Users now work from anywhere and applications run in the cloud, so routing all traffic through a central data centre for security inspection no longer makes sense. Secure access service edge (SASE) moves networking and security controls closer to users.
What SASE includes
- SD-WAN for connecting sites efficiently.
- Secure web gateway (SWG) to filter web traffic and block threats.
- Cloud access security broker (CASB) for visibility and control over SaaS use.
- Zero trust network access (ZTNA) for application-level remote access.
- Firewall as a service (FWaaS) delivered from the cloud.
The security components are sometimes described together as security service edge (SSE).
Benefits
- Consistent policy for users wherever they work.
- Less backhauling of traffic and better cloud performance.
- Fewer separate appliances to manage.
Single vendor or best of breed?
Single-vendor SASE simplifies management and integration; combining specialist products can offer stronger individual capabilities. Evaluate how policies, identity and logging work across the components either way.
A phased approach
- Start with SSE for remote users, often replacing VPN with ZTNA.
- Add SD-WAN as branch circuits come up for renewal.
- Consolidate policy and logging into one model.
5 proven steps to adopt SASE
- Assess current architecture. Document existing WAN, remote access, web security and firewall tools, contracts and renewal dates.
- Define target outcomes. Typical goals include better user experience, consistent policy for all locations and simplified operations.
- Start with secure remote access or web security. Many organisations begin by replacing VPN with ZTNA or moving web filtering to the cloud.
- Extend to branches. Connect sites through SD-WAN to the SASE platform, applying the same policies to office and remote users.
- Consolidate and optimise. Retire overlapping tools as contracts end and tune policies using visibility from the platform.
Single-vendor or multi-vendor SASE?
Single-vendor SASE offers unified management and consistent policy, while a multi-vendor approach lets organisations choose the best networking and security components. Evaluate integration, performance, points of presence near your users and operational simplicity.
Common mistakes to avoid
- Expecting to replace every security tool at once.
- Ignoring data protection policies when moving inspection to the cloud.
- Not testing performance from all regions where users work.
- Separating network and security teams without shared processes.
Frequently asked questions
What is SSE?
Security service edge is the security portion of SASE, including SWG, CASB and ZTNA, without the SD-WAN component.
Is SASE only for large enterprises?
No. Mid-sized organisations often benefit most because SASE reduces the number of tools they must manage.
A 90-day action plan
Days 1 to 30: map current networking and security tools, contract end dates and pain points, and agree target outcomes with both networking and security leaders.
Days 31 to 60: evaluate providers against your requirements, focusing on points of presence near your users, policy management and integration with identity systems.
Days 61 to 90: pilot cloud-delivered web security and private application access for a group of remote users, then plan branch connectivity in phases.
Questions to ask providers
- How many points of presence are near our users, and what latency should we expect?
- Is there one policy engine for all users and locations?
- How is encrypted traffic inspected while respecting privacy requirements?
- Which data protection controls are included?
- How do licences scale for users, sites and bandwidth?
Key terms explained
- Secure web gateway: a service that filters web traffic for threats and policy violations.
- CASB: a cloud access security broker that controls use of SaaS applications.
- Firewall as a service: firewall functions delivered from the cloud.
- Point of presence: a location where the provider processes user traffic.
The bottom line
Converging networking and security into a cloud-delivered service helps organisations protect users consistently wherever they work, while reducing the number of separate tools to manage. Most succeed by moving in phases, starting with remote access or web security and extending to branches as contracts end. Align networking and security teams early, test performance from every region and keep data protection requirements in view. A phased, outcome-focused approach delivers early wins and builds confidence for the wider transformation.
Further reading on SASE
For authoritative, vendor-neutral guidance on SASE, see NIST SP 800-207 Zero Trust Architecture. You can also browse our free whitepapers.

