling traffic at a site that still has things plugged into it. The honest pattern for most organizations of this size is SASE for people and cloud access, with managed firewall continuing at the sites that need it.

Is SASE only for large organizations?

No, and the economics have shifted. It used to require hardware at every location, which ruled it out for organizations of this size. Delivered from the cloud it is priced per user, so a 40-person company with people in three cities can buy the same model as a much larger one. The parts that scale with organization size are the design work and the number of applications needing individual policies, not the technology itself.

How long does a SASE migration take?

The VPN replacement, the stage that delivers most of the value, is typically weeks rather than months for an organization of 15 to 200 people, including a pilot group. Extending filtering to everybody follows quickly. Moving firewall functions to the cloud is deliberately slow, because it should follow your hardware renewal dates rather than lead them. We will give you a timeline for your locations once we have mapped the applications.

What does SASE cost?

Ask any provider to set the subscription against what stops: VPN appliance support, separate filtering subscriptions, and eventually some firewall hardware. That comparison, with your renewal dates in it, is the only one worth making.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.