Skip to content

SASE: Cloud-Based Network and Security Architecture for Decentralized Infrastructures

Bottom line: SASE replaces the centralized hub-and-spoke model with decentralized, cloud-based security and SD-WAN routing to address latency and compliance challenges in hybrid cloud infrastructures.

Secure Access Service Edge (SASE) is an architectural model that combines software-defined networking functions with cloud-native security services. It was coined by Gartner in 2019 and addresses the shortcomings of traditional hub-and-spoke models in cloud and hybrid work environments.

The classic hub-and-spoke model of enterprise IT, in which all data traffic had to flow through a central data center, has become obsolete with the proliferation of cloud services (SaaS, IaaS) and hybrid work. When employees directly access Microsoft 365, Salesforce, or AWS from home, the forced routing through corporate infrastructure creates significant latency problems and congests expensive links — a phenomenon known as backhauling or hairpinning.

SASE solves this conflict by shifting security and network functions directly to the logical edge closest to the end user. The approach rests on two pillars: the networking component SD-WAN (Software-Defined Wide Area Network), which abstracts physical links and intelligently routes data traffic at the software level, and the security component SSE (Security Service Edge), which provides cloud-native security services. Data traffic is routed directly from the user’s device to the nearest Point of Presence (PoP) of the SASE provider, checked there, and then forwarded to its destination.

Implications relevant to CISOs arise from the centralized security architecture in the cloud: with SASE, security policies can be enforced in a policy-based and context-dependent manner, regardless of where the user or device is located. This improves compliance conformity under NIS2 and IT Baseline Protection standards through unified, cloud-centric logging and monitoring capabilities.

Decision-makers must weigh single-vendor versus multi-vendor approaches. Single-vendor SASE (from providers such as Zscaler or Palo Alto Networks) reduces integration complexity, while multi-vendor approaches offer more flexibility but entail higher operational complexity. At the same time, the cost model shifts from capex (hardware investments) to opex (cloud subscriptions), enabling consolidation of network and security agents.


Source: www.it-daily.net · Published 31 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: