Skip to main content
Oyoon Altaqnya

SASE / SSE

Secure access to the web, cloud and private applications for branches and remote users, enforced in the cloud instead of through a central data center.

NIST CSF 2.0 functions
Protect
Relevant for
  • Banking and financial services
  • Telecommunications
  • Government and public sector
  • Oil and gas

Overview

Staff now work from branches, homes and cloud applications, and much of their traffic never touches the head office. Sending it all back through one data center slows people down, and leaving it unprotected exposes the organization.

We help you move security to where users and applications are, with one set of policies for web, cloud and private access.

What you get

  • Staff protected the same way in the office, at home and on the road
  • Access to applications decided by user and device, not by network location
  • Direct, secured access to the internet and cloud without sending traffic back to the data center
  • Consistent policy and logging across web, cloud and private applications

What we cover

  • Secure web gateway and URL filtering
  • Cloud access security broker (CASB)
  • Zero trust network access (ZTNA) to private applications
  • Cloud-delivered firewall and DNS security
  • SD-WAN integration for branches
  • Data protection and logging for your SIEM

How we work

  1. Assess

    We review where users, applications and branches are, and how traffic flows today.

  2. Design

    We design policies and the migration order, keeping your existing firewalls and VPN where they still make sense.

  3. Pilot

    A pilot group moves first, so we can check performance and application compatibility.

  4. Roll out

    We migrate users and sites in waves, and train your administrators.

Deliverables

  • Architecture and policy design
  • Configured SASE or SSE service
  • Migration plan with a rollback option
  • Administrator training and documentation

Questions buyers ask

What is the difference between SASE and SSE?

SSE is the set of security services for web, cloud and private application access. SASE adds the networking side, such as SD-WAN. We recommend the scope that fits your sites and applications.

Can SASE replace our VPN?

For many applications, yes, because zero trust network access gives per-application access. We migrate in stages and keep the VPN where it is still needed.

  • Next-Generation Firewall (NGFW)

    Next-generation firewalls that control traffic by application, user and content, with a clean, documented rule base.

    NIST CSF function: Protect
  • Identity & Access Management (IAM)

    Identity and access management with single sign-on, so the right people reach the right systems and access is granted and removed through a clear process.

    NIST CSF function: Protect
  • Secure DNS

    DNS filtering that blocks malicious and newly registered domains for every device, with query logs that feed your security monitoring.

    NIST CSF function: Protect