SASE explained: what Secure Access Service Edge is, how it works, and why UK regulated organisations are adopting it. Includes sovereign SASE, the SASE vs SSE distinction, and what genuine convergence actually looks like in practice.
Secure Access Service Edge (SASE) is a cloud-native architecture that converges network connectivity with security services into a single, unified platform. Rather than managing separate point solutions for WAN connectivity, firewalls, web gateways, and access control, SASE delivers all of these through one integrated service.
Gartner first defined SASE in 2019, recognising that traditional hub-and-spoke network models no longer fit how organisations work. With users accessing cloud applications from anywhere and data spread across multiple environments, the perimeter-based security model had become structurally inadequate. SASE addresses this by delivering security and connectivity together, from the cloud, closer to where users and applications actually are.
SASE stands for Secure Access Service Edge. It is pronounced “sassy.” The name reflects the architecture’s intent: secure access, delivered at the service edge rather than from a central data centre.
SASE operates on a fundamentally different principle from legacy network architectures. Rather than routing traffic through a central data centre for inspection, SASE delivers security services from cloud-based points of presence positioned close to users and applications.
When a user accesses an application, whether from headquarters, a remote location, or a branch site, their traffic routes to the nearest SASE point of presence. At that edge location, the platform inspects the traffic, applies security policies, and validates identity and device posture before granting access.
This eliminates unnecessary backhauling. A remote clinician accessing a cloud-hosted patient management system does not send traffic via a hospital data centre and back out again. SASE creates a direct, secure path from user to application.
The architecture combines SD-WAN for intelligent traffic routing with cloud-delivered security services, known collectively as the Security Service Edge (SSE). Because SASE is cloud-delivered, it scales without deploying physical hardware at each location.
A complete SASE architecture integrates five essential capabilities. The four security components (CASB, ZTNA, FWaaS, and SWG) collectively form the Security Service Edge (SSE). SASE combines SD-WAN with SSE, unifying network and security functions into one cloud-delivered framework.
SD-WAN provides the connectivity layer, creating a managed overlay network that intelligently routes traffic across multiple circuit types, including broadband, cellular, MPLS, and satellite, based on performance, cost, and security requirements. It allows organisations to move away from expensive, inflexible MPLS contracts while maintaining network performance and resilience.
A Secure Web Gateway protects users from web-based threats by inspecting internet traffic, blocking malicious destinations, enforcing acceptable use policies, and preventing data exfiltration. SWG applies these controls wherever the user is, rather than only when they are on the corporate network.
CASB extends security controls to SaaS applications and cloud services. It provides visibility into cloud application usage, enforces data loss prevention policies, detects threats, and ensures compliance across platforms such as Microsoft 365 and Google Workspace.
FWaaS delivers firewall capabilities from the cloud, including deep packet inspection, intrusion prevention, and advanced threat detection. Unlike physical appliances, FWaaS provides consistent protection that travels with users regardless of location.
ZTNA enforces the principle of continuous verification. Rather than placing users on the network after a single VPN authentication, ZTNA creates secure, direct connections between verified users and specific applications based on ongoing validation of identity and device posture. It is the modern replacement for legacy remote access VPN.
These two terms are often used interchangeably, and the distinction matters.
SSE (Security Service Edge) is the security half of SASE: secure web gateway, ZTNA, CASB, and firewall as a service, delivered as cloud-native services. SSE protects users and applications without requiring traffic to route through on-premise appliances.
SASE is the complete architecture. It includes SSE plus the network connectivity layer, typically SD-WAN, that handles how traffic moves across the estate. SASE brings both halves together under one architecture and, in a well-delivered implementation, under one operating model.
The distinction matters because many providers sell SSE products and call the result SASE. The network layer is either absent, delivered separately, or managed through a different contract. That is SSE rebranded, not genuine SASE convergence.
The SASE market has a labelling problem. The category now covers two very different things, and understanding the difference is important when evaluating providers.
A SASE bundle is a collection of existing products packaged together and sold as a platform. The underlying products still have separate architectures, separate management interfaces, and separate operational models. The vendor has put them in a box together, but the customer still manages the seams between them.
A SASE platform is architecturally converged. Connectivity and security share a common control plane, a common data layer, and a common operational model. Policy changes in one layer propagate consistently across the others. Telemetry from the network informs the security posture. Evidence of change and compliance is generated from one place.
The practical consequences are significant. A SASE bundle means customers inherit the complexity the vendor is claiming to remove. Multiple dashboards, separate change processes, separate evidence trails for auditors. A genuine platform means one operating model, one view, one point of accountability.
For regulated organisations that have to evidence their controls continuously, rather than assemble evidence before an audit, the difference between a bundle and a platform is the difference between operational confidence and operational overhead.
The shift toward SASE is a response to genuine changes in how organisations operate, not a technology trend.
Cloud adoption has changed traffic patterns. NHS trusts run electronic patient record systems in cloud environments. Local authorities deliver citizen services through SaaS platforms. The majority of traffic now flows to cloud destinations rather than internal data centres, making traditional architectures inefficient and expensive to maintain.
Hybrid working is structural. Clinical staff access systems from hospitals, community sites, and home. Officers access policing systems from mobile data terminals and third-party sites. Security and performance need to be consistent regardless of where people connect from.
Compliance requirements have intensified. NHS organisations must evidence their controls against CAF and DSPT. Public sector bodies face PSN Code of Connection obligations. Policing operates against its own information assurance standards. Managing compliance across fragmented point solutions creates evidence gaps and increases risk.
The threat landscape has evolved. Cyber attacks targeting healthcare and public sector organisations continue to grow in sophistication. Ransomware, supply chain attacks, and credential-based access attempts require layered, adaptive defence rather than perimeter controls.
IT teams are stretched. Managing multiple vendors, coordinating upgrades, and integrating separate systems consumes capacity that could be spent on higher-value work.
Sovereign SASE refers to a SASE architecture designed to meet specific data sovereignty, regulatory, and national security requirements. For UK regulated organisations, this is not a nice-to-have.
NHS patient data, citizen information, and law enforcement data must be processed and stored within the UK. Standard global SASE platforms that route traffic through international points of presence create data residency risks and can conflict with the governance requirements of regulated networks like HSCN and PSN.
Sovereign SASE addresses this through UK-based infrastructure, UK-based network operations, and a supply chain that provides the transparency and provenance that regulated buyers need. It is not a global platform adapted for UK use. It is built for UK regulated requirements from the outset.
SASE continues to develop as both the technology and the threat landscape evolve. AI-assisted operations are beginning to appear in observability and threat detection layers. Integration with ITSM, SIEM, and identity platforms is becoming an expectation rather than a differentiator. For UK regulated organisations, the emphasis on sovereign infrastructure and continuous compliance evidence is intensifying, driven by frameworks including CAF, NIS2, and DORA.
The organisations best positioned are those that have built on a genuine platform rather than a bundle of products. When the architecture changes, they adapt one operating model. When new compliance requirements surface, the evidence is already there.
Cloud Gateway delivers SASE capabilities through its secure connectivity platform. It is built to support mission-critical services, with native connectivity to HSCN and PSN, evidence generation aligned to UK assurance frameworks, and a single UK team operating the platform end to end. For more on how the platform works, see our platform page.