SASE 101: Everything You Need to Know
Summary: In this post, we are going to break down the basics of SASE including what it is, what it’s not, and what types of environments can benefit from it.
Let’s start as basic as it gets: SASE stands for Secure Access Service Edge.
For the first few years of existence, SASE was a buzzword being thrown around the network and IT industry because there was no clear definition. It was originally coined by Gartner in 2019 with Cato Networks as the forefront example of what SASE should look like. Years later, when more technologies emerged onto the SASE scene, they released the SASE Gartner Magic Quadrant which included a guideline what what these technologies needed to be considered SASE.
In short, SASE is the convergence of network edge functions (most prominently, SD-WAN) and network security into a single service.
Now, here’s the long version:
The Requirements to be a SASE Platform
The word “SASE” was coined by Gartner and, therefore, they were the organization that decided what SASE is meant to include. According to their 2025 SASE Gartner Magic Quadrant, here’s what SASE solutions should include:
- A POP-based architecture
- Centralized management with no more than two consoles to manage all SASE functionality
- SWG (Secure Web Gateway) via proxy
- SaaS visibility and access controls
- ZTNA (Zero Trust Network Access)
- SD-WAN (Software-Defined Wide Area Network)
- Layer 7 Firewall
“Nice to Have” Features of a SASE Platform
There are some providers that go above and beyond the features listed above. These are not requirements to be included in the Gartner Magic Quadrant, but they are certainly beneficial to customers and help enhance a provider’s SASE solution.
- Unified management with a single console to manage all functionality of SASE
- Secure connection to the SASE platform using:
- software agents
- agentless portals
- browser plug-ins
- secure enterprise browsers
- remote browser isolation (RBI)
- Sensitive data visibility and control (Data Loss Prevention, or DLP)
- Additional security capabilities:
- Network sandboxing
- DNS protection
- API-based SaaS access
- Application layer visibility and protection
- Continuous adaptive risk scoring
- Additional networking capabilities:
- Enhanced internet
- Private network backbone connecting POPs
- External DNS services
- Cloud on-ramps
- Ability to replace a branch router and support meshed topologies
- Digital Experience Monitoring (DEM)
- Support for Operational Technology (OT) and Internet of Things (IoT)
SASE has unfortunately started to become a term that people throw around like hot cakes! Everyone who has an SD-WAN or security platform is claiming to be SASE and it’s hard to fight through all the noise to get through to the truth. That’s what I’ll help you start to do today.
What SASE is NOT
It’s important to understand that at it’s core, SASE is a framework, not a point product. Instead of bringing in different products for SD-WAN, firewall, CASB, etc., we are now converging all of those into (ideally) a single platform to manage.
By 2028, 70% of SD-WAN purchases will be part of a single-vendor SASE Platform offering, up from 25% in 2025.
2025 SASE Gartner Magic Quadrant
This is something we need to keep in mind when recommending providers because one SASE solution may be a great fit for one company and not another. For example, the platform I recommend a large enterprise with all remote users would look very different from the platform I recommend a restaurant franchise with a few employees at a time and a concern about keeping their POS system up and running.
Because of these nuances, I always recommend talking to a Trusted Advisor or an agnostic subject matter expert (like me!) about which features are going to be most beneficial and which platforms are going to be the best fit in your specific environment.
Different Types of SASE Providers
There are a couple different types of SASE providers that we should talk about:
Unified Platforms
All-in-one providers are those solution providers who are doing everything in-house. They own the SD-WAN portion, they own the security portion, and everything integrates seamlessly together. With this type of setup, the end client would have a unified portal to log into to make policy changes for both network and security.
An example of a provider in this bucket is Cato Networks. Cato was Gartner’s SASE pioneer. They were the example that Gartner used in order to outline what SASE is and what it will be moving forward. Cato’s POP-based SD-WAN solution paired with their cloud-based next-generation firewall and other security services make them a front-runner for many SASE opportunities.
Best-of-Breed Providers
Best-of-Breed SASE vendors combine separate SD-WAN and security platforms into a single SASE solution. Oftentimes, this is a gateway or POP-based SD-WAN solution (e.g., VeloCloud SD-WAN) paired with a cloud-based security platform (e.g., Zscaler, Checkpoint, etc). This will usually result in two management portals, but for companies that have siloed networking and security teams, this isn’t necessarily a drawback.
An example of a combination provider is GTT. While they do have a unified platform option (Palo Alto Prisma), they can also combine Palo Alto’s network security with VeloCloud SD-WAN or HPE Aruba SD-WAN. Many managed service providers like this offer a myriad of options to fit most scenarios their clients will bring to them.
By 2028, 50% of new SASE deployments will be based on a single-vendor SASE Platform offering, up from 30% in 2025.
2025 SASE Gartner Magic Quadrant
Types of Companies that Need SASE
Since SASE is the convergence of network and security, the most obvious type of company that should be considering SASE is one that is in need of a security refresh as well as an improved network. For example, if your firewalls are outdated or clunky to manage and your end users are complaining about internet connectivity speeds and connecting to mission-critical applications, SASE may be the answer to your problems.
Alternatively, if you just recently invested in network security or a new SD-WAN platform, there’s no need to forklift everything in favor of SASE. Most SASE providers allow their clients to only use the SD-WAN portion, or only use the security portion if that’s all they need. Keeping the two platforms separate is an option for transition phase until it makes sense to deploy a full SASE solution.
Additional use cases that make sense for SASE:
- Companies with work-from-home or remote users (ZTNA/VPN is part of SASE)
- Companies that are accessing public cloud services or SaaS-based applications (SD-WAN, CASB, and FWaaS are included with SASE)
- Companies that are tired of having multiple vendors finger point to each other when something goes wrong. With SASE, security and network edge functions are all from a single provider.
I hope this article has started to demystify the term SASE and gave you a sense of whether or not you should be considering this technology convergence for your company. As a next step, I’d suggest gaining a better understanding of the features of SASE to determine which ones should be required for your organization.