FAQ
SASE & SSE
Frequently asked questions about SASE and SSE.
SASE stands for 'Secure Access Service Edge'. It's a term originally coined by Gartner to describe a cloud-based, unified approach to networking and cyber security. SASE is neither a product, nor a service - it defines a delivery framework from which a number of core connectivity and security services are offered.
A SASE approach can be adopted by any organisation that wants to simplify their network, and secure it. We work with both the Private and Public Sectors, from Health, Central and Local Government, Police, Finance, and more. Check out some of our case studies in our knowledge centre.
Unlike pure-play SASE vendors that focus solely on software, Cloud Gateway combines SASE capabilities with a unified platform approach and flexible delivery models. We provide the full SASE portfolio (Connect, Protect, Observe) through a single control plane, but critically, we offer both fully managed and co-managed options. This means enterprises get enterprise-grade SASE without needing to build internal expertise immediately. Our UK-sovereign infrastructure and 24x7 UK-based NOC provide local support and data residency that global SASE providers often can't match.
SSE stands for 'Secure Service Edge'. It's a subset of SASE which focuses on the framework for security service delivery. SSE focusses on a unified approach to deploying a range of cloud-native security tools throughout the business.
Network-as-a-Service (NaaS) is a delivery model for connectivity and security functions. It is a future vision for completely self-serve, DIY network provision and management. Today, we deliver connectivity and security services through a managed service model. As our platform matures, we'll introduce self-service and automation capabilities that align with true NaaS principles.
SD-WAN is a core component of SASE, and is largely responsible for delivering the 'Access' part of 'Secure Access Service Edge'. SD-WAN (Software Defined Wide Area Network) is a technology that uses software to manage and optimise connectivity across multiple locations. Unlike traditional WAN infrastructure, SD-WAN provides centralised control, improved performance, and enhanced security through intelligent traffic routing. Learn more here
FWaaS is a core component of a SSE offering, which provides advanced security through configurable firewall and UTM (Unified Threat Management) capabilities to manage and control traffic passing through the platform.
Secure Web Gateway is another core capability as part of a SASE portfolio. It provides centralised, controlled access to the internet. Secure Web Gateway includes:
URL Filtering
DNS Inspection
Application Control
Proxy Services
Deep Packet Inspection (DPI)
FAQ
Cloud Gateway
Frequently asked questions about Cloud Gateway and the solutions we deliver.
Traditional MSPs typically resell and manage disparate vendor solutions with limited integration. Cloud Gateway operates a unified, cloud-native platform with a single control plane that abstracts vendor complexity and standardises policy across all services. While MSPs often rely on manual processes and ticket-based operations, our platform is automation-first with API-driven provisioning, enabling deployment in minutes rather than weeks.
Our unified control plane means all services - whether connectivity, security, or observability - are managed through a single interface with consistent policies and workflows. You don't need separate consoles for firewall management, SD-WAN configuration, and security policies. Real-time telemetry and automated workflows operate across all services, and our platform abstracts vendor complexity so you work with standardised policies regardless of underlying technology.
It's up to you. We provide a fully managed service where provisioning, support and service changes are managed on your behalf. Alternatively our portal is equipped with features that allow you to manage elements of the service yourself.
Our platform is almost entirely cloud-native. We like to remain flexible, so we have developed the platform in such a way that it can be deployed on physical or virtual infrastructure. There may also be some physical network components to and from your private network, the internet and to cloud. A blend of cloud and physical infrastructure allows us to leverage the benefits of cloud such as elasticity, auto-scaling and improved resilience, but also maximise availability to deliver the correctly sized platform at the moment you need it.
We select best-of-breed vendor technologies that may vary depending on the exact use case or customer architecture. We are capable of using devices from some of the most recognisable names in the industry.
We work closely with cyber security partners and have relationships with the National Cyber Security Centre (NCSC), to ensure we are always improving the security of our own infrastructure. The security services we provide are constantly updating dynamically in accordance with the latest emerging threats. We are ISO 27001 certified, and hold Cyber Essentials Plus certificates. Additionally, our architecture is audited by NHS Digital and The Government Digital Service (GDS) as part of our HSCN and PSN connectivity offerings.
Via our cloud on-ramp we can connect to hundreds of CSPs. This includes major providers like Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP) and Oracle.
Yes, our platform is designed to connect users, sites, devices, data centers, and multiple cloud environments through a single control plane. Our SASE architecture inherently supports distributed, hybrid infrastructures, allowing consistent security policies whether users are in the office, at home, or accessing cloud applications.
Yes. As part of the service you'll receive logins to the Cloud Gateway Portal. The portal gives you an orchestrated window into the traffic and security logs generated by our SASE Platform.
It contains:
Connectivity and Security Dashboards
Licence utilisation data and bandwidth usage
Firewall policy information
Support / ticket management
Our platform enables rapid service provisioning through policy-driven, Infrastructure-as-Code automation. Services can be deployed and updated in days rather than the months-long cycles typical of traditional approaches. The exact timeline depends on the complexity of your requirements, but our automated approach significantly reduces deployment friction compared to legacy MSP solutions.
Yes, that's exactly how most customers begin. Start with your most pressing need - perhaps Secure Web Gateway or SD-WAN. Additional services integrate seamlessly through our unified platform, inheriting your existing policies automatically. No penalties for starting small, and you get the same unified control plane experience whether you have one service or our entire portfolio.
We deploy alongside your existing infrastructure - no "rip and replace" required. Start with parallel running, then gradually migrate services at your pace. Our automated platform deploys in minutes, not weeks, while our 24x7 UK NOC handles the technical complexity. Your current services stay running throughout, with our unified control plane integrating with your existing tools via APIs and SIEM/SOC connections.
Yes, our platform exports real-time security logs that integrate with existing SIEM and SOC tools, enabling continuous monitoring and rapid analysis. This allows you to maintain your current security operations workflow while benefiting from our unified platform capabilities.
Got a question for us?
If you haven't found the answer to your question. Get in touch we'd be delighted to help.