Network

Understanding SASE: network and security from a single cloud

16 August 2026

SD-WAN and security are converging. SASE bundles network and security functions into a cloud-based model – creating a realistic path to secure access for distributed organizations.

For decades, IT security was tied to a place: the corporate network with a firewall at the boundary to the internet. But that clear edge no longer exists. Applications live in the cloud, employees work from anywhere, and data often flows past headquarters entirely.

SASE is a response to this shift: an architecture model that brings network and security closer to the user, device and application – instead of routing every access awkwardly through headquarters.

What is SASE?

SASE stands for Secure Access Service Edge. At its core: network and security functions are delivered from the cloud and applied where access actually happens – as close as possible to the user, device and application.

Access decisions are no longer based on location alone, but more on identity, device posture, context and the target application. This creates a more modern approach for distributed organizations, cloud services and mobile work.

The five building blocks

SD-WAN

Connects sites intelligently and application-aware as the network foundation

Secure Web Gateway

Protects web access, filters content and blocks malicious destinations

CASB

Brings visibility and control over the cloud services in use

ZTNA

Grants access to individual applications on a least-privilege basis

FWaaS

Delivers firewall capabilities from the cloud, without hardware at every site

SASE and SSE: the difference

SSE stands for Security Service Edge and describes the security side of SASE. It typically includes SWG, CASB, ZTNA and FWaaS – but without the SD-WAN network component.

For many organizations this matters, because they can modernize security without immediately rebuilding the entire WAN or SD-WAN architecture. SASE is the larger target picture; SSE can be a sensible first step.

Key takeaway

SASE = SSE + SD-WAN. Those not yet ready to rebuild their network entirely can start with SSE and add the network side later.

One vendor or several?

A central design question is whether all building blocks come from a single vendor or whether several specialized solutions are combined. A single-vendor approach can simplify operations and policy. A best-of-breed approach offers more flexibility but creates more integration effort.

The right answer depends on existing infrastructure, contracts, security level, operating model and internal resources. What matters is not the vendor, but whether architecture, operations and security control fit together.

Why SASE is becoming relevant for organizations

Consistent policies

Security rules apply more consistently across office, home office and mobile users

Better user experience

Access runs through suitable points of presence instead of unnecessarily via headquarters

Less complexity

Network and security functions are brought together more closely

Modern remote access

ZTNA replaces classic VPN thinking with controlled application access

Scalability

New sites and users can be onboarded in a more structured way

The path to SASE – without a big bang

1

Take inventory

Make applications, user groups, sites, VPN, MPLS, firewalls and existing contracts transparent

2

Start with the biggest lever

Often ZTNA or SSE is the pragmatic entry point before the network side is fully rebuilt

3

Pilot

Start with one site, one user group or one application and sharpen policies

4

Expand step by step

Add SSE building blocks, bring in SD-WAN and retire legacy systems in an orderly way

Plan SASE and secure access in a structured way
To IT Security