What are the greatest advantages offered by SASE?
Sort by:
By far it is providing the same level of protection for assets on our network and when they are out and about.
Disclaimer: I work for a SASE company and also wrote a book on what SASE is, and why you need it (vendor agnostic)
Now for some vendors, they will try to lock you into purchasing more appliances and kit, as well as a cloud overlay. They will call this a SASE deployment, when in fact it’s more like a combination of on-prem technology projected to the cloud.
Other vendors may offer a multi tiered offering through a combination of products, and some people offer a single-vendor approach.
Now honestly, each one of these architectures has pros and cons, and while I believe that converged single-vendor is the best approach, every situation is different.
Now the three greatest advantages in my mind are pretty simple, but maybe not as quantifiable as you’d like:
1) Emhanced security: because the tech stack should be hosted in the cloud at a point of presence, you don’t need to worry about buying more firewalls or how many PPS each edge device supports. You treat your remote workers as ‘branches of one’ which helps facilitate a ZTNA approach.
2) faster and more flexibility: you have a direct link to the internet through a cloud gateway, which means no more backhauling through multiple security appliances in your DC. Spinning up another site or user takes seconds (and most vendors have flexi licenses. ) Which means you don’t have to wait 6 months for an ASA license or new fiber to be run in for MPLS.
3) Easy management: most companies out there have an overlay to manage the networking, security, access policies etc all in one place. This helps converge different internal teams, and reduces confusion. The CLI is a thing of the past, and so is infighting.
There’s tons of benefits and advantages, and if you want to talk more in the future - I’ll be happy to chat :)
SASE is useful only if you use Clouds extensively and there is a need to protect the Edge (Employees and Customers) especially when there is Zero Trust principle for security. I think one of the key benefits is an all-in-one security management solution as compared to a mix-and-match.
One of my customers which had multi-cloud environment upgraded their security with SASE and were able to demonstrate to the management and their customers that their security was as good as it gets.
If a vendor is selling SASE for closed network enterprises, they should carefully evaluate if they indeed need it.
Traditionally in organisations network grows organically and with virtualisation and "Hot-Hot" availability, the network is still flat. Now with the new normal, cloud adoption and SaaS, networks architecture can be software-defined, one can implement micro-segmentation and granular cyber security policies much needed to implement an effective, manageable and secure network architecture, and cyber security in the host environment and for Zero Trust.
Security, Agility and Simplicity.