The SASE solution to network and security’s complicated relationship status

Bob Gilbert, VP, Security Cloud GTM Strategy and Chief Evangelist, Netskope, discusses the complicated relationship between network and security, and how Secure Access Service Edge (SASE) can mitigate against this friction.
Bob Gilbert, VP, Security Cloud GTM Strategy and Chief Evangelist, Netskope, discusses the complicated relationship between network and security, and how Secure Access Service Edge (SASE) can mitigate can ease this struggle.

If our friends Security and Networking were on Facebook, they would probably both list their relationship status as “It’s Complicated.” Sometimes everything’s great, but now and then, things can get a little weird, unclear, or uncomfortable.

At many organisations, there has traditionally been a barrier between the security and networking teams. Each team has its own objectives, and at times, those objectives can be at cross-purposes. Enforcing security affects the networking team’s ability to do its job and serve user demands. At the same time, the needs and expectations of networking also directly impact the security team. This friction can cause networking and security to butt heads. This conflict can cost companies real money and put digital transformation projects at risk.

Over the last year, that friction has generated some extra heat. With networking teams scrambling to support remote workforces during the COVID-19 pandemic, security teams were tasked with the dual responsibilities of helping enable business continuity while also protecting their organisations from opportunistic attacks. Unfortunately, this heightened state of tension in the networking/security relationship isn’t going away.

Different teams with different needs

Organisations traditionally task the networking team with providing the connectivity so end users can access the resources they need. However, to keep users happy and business productive, the network has to be reliably available and fast.

At the same time, the security team needs to protect the company’s data. To do that, security has traditionally needed to implement heavy-handed controls that can impact a user’s access to resources. The traditional process of filtering network traffic for threats and enforcing access controls typically meant that users would experience slow performance or being blocked entirely from accessing an application or file. If security blocks access to a resource in the name of protecting the organisation, that obstruction may then cause problems for the networking team tasked with giving the user the access they need to do their job.

This complicated situation is really the root of the problem, and it’s been a long-standing issue between networking and security teams. They’ve been making it work for years for the sake of the company, but no one’s feeling the love.

SASE brings networking and security together

Technology may solve the issue. Thanks to the Secure Access Service Edge (SASE), things are finally getting much less complicated for security and networking. From a technology standpoint, SASE merges a modern set of security capabilities cloud-delivered with a modern set of networking capabilities. As a result, networking and security technologies are transforming to serve better a world where there will be more applications, users, and data outside the corporate network than inside it.

SASE is about a technology shift that’s already in progress. But there’s another side to this story. Digital transformation means that users expect to work from everywhere, on their own devices, with unfettered access to what they need. To that end, SASE is also playing the part of “marriage counsellor” for networking and security, bringing both teams together with the common objective of providing fast and secure access for any user on any device accessing any internet resource.

SASE establishes a set of requirements where the network and security architectures can evolve to better serve both sides, making both teams happier. The relationship status has suddenly changed, and they’re able to work together more harmoniously than ever before.

Bringing the magic back: allow is the new block

The ultimate end-state with SASE is that security doesn’t get in the way anymore. It’s actually integrated. It doesn’t impact the experience of the user or slow things down. And it doesn’t get in the way like the firewalls and secure web gateways (SWGs) of old, blocking access to everything just in case.

Instead of blocking everything that potentially poses a risk, security can now be very prescriptive and precise. SASE only blocks access based on actual risks as defined by granular, policy-based controls. It doesn’t arbitrarily deny access to benign or simply unknown access just to be safe, which has notoriously caused problems at many organisations. With a SASE architecture, allow is the new block.

On the networking side, security has historically been forced into their architecture. Because security was a mandatory requirement, the network team had to reroute traffic through the security appliances located in the data centre. But this sort of “hairpinning” of all network traffic creates a security bottleneck that significantly degrades user performance.

With SASE, users are allowed to go directly to where they want to go. A “direct-to-net” network architecture is enabled by security being implemented at the network edge, as close to the user as possible.

Equal partners build a lasting relationship

Some companies are already adopting SASE, modernising their architecture, and building a better relationship between teams. But as with anything, there are always going to be laggards. For example, some organisations are slow to adopt because they can’t get out of their own way. Or there’s the slow, bureaucratic process of regulations evolving. And for some bigger enterprises (like large, monolithic financial institutions), it’s going to take a more measured and gradual adoption process before they will be comfortable with letting go of blocking access to everything as a general rule.

For security, SASE is like using a scalpel rather than a sledgehammer. Organisations can immediately go from coarse “block everything” security to fine-grained controls. Zero Trust is another area that’s also evolving as part of this. Zero Trust traditionally meant “don’t trust anybody,” but in the SASE era, the Zero Trust concept has evolved to be something more adaptive. The emergence of artificial intelligence (AI) and machine learning (ML) capabilities is a part of this, making access control and data protection more intelligent and automated.

READ MORE:

But the reason SASE will win out is that it wasn’t designed to favour security over networking, or vice versa. SASE is a more simplified and elegant umbrella architecture. It provides fast and secure access for any user, anywhere, on any device, to anything they might need. From a security perspective, it’s moving the visibility, control, and inspection point as close to the user as you can. Wherever they go, the system follows them. And the network becomes a very important part of that because you’re no longer dealing with entities that are residing in one physical location. They’re everywhere now, so the network itself plays just as important a role as security does. And that equal value in the partnership between network and security is something that’s been missing for a very long time.

For more news from Top Business Tech, don’t forget to subscribe to our daily bulletin!

Follow us on LinkedIn and Twitter

Amber Donovan-Stevens

Amber is a Content Editor at Top Business Tech

Choose an AI solution to transform beyond technology

Kit Cox • 09th December 2024

The first step is knowing exactly what your business wants to achieve with AI; think faster, smarter and more efficient. Once you know what you are working towards, you can start looking for a solution that can help you make it a reality. AI integration can feel like a daunting task at the beginning, so...

A Roadmap to Security and Privacy Compliance

John Lynch Director of Kiteworks • 04th December 2024

Only by understanding the current regulatory environment and implementing robust data protection measures, can organisations enhance their security posture, ensure compliance, and build resilience against the latest cyber threats. This article provides a comprehensive roadmap of how to do it.

Data-Sharing Done Right: Finding the Best Business Approach

Bart Koek • 20th November 2024

To ensure data is not only available, but also accessible to those that need it, businesses recognise that it is vital to focus on collecting, sorting and governing all the data in their organisation. But what happens when data also needs to be accessed and shared across the business? That is where organisations discover a...

Nova: The Ultimate AI-Powered Martech Solution for Boosting Sales, Marketing...

Erin Lanahan • 19th November 2024

Discover how Nova, the AI-powered engine behind Launched, revolutionises Martech by automating sales and marketing tasks, enhancing personalisation, and delivering unmatched ROI. With advanced intent data integration, revenue attribution, and real-time insights, Nova empowers businesses to scale, streamline operations, and outperform competitors like 6Sense and 11x.ai. Experience the future of Martech with Nova’s transformative AI...

How E-commerce Marketers Can Win Black Friday

Sue Azari • 11th November 2024

As new global eCommerce players expand their influence across both European and US markets, traditional brands are navigating a rapidly shifting landscape. These fast-growing Asian platforms have gained traction by offering ultra-low prices, rapid product turnarounds, heavy investment in paid user acquisition, and leveraging viral social media trends to create demand almost in real-time. This...

Why microgrids are big news

Craig Tropea • 31st October 2024

As the world continues its march towards a greener future, businesses, communities, and individuals alike are all increasingly turning towards renewable energy sources to power their operations. What is most interesting, though, is how many of them are taking the pro-active position of researching, selecting, and implementing their preferred solutions without the assistance of traditional...

Is automation the silver bullet for customer retention?

Carter Busse • 22nd October 2024

CX innovation has accelerated rapidly since 2020, as business and consumer expectations evolved dramatically during the Covid-19 pandemic. Now, finding the best way to engage and respond to customers has become a top business priority and a key business challenge. Not only do customers expect the highest standard, but companies are prioritising superb CX to...