Skip to main content

Secure Access Service Edge SASE

Optimised networks and security for all applications, users and locations – on a single, central platform.

What is SASE?

The acronym SASE stands for “Secure Access Service Edge” and refers to a cloud-based solution that combines network and security functions in a single integrated service. It combines SD-WAN (Software-Defined Wide Area Network) with SSE (Secure Service Edge) functions such as secure web gateway, Zero Trust Network Access (ZTNA), Firewall as a Service, Cloud Access Security Broker (CASB) and more.

What advantages does SASE offer?

The aim of SASE solutions is to ensure secure connectivity while reducing the complexity of security applications.


Reduced complexity

Combining security functions, for which a number of individual products from different manufacturers are traditionally used, with a single integrated and cloud-based solution significantly reduces complexity. This can massively reduce operating costs.


Increased security

With the increasing use of cloud services and remote employees, the attack surface has grown. SASE offers a comprehensive security solution designed to support and secure these scenarios. This protects data and applications from threats and unauthorised access, while functions such as ZTNA also secure remote access to company resources.


Bessere Performance

Traditional network architectures can be overloaded by increasing data traffic and the use of cloud services. SASE optimises network performance through the use of SD-WAN and the provision of security functions at the edge.

The functional principle of SASE

SASE functional principle diagram
SSE and SD-WAN

SASE combines network and security-as-a-service functions in one cloud platform. By consolidating these functions, companies can greatly simplify their security architecture while improving the security and performance of their networks. Expensive MPLS solutions can also be replaced.

    What are the components of SASE?

    SSE – Secure Service Edge as a Service

    Enables organisations to apply end-to-end security from the cloud and ensure access to applications distributed across multiple clouds, data centres and software-as-a-service applications.

    SSE extends security services to the edge of the network, closer to the user and device. This proximity improves performance, reduces latency and improves the overall user experience while ensuring security at the point of access.

    An SSE solution, when combined with an advanced SD-WAN, creates a SASE architecture that significantly improves the quality of experience for end users of applications hosted in the cloud.

    The following security aspects are typically integrated into an SSE solution:

    • Zero Trust Network Access (ZTNA)
    • Secure Web Gateway
    • Secure Mail Gateway
    • Firewall as a Service
    • Data Loss Prevention (DLP)
    • Cloud Access Security Broker (CASB)
    • Remote Browser Isolation
    • Extended Detection and Response (XDR)
    Secure SD-WAN as a Service

    SD-WAN stands for Software Defined Wide Area Network. It is a technology that simplifies network management and operation by using software to control and manage WAN connections. Essentially, SD-WAN separates the control plane from the data traffic and enables centralised management and configuration of WAN resources.

    Most enterprise networks utilise legacy carrier services such as managed MPLS, which are expensive and take weeks or months to set up. Even small changes by the service provider are often associated with long waiting times.

    SD-WAN technology offers a solution here by enabling flexibility and cost efficiency for IT networks. It connects locations via multiple internet connections and bundles them in an encrypted overlay. Guidelines, application-oriented routing and dynamic connection evaluation optimise the use of existing Internet connections.

    In addition, one of our SASE partners offers a last-mile service. The monitoring and management service for the last mile is operated from a Network Operation Centre (NOC) set up specifically for this purpose. The service monitors the SASE sockets and offers
    Real-time detection of connection failures or degradations, proactive opening of tickets with the ISP and follow-up until the connection service is restored.

    May we personally provide you with arguments in favour of ensec? Please contact us.

    Or give us a call:

    +41 44 711 11 44