What Is SASE? Security and Networking, Finally in One Conversation
- 11 minutes ago
- 5 min read

For most of the last two decades, networking and security were separate purchases, separate teams, and separate arguments. You bought connectivity from one set of vendors and security from another, then spent a lot of money and effort making them play nicely at the office edge. SASE is the industry's attempt to stop doing that.
SASE — Secure Access Service Edge, pronounced "sassy" — is a cloud-delivered model that combines wide-area networking and network security into a single service, delivered from the cloud and enforced close to the user wherever they are. Coined by Gartner in 2019, it's less a single product than an architecture: instead of routing everyone's traffic back to a headquarters firewall, security and connectivity follow the user.
This guide explains what's actually inside SASE, why the old model broke, and how to tell whether it's a genuine fit for your business or just a rebranding of things you already own.
Why the old model stopped working
The traditional design assumed a castle-and-moat: employees sat inside the office, applications lived in the company data center, and a big firewall at the perimeter inspected everything going in and out. Remote users connected back through a VPN, and traffic "hairpinned" — traveled all the way back to HQ to be inspected, then back out to a cloud app.
That design fell apart for a simple reason: the users and the applications both left the building. When your team works from anywhere and your apps live in Microsoft 365, Salesforce, and a dozen other clouds, backhauling every packet to a central firewall adds latency, frustrates users, and creates a bottleneck you pay to expand. SASE flips it: inspection happens in the cloud, near the user, so the shortest secure path wins.
What's actually inside SASE
SASE is best understood as two halves that finally share one control plane.
The networking half is essentially SD-WAN — software-defined wide-area networking that intelligently routes traffic across whatever connections a site has. If SD-WAN is new to you, our SD-WAN explainer covers the fundamentals; SASE builds security directly on top of it.
The security half is often referred to as SSE (Security Service Edge) and typically bundles four capabilities. A Secure Web Gateway filters and inspects web traffic. A Cloud Access Security Broker (CASB) governs how your data moves in and out of SaaS apps. Firewall-as-a-Service delivers firewall inspection from the cloud instead of a box. And Zero Trust Network Access (ZTNA) replaces the old "trust anyone on the VPN" model with per-application access that verifies identity every time. Vendor learning resources from Palo Alto Networks and Cloudflare lay out these components in more depth and are useful vendor-neutral primers even if you never buy from them.
The defining idea is zero trust: never assume a user or device is safe because of where it's connecting from. The U.S. government's own shift in this direction, documented in CISA's Zero Trust Maturity Model, is a good sign of where enterprise security is heading.
SASE vs. SSE vs. "just buying a firewall"
Buyers get tangled here, so keep it simple. SSE is the security half on its own. SASE is SSE *plus* the networking (SD-WAN) half, converged. If a vendor is pitching you "SASE" but only delivers the security services and expects you to bolt on networking separately, that's SSE — which may be exactly what you need, but call it what it is.
And no, buying a next-generation firewall is not SASE. A firewall is a component. SASE is the model that delivers firewalling, web filtering, data control, and secure access as one cloud service that follows your users. The distinction matters because the value of SASE comes from *convergence* — one policy, one console, one vendor relationship — not from owning more boxes.
When SASE is worth it — and when it isn't
SASE earns its keep when your reality looks like this: a distributed workforce, heavy reliance on cloud and SaaS applications, multiple offices, and a security stack that's become a patchwork of appliances that are expensive to maintain and hard to keep consistent. If your VPN is straining, your branch offices each have their own aging firewall, and your team is everywhere, SASE is likely a real upgrade.
It's less compelling if you're a single-location business with most applications still on-premises and a simple, stable network. In that case you may be better served by targeted improvements than by a full architectural shift. SASE is a journey, not a one-day cutover — most organizations phase it in, often starting with ZTNA to retire the VPN, then converging networking over time.
The risk to watch for is the "SASE-washing" problem: vendors relabeling existing products as SASE without true convergence. The test is whether networking and security share a single policy engine and console, or whether you're being sold two things in one invoice. (We wrote about how to spot that kind of pitch in Is Your Cybersecurity Advisor Actually Selling You Something?)
How to evaluate a SASE offering
Single control plane. Can you write one policy that governs both a user's network path and their security posture? If not, it isn't converged.
Points of presence. SASE inspects in the cloud, so the provider's global footprint matters — traffic should hit a nearby node, not cross an ocean for inspection.
Identity integration. ZTNA lives or dies on clean identity. Confirm it integrates with your identity provider (Microsoft Entra, Okta, Google).
Migration path. How do you get from today's VPN and firewalls to this model without a risky big-bang cutover?
Real cost over time. Model licensing per user against the appliances, maintenance, and bandwidth you'd retire. The savings are often real but rarely match the first quote.
Frequently asked questions
Is SASE a product or a strategy? Both, in practice. It's an architecture (a strategy for converging networking and security in the cloud), but vendors sell it as a product suite. Judge any product by how well it delivers the converged model, not by the label.
How is SASE different from SD-WAN? SD-WAN is the networking half. SASE includes SD-WAN and adds cloud-delivered security (secure web gateway, CASB, firewall-as-a-service, and zero trust access) under one policy.
Does SASE replace our VPN? That's usually the first and biggest win. Zero Trust Network Access grants per-application access with continuous identity verification, which is both more secure and less clunky than a traditional VPN.
Is SASE only for large enterprises? No. Mid-market and distributed businesses often see the clearest benefit because they feel the pain of managing separate security appliances at multiple sites without a large team to do it.
What does SASE cost? It's typically licensed per user per month, sometimes with bandwidth or points-of-presence components. The honest comparison is against everything it lets you retire — VPN concentrators, branch firewalls, and their maintenance.
The bottom line
SASE is the recognition that in a cloud-and-anywhere world, networking and security are one problem, not two. Done right, it simplifies a sprawling stack into a single policy that follows your users and cuts the latency of backhauling traffic to a central firewall. Done wrong — or bought from a vendor who's simply relabeled old products — it's an expensive way to end up with the same complexity plus a new acronym.
Because SASE sits precisely where the networking and security sales pitches overlap, it's one of the easiest categories to oversell. AGI Beacon doesn't carry a quota on any platform, so we can tell you whether you need full SASE, just SSE, or a few targeted fixes — and shortlist the providers whose footprint and identity integration actually match your environment. Start the conversation here.
.png)



Comments