{"id":52966,"date":"2022-12-06T09:52:51","date_gmt":"2022-12-06T01:52:51","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=52966"},"modified":"2022-12-06T09:52:53","modified_gmt":"2022-12-06T01:52:53","slug":"is-the-future-of-sd-wan-and-sase-in-managed-services","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2022\/12\/06\/is-the-future-of-sd-wan-and-sase-in-managed-services\/","title":{"rendered":"Is the future of SD-WAN and SASE in managed services?"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><em>By Guy Matthews<br>Editor, NetReporter<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Security provisions for data and applications relied for decades on the same sort of architecture. The typical model was based around a hub and spoke structure, and was heavily hardware-centric. It was also supported by private MPLS circuits to connect everything together. We\u2019re talking about a world of centralized applications living inside the corporate perimeter with only modest volumes of outbound Internet traffic and a time when remote working was the exception not the rule.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Mauricio Sanchez, Research Director, Network Security, SASE &amp; SD-WAN with analyst firm the Dell\u2019Oro Group, says this cosy scenario was ripped up in 2020 when COVID struck. Now post pandemic, we\u2019re into a world of hybrid work with employee time split between the office and any number of other possible end points. The security implications are huge, he notes: \u201cThe cost of the average corporate data breach is now over $4 million,\u201d he says. \u201cThat&#8217;s a significant amount, and that&#8217;s just the average. Some breaches are at a much higher level.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sanchez cites a recent McKinsey Report indicating that 58% of US employees are now hybrid workers, 10 times the figure from before the pandemic: \u201cThis is the new normal and here to stay,\u201d he says. \u201cFor all these reasons, the legacy network fell flat during the pandemic. In any case, old MPLS circuits are no longer enough once cloud applications become the norm. The amount of traffic piped between points in the network has become much greater, with more money needing to be spent in order to upgrade to faster legacy pipes. The security stack has become a choke point on the perimeter. The hardware-centric view just doesn\u2019t work as well as it did in the past. Plus we now have a poor app experience among users.\u201d<br>This background, he believes, is what\u2019s been setting the stage for a conversation around Secure Access Service Edge, or SASE: \u201cOn the one hand you have SD-WAN, and the promise of being able to reduce the operational costs of the network, and on the other you&#8217;ve got a new breed of cloud-delivered security solutions in the form of SASE,\u201d he explains. \u201cWe&#8217;ve seen these two being combined over the last couple of years to drive a new topology. They&#8217;re coming together in service of the hybrid, cloud-centric enterprise.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Figure 1: Enterprise SASE spend<\/em><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech1-1.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"864\" height=\"486\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech1-1.jpg\" alt=\"\" class=\"wp-image-52970\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech1-1.jpg 864w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech1-1-300x169.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech1-1-768x432.jpg 768w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech1-1-600x337.jpg 600w\" sizes=\"auto, (max-width: 864px) 100vw, 864px\" \/><\/a><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Sanchez says Dell\u2019Oro has measured a sizable increase in the amount that enterprises have been spending on SASE: \u201cWe&#8217;re on track to hit that $6 billion figure by the end of this year,\u201d he notes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To find out more about what SD-WAN and SASE really mean for enterprises, Sanchez taps into a panel of expert stakeholders, starting with Craig Connors, VP &amp; GM of VMWare\u2019s SASE Business: \u201cA lot of people forget that the SASE term was actually coined prior to the pandemic,\u201d he points out. \u201cThe shifts we\u2019ve talked about were happening already.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In addition to the obvious SASE driver of remote work, Connors also mentions rising levels of IoT devices, and all the applications that are moving to the edge into various clouds. Then there\u2019s the matter, he says, of rising cyber-attacks in part driven by cryptocurrency and the new ways it offers to monetize illegal activity: \u201cWe were already rethinking how to connect and secure these new emerging use cases,\u201d he says. \u201cBut it\u2019s hard to pin down exactly what SASE is because so many different vendors claim so many different things. So the priority is to go back to the use cases and look at what you&#8217;re trying to accomplish.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Parag Thakore, Senior Vice President with security platform Netskope, notes that with SD-WAN, as much as with SASE, enterprises want a consistent, uniform performance combined with security, not just to branch offices but to every user device, IoT endpoint or multi-cloud environment. \u201cPeople are talking about being application aware and context aware,\u201d he says.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Marc Cohn is Leader of the Security Test &amp; Certification Incubation Group with the MEF standards body. He says what MEF is trying to do is recognise SASE as an architecture, catering to the traditional service provider customer base that the organisation serves: \u201cThen we can try to provide a language and a set of standards that can help a service provider manage this multi-vendor environment we face,\u201d he claims. \u201cThat&#8217;s the role of a SASE standard, and a Zero Trust standard which is the other important companion standard to SASE that we&#8217;re addressing in the MEF.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Central to the SD-WAN and SASE conversation is the choice between dealing with a complicated multi-vendor marketplace for solutions versus opting to outsource to a managed service provider. Thakore says that Netskope always wants, by instinct, to offer customers flexibility and choice: \u201cSuccessful SASE would imply fewer vendors, simpler operations, reduced complexity, all as part of lower costs,\u201d he argues. \u201cBut we understand that it is a journey, not a matter of \u2018rip and replace\u2019.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Options, he says, include the purchase of many individual products that are part of the SASE architecture, requiring tight and deep partnerships and integrations with many security and networking players: \u201cOn the other side, some want simplified operations and the need to connect remote users IoT devices, branch offices, multi cloud environments, all in a single fabric,\u201d he says. \u201cIn that case, you can purchase an entire converged SASE platform. Both options should be supported. I think flexibility and choice are the key.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cohn of MEF believes the longer-term trend is a move away from reliance on just a single vendor: \u201cI think we&#8217;re all going to move to multiple vendors and those multiple vendors are going to provide a richer and broader set of cybersecurity functions and applications that are going to be delivered in the SASE environment,\u201d he claims. \u201cBut as Parag says, there&#8217;s no one size fits all. Let\u2019s acknowledge that there&#8217;s a need for vendor provided solutions as well as managed services. That&#8217;s why we&#8217;re seeing demand along those lines.\u201d <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Figure 2: SASE consumption trends<\/em><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech2-1.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"864\" height=\"486\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech2-1.jpg\" alt=\"\" class=\"wp-image-52971\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech2-1.jpg 864w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech2-1-300x169.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech2-1-768x432.jpg 768w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2022\/12\/tech2-1-600x337.jpg 600w\" sizes=\"auto, (max-width: 864px) 100vw, 864px\" \/><\/a><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Cohn sees a couple of factors that might hinder adoption of managed SASE services: \u201cOne of them is that the network and security organizations within many enterprises is traditionally two distinct organizations,\u201d he observes. \u201cAnd if you&#8217;re going to create a converged offering, you have to figure out who you&#8217;re going to sell it to. That\u2019s going to change over time, but it won\u2019t happen overnight. The second factor is that if we look at the long-term outsourcing trend, there is a propensity to look at cloud services.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Connors of VMware knows of scenarios where network engineers prefer one vendor and security engineers prefer another: \u201cThat just underscores another shift that is happening, and has to happen, which is that networking and security are converging,\u201d he points out. \u201cThat\u2019s not just about the products we offer, but the people building these solutions on the ground. I think there will be a lot of areas where managed services can help as SASE emerges.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thakore of Netskope references a recent survey the company carried out among 3,500 CIOs indicating that two thirds think that SASE will change how they structure their teams in future. \u201cIf you have separate groups for security and networking, who has budget control?\u201d he queries. \u201cCIOs are in the process of figuring out how they will all structure this. Will they do it themselves. Are we talking independent decisions or ones made together?\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Last word to Connors of VMware: \u201cAs customers are converging networking and security one thing we can do is advise on what the landscape looks like and how to unite two different things that have been siloed for so long, whether it&#8217;s one vendor or multi-vendor,\u201d he concludes. \u201cWe need to talk to them about ROI, achieving simplicity and meeting use cases. That&#8217;s where the expertise of managed service can really come in and help.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security provisions for data and applications relied for decades on the same sort of architecture. The typical model was based around a hub and spoke structure, and was heavily hardware-centric. It was also supported by private MPLS circuits to connect everything together.<\/p>\n","protected":false},"author":6,"featured_media":52972,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,26],"tags":[96,2727,1656],"class_list":["post-52966","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-opinions","tag-technology","tag-technology-adaption","tag-technology-investment"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/52966","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=52966"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/52966\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/52972"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=52966"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=52966"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=52966"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}