What is SASE? A complete guide to Secure Access Service Edge

SASE explained: what Secure Access Service Edge is, how it works, and why UK regulated organisations are adopting it. Includes sovereign SASE, the SASE vs SSE distinction, and what genuine convergence actually looks like in practice.

What is SASE?

Secure Access Service Edge (SASE) is a cloud-native architecture that converges network connectivity with security services into a single, unified platform. Rather than managing separate point solutions for WAN connectivity, firewalls, web gateways, and access control, SASE delivers all of these through one integrated service.

Gartner first defined SASE in 2019, recognising that traditional hub-and-spoke network models no longer fit how organisations work. With users accessing cloud applications from anywhere and data spread across multiple environments, the perimeter-based security model had become structurally inadequate. SASE addresses this by delivering security and connectivity together, from the cloud, closer to where users and applications actually are.

What does SASE stand for?

SASE stands for Secure Access Service Edge. It is pronounced “sassy.” The name reflects the architecture’s intent: secure access, delivered at the service edge rather than from a central data centre.

How does SASE work?

SASE operates on a fundamentally different principle from legacy network architectures. Rather than routing traffic through a central data centre for inspection, SASE delivers security services from cloud-based points of presence positioned close to users and applications.

When a user accesses an application, whether from headquarters, a remote location, or a branch site, their traffic routes to the nearest SASE point of presence. At that edge location, the platform inspects the traffic, applies security policies, and validates identity and device posture before granting access.

This eliminates unnecessary backhauling. A remote clinician accessing a cloud-hosted patient management system does not send traffic via a hospital data centre and back out again. SASE creates a direct, secure path from user to application.

The architecture combines SD-WAN for intelligent traffic routing with cloud-delivered security services, known collectively as the Security Service Edge (SSE). Because SASE is cloud-delivered, it scales without deploying physical hardware at each location.

The five core components of SASE

A complete SASE architecture integrates five essential capabilities. The four security components (CASB, ZTNA, FWaaS, and SWG) collectively form the Security Service Edge (SSE). SASE combines SD-WAN with SSE, unifying network and security functions into one cloud-delivered framework.

Software-defined WAN (SD-WAN)

SD-WAN provides the connectivity layer, creating a managed overlay network that intelligently routes traffic across multiple circuit types, including broadband, cellular, MPLS, and satellite, based on performance, cost, and security requirements. It allows organisations to move away from expensive, inflexible MPLS contracts while maintaining network performance and resilience.

Secure Web Gateway (SWG)

A Secure Web Gateway protects users from web-based threats by inspecting internet traffic, blocking malicious destinations, enforcing acceptable use policies, and preventing data exfiltration. SWG applies these controls wherever the user is, rather than only when they are on the corporate network.

Cloud Access Security Broker (CASB)

CASB extends security controls to SaaS applications and cloud services. It provides visibility into cloud application usage, enforces data loss prevention policies, detects threats, and ensures compliance across platforms such as Microsoft 365 and Google Workspace.

Firewall as a Service (FWaaS)

FWaaS delivers firewall capabilities from the cloud, including deep packet inspection, intrusion prevention, and advanced threat detection. Unlike physical appliances, FWaaS provides consistent protection that travels with users regardless of location.

Zero Trust Network Access (ZTNA)

ZTNA enforces the principle of continuous verification. Rather than placing users on the network after a single VPN authentication, ZTNA creates secure, direct connections between verified users and specific applications based on ongoing validation of identity and device posture. It is the modern replacement for legacy remote access VPN.

SASE vs SSE: what is the difference?

These two terms are often used interchangeably, and the distinction matters.

SSE (Security Service Edge) is the security half of SASE: secure web gateway, ZTNA, CASB, and firewall as a service, delivered as cloud-native services. SSE protects users and applications without requiring traffic to route through on-premise appliances.

SASE is the complete architecture. It includes SSE plus the network connectivity layer, typically SD-WAN, that handles how traffic moves across the estate. SASE brings both halves together under one architecture and, in a well-delivered implementation, under one operating model.

The distinction matters because many providers sell SSE products and call the result SASE. The network layer is either absent, delivered separately, or managed through a different contract. That is SSE rebranded, not genuine SASE convergence.

SASE platform vs SASE bundle: why this distinction matters

The SASE market has a labelling problem. The category now covers two very different things, and understanding the difference is important when evaluating providers.

A SASE bundle is a collection of existing products packaged together and sold as a platform. The underlying products still have separate architectures, separate management interfaces, and separate operational models. The vendor has put them in a box together, but the customer still manages the seams between them.

A SASE platform is architecturally converged. Connectivity and security share a common control plane, a common data layer, and a common operational model. Policy changes in one layer propagate consistently across the others. Telemetry from the network informs the security posture. Evidence of change and compliance is generated from one place.

The practical consequences are significant. A SASE bundle means customers inherit the complexity the vendor is claiming to remove. Multiple dashboards, separate change processes, separate evidence trails for auditors. A genuine platform means one operating model, one view, one point of accountability.

For regulated organisations that have to evidence their controls continuously, rather than assemble evidence before an audit, the difference between a bundle and a platform is the difference between operational confidence and operational overhead.

Why regulated organisations need SASE

The shift toward SASE is a response to genuine changes in how organisations operate, not a technology trend.

Cloud adoption has changed traffic patterns. NHS trusts run electronic patient record systems in cloud environments. Local authorities deliver citizen services through SaaS platforms. The majority of traffic now flows to cloud destinations rather than internal data centres, making traditional architectures inefficient and expensive to maintain.

Hybrid working is structural. Clinical staff access systems from hospitals, community sites, and home. Officers access policing systems from mobile data terminals and third-party sites. Security and performance need to be consistent regardless of where people connect from.

Compliance requirements have intensified. NHS organisations must evidence their controls against CAF and DSPT. Public sector bodies face PSN Code of Connection obligations. Policing operates against its own information assurance standards. Managing compliance across fragmented point solutions creates evidence gaps and increases risk.

The threat landscape has evolved. Cyber attacks targeting healthcare and public sector organisations continue to grow in sophistication. Ransomware, supply chain attacks, and credential-based access attempts require layered, adaptive defence rather than perimeter controls.

IT teams are stretched. Managing multiple vendors, coordinating upgrades, and integrating separate systems consumes capacity that could be spent on higher-value work.

What is sovereign SASE?

Sovereign SASE refers to a SASE architecture designed to meet specific data sovereignty, regulatory, and national security requirements. For UK regulated organisations, this is not a nice-to-have.

NHS patient data, citizen information, and law enforcement data must be processed and stored within the UK. Standard global SASE platforms that route traffic through international points of presence create data residency risks and can conflict with the governance requirements of regulated networks like HSCN and PSN.

Sovereign SASE addresses this through UK-based infrastructure, UK-based network operations, and a supply chain that provides the transparency and provenance that regulated buyers need. It is not a global platform adapted for UK use. It is built for UK regulated requirements from the outset.

Key benefits of SASE for regulated organisations

  • Simplified operations. A single platform for connectivity, security, access control, and monitoring replaces the complexity of managing multiple vendor relationships and separate operational models.
  • Consistent security posture. Integrated security functions share context and policy, closing the gaps that emerge when networking and security operate in silos. Every access request is validated against the same controls regardless of where the user is.
  • Improved application performance. Processing traffic at the edge rather than backhauling it through a central location reduces latency and improves the experience for users accessing cloud applications.
  • Audit-ready evidence. Compliance evidence, change records, policy enforcement logs, and SLA delivery data are generated as a by-product of the service rather than assembled retrospectively before an assessment cycle.
  • Cost predictability. Replacing hardware refresh cycles and per-site appliance costs with a cloud-delivered managed service changes the cost model and reduces the unpredictability that comes with owned infrastructure.

SASE in practice: worked examples

  • Connecting distributed NHS sites. A hospital trust with multiple sites uses SASE to create secure, high-performance connectivity across the estate. HSCN connectivity is built in, ensuring compliance without managing individual connection arrangements per site. Security policy is applied consistently from the same platform that manages the network.
  • Securing a hybrid workforce in local government. A county council supports staff working from home, hot-desking in council offices, and visiting residents on-site. SASE provides consistent inspection and access control across all user locations, without VPN performance constraints or separate management for remote users.
  • Modernising a police force WAN estate. A force consolidating a multi-site estate moves from legacy MPLS to managed SD-WAN, with the security layer applied consistently across all sites and to officers accessing systems from mobile data terminals and third-party locations. Compliance evidence is generated automatically as the service runs.
  • Supporting a healthcare technology provider. A healthtech company delivering a cloud-hosted clinical application to NHS customers uses SASE to connect their cloud environment to HSCN, apply managed security at the boundary, and produce the supplier assurance evidence their NHS customers require.

What to consider when evaluating SASE

  • Assess your current architecture first. Document your existing network topology, security tools, and traffic patterns before defining requirements. The gaps in the current estate should drive the specification, not the other way round.
  • Define compliance requirements clearly. Which frameworks apply to your organisation? What evidence do assessors expect? SASE implementations that are not designed around these requirements from the outset will create problems at audit time.
  • Distinguish platform from bundle. Ask providers to explain how their connectivity and security layers share a control plane, what the operational model looks like in practice, and how compliance evidence is generated. Vague answers indicate a bundle.
  • Consider the operating model. Fully managed, co-managed, or self-service capabilities each suit different organisational contexts. The right SASE platform supports all three without a different underlying product for each.
  • Plan phased adoption. Most organisations begin with one problem: a network modernisation, an expiring HSCN connection, a security audit finding that needs closing. The platform that solves the first problem should be the same one that solves the next, without rebuilding the architecture.

Common misconceptions about SASE

  • “SASE is just SD-WAN with security features added.” SD-WAN is a component of SASE, not the whole thing. SASE represents the convergence of network and security into a unified architecture, not an incremental add-on to an existing WAN solution.
  • “Only large organisations need SASE.” The cloud-delivery model makes the capabilities accessible regardless of organisation size. A small NHS trust or district council benefits from the same architecture as a large central government department.
  • “SASE means replacing all on-premise infrastructure.” SASE integrates with existing on-premise systems. Hybrid architectures are common during transition, with SASE securing cloud access and remote users while on-premise infrastructure continues to serve local requirements.
  • “SASE means a single vendor for everything.” A genuine SASE platform delivers integrated network and security from one operating model. That operating model may incorporate multiple underlying technologies and partner capabilities, but the customer sees one service, one contract, and one point of accountability.

The direction of travel

SASE continues to develop as both the technology and the threat landscape evolve. AI-assisted operations are beginning to appear in observability and threat detection layers. Integration with ITSM, SIEM, and identity platforms is becoming an expectation rather than a differentiator. For UK regulated organisations, the emphasis on sovereign infrastructure and continuous compliance evidence is intensifying, driven by frameworks including CAF, NIS2, and DORA.

The organisations best positioned are those that have built on a genuine platform rather than a bundle of products. When the architecture changes, they adapt one operating model. When new compliance requirements surface, the evidence is already there.

Cloud Gateway delivers SASE capabilities through its secure connectivity platform. It is built to support mission-critical services, with native connectivity to HSCN and PSN, evidence generation aligned to UK assurance frameworks, and a single UK team operating the platform end to end. For more on how the platform works, see our platform page.

Related Articles

Want to know more about how we work?