SASE: Secure Access Service Edge Defined

Updated: August 28, 2026 Time to read: ~

TL;DR

Secure Access Service Edge (SASE) is a cloud-native security architecture, coined by Gartner in 2019, that consolidates multiple network security tools — including Software-Defined Wide Area Network (SD-WAN), Firewall as a Service (FWaaS), Cloud Access Security Broker (CASB), Secure Web Gateway (SGW), and Zero Trust network access — into a single vendor solution. Unlike traditional perimeter-based security, SASE centers protection on user identity and device, making it especially valuable for distributed workforces. While adoption offers agility, cost savings, and simplified management, organizations should weigh challenges like staff retraining and the model's relative immaturity before committing.

What is Secure Access Service Edge (SASE)?

Secure access service edge, or SASE, is a form of security network architecture. Rather than working with four or five different vendors on pieces of your security plan, you'll work with just one that deploys everything you need in a cloud environment.

When did SASE begin?

We didn't know anything about the SASE movement until 2019, when Gartner defined the acronym and changed our terminology forever. 

Three security analysts developed the Gartner SASE vision. As they looked at the current security landscape, they realized that most companies focused on servers and locations. The dominant philosophy was that if they could keep one specific item in a defined space (such as a main server within a data center in Cleveland) protected, all users would also be protected. 

How does SASE shift the security focus?

In the SASE model, the focus shifts to the user's identity and the device that person uses. Security should start here and radiate outward rather than focusing on the destination and radiating in. 

The concept of the "edge" is an integral part of the SASE model. In security terms, the edge is close to a consumer. The smaller the distance between a device (like a phone) and the destination (like a server), the fewer delays and the better the experience.

What is SASE?

A SASE solution in the Gartner model has three main characteristics. The solution is:

  • Driven by users and resources. An individual's identity, not the person's Internet Protocol (IP) address, determines access. Security options are set at the cloud level, triggered by the person's identity. 
  • Cloud-first, not just cloud-enabled. The solutions are designed to work within the cloud, and they offer cloud-based advantages such as adaptability, easy maintenance, and savings. 
  • Completely supported. One network provides everything a user might need, no matter where that person is. 

A solution like this may seem attractive now, especially if you have users distributed across many offices or even all across the world. But as more devices connect to the internet, and as consumers grow impatient with latency issues, SASE is likely to be even more valuable to companies just like yours.

What are the benefits and challenges of SASE?

Switching from several solutions to one isn't easy. Perusing the pros and cons can help you understand if this is the right path for you or your organization. 

SASE BenefitsSASE Challenges
Agility: Scale up or down as your client base changes.Change: New interfaces and workflows require adjustment.
Control: Apply consistent security policies across all devices.Newness: Gartner estimates up to 10 years for mainstream adoption; vendor offerings may shift.
Cost: Single-vendor purchasing reduces contract overhead.Training: Staff, leaders, and customers may all need onboarding.
Ease: Fewer vendors and protocols to track and supervise. 

Some security professionals may look over these lists and decide that now is the time to invest in SASE. But others may choose to wait a year or two before taking this step. 

If you do jump into the SASE space, expect quick implementation. Most vendors offer connections through virtual appliances, so you won't need to overhaul data centers or otherwise invest in hardware updates. You will need time to train staff, however.

What do SASE services include?

We've mentioned that SASE vendors combine several different security options into one product. Let's dig deeper into what companies following the Gartner SASE model include in their offerings. 

In general, analysts say, SASE products are comprised of five main technologies. They are:

  1. SD-WAN. A software-defined wide area network, or SD-WAN, connects far-flung users to key assets within your company. In the SASE model, everything is based within the cloud with distributed access points close to users. 
  2. FWaaS. Firewall as a service, or FWaaS, puts security technology in the cloud to protect the service edge. 
  3. Cloud Access Security Broker (CASB). These tools ensure security policies are applied properly, no matter what device the user selects for a connection. 
  4. SGW. Secure web gateways, or SGWs, block some types of malicious traffic to company servers. They inspect packets at the edge with rules they update consistently.
  5. Zero Trust network access. Security relies on the user's identity rather than the IP address the person is using right now. 

Don't think of this as a shopping list. Some companies offer more products under the SASE model, and others swap out some elements for others they think will have more impact. 

How do you choose a SASE vendor?

Several companies are competing for your SASE business. In fact, there are so many entering the space that listing them is nearly impossible. As soon as we'd create a list, it would go out of date. 

Who can you trust in an ever-changing environment? Consult up-to-date analyst reports and vendor comparison resources to evaluate current SASE offerings.

Frequently asked questions

What makes SASE different from traditional network security?

Traditional security models protect a fixed location — like a central server in a data center — and assume that users inside that perimeter are safe. SASE flips this model by anchoring security to the user's identity and the device they're using, regardless of where they are located.

When was SASE introduced, and who created it?

The term was coined in 2019 by three security analysts at Gartner. They observed that most organizations were still focused on protecting physical server locations rather than the distributed users and devices that increasingly define modern work.

What technologies are bundled into a SASE solution?

A standard SASE offering typically combines five core technologies: SD-WAN (Software-Defined Wide Area Network), FWaaS (Firewall as a Service), Cloud Access Security Broker (CASB), SGW (Secure Web Gateways), and Zero Trust network access — all delivered through a single cloud-based vendor.

What are the main challenges of adopting SASE?

The three primary hurdles are organizational change (adapting to new interfaces and workflows), the relative immaturity of the market (Gartner projected up to 10 years for mainstream adoption), and the training burden placed on staff, leadership, and potentially customers.

Do I need to replace my hardware infrastructure to implement SASE?

Not necessarily. Most SASE vendors deliver their solutions through virtual appliances, which means you can avoid overhauling data centers or investing heavily in hardware upgrades. The main investment will be in staff training and onboarding.

Is SASE suitable for companies with globally distributed teams?

Yes — SASE is particularly well-suited for organizations with users spread across multiple offices or locations worldwide. Its cloud-first design and identity-driven access model ensure consistent security policies regardless of where or how employees connect.

References

Gartner Says the Future of Network Security Lies With SASE. (November 2019). The Hacker News. 

SASE: The Next Frontier in Cybersecurity. (February 2020). Digitalist Magazine.

Analysts Debate SASE's Merits as Vendors Board Hype Train. (November 2019). SDX Central. 

Who's Selling SASE and What Do You Get? (October 2020). Network World.

Continue your Identity journey