Security models demystified: zero trust, SASE, and shared responsibility

Zero trust, SASE, shared responsibility, and defence in depth are the frameworks shaping how organisations secure hybrid environments. This guide explains each model, why they are difficult to implement consistently, and how to close the gap between theory and practice.

Security models provide the conceptual foundation for how organisations protect their data, applications, and infrastructure. The gap between understanding these models and implementing them consistently across hybrid, multi-cloud, and legacy environments is where most security programmes struggle.

Organisations typically operate across multiple models simultaneously: applying zero trust principles to user access, adopting SASE for branch connectivity, and managing shared responsibility across AWS, Azure, and on-premises systems, all while maintaining audit trails for compliance frameworks. Without a unified approach to applying these models consistently, the result is security gaps, operational overhead, and compliance problems that compound over time.

This guide covers the four major security models, the common challenges that prevent effective implementation, and the misconceptions that cause organisations to misapply them.

The major security models

Zero trust

Zero trust assumes that threats exist both inside and outside the network perimeter. Every user, device, and connection is treated as unverified until proven otherwise. Access is granted based on continuous verification of identity, device health, and context – not on network location.

Traditional perimeter-based security fails in hybrid environments where users, applications, and data exist across multiple locations and providers. Zero trust provides a framework for securing access regardless of where resources live or where users connect from.

Three principles define the model. First, verify explicitly using all available signals: identity, location, device health, workload classification. Second, apply least privilege access – grant only the minimum permissions required for the task. Third, assume breach and segment networks accordingly, monitoring continuously to contain potential compromises if they occur.

Our zero trust guide covers implementation in detail, including how ZTNA relates to the broader model.

SASE

Secure Access Service Edge (SASE) combines software-defined WAN capabilities with cloud-delivered security services – Secure Web Gateway, Cloud Access Security Broker, Firewall as a Service, and zero trust network access – into a unified platform.

SASE addresses the challenge that organisations no longer have a single, defined perimeter. Users, applications, and data are distributed across branches, remote workers, multiple clouds, and legacy data centres. SASE delivers security that follows users and workloads rather than being anchored to fixed network locations.

The practical benefits are consistent security policy enforcement regardless of where users or applications reside, reduced complexity from consolidating multiple security tools into one platform, and improved performance through cloud-delivered services closer to users. For organisations with multiple sites, remote workers, and cloud migrations underway, SASE principles address a class of problem that traditional approaches cannot.

Our SASE guide covers the architecture in depth, including the distinction between a genuine SASE platform and a bundled product set.

Shared responsibility

The shared responsibility model defines the division of security obligations between cloud providers and their customers. The provider secures the infrastructure – physical security, the hypervisor, and the network infrastructure underneath. Customers secure everything they deploy into the cloud: data, applications, identity management, and access controls.

Misunderstanding shared responsibility causes many cloud security failures. Organisations assume their cloud provider handles security comprehensively, only to discover – often following an incident – that data protection, access management, and application security remain their obligation.

The dividing line is consistent across AWS, Azure, and Google Cloud. Physical security and the virtualisation layer sit with the provider. Data encryption, identity and access management, application security, operating system patching, network traffic controls, and compliance evidence all sit with the customer. The cloud provider gives you the tools; configuring and governing them correctly is your responsibility.

Defence in depth

Defence in depth applies multiple independent layers of security controls throughout an IT environment. If one layer fails, others remain to prevent or limit damage. The layers typically include perimeter controls, network segmentation, endpoint protection, application security, data encryption, and security monitoring.

No single security control is foolproof. Defence in depth ensures that a vulnerability in one area does not compromise the entire environment. For organisations handling sensitive data, the layered approach is also often a compliance expectation, not just a security preference.

In practice this means perimeter controls such as firewalls and DDoS protection, network segmentation and intrusion detection at the network layer, endpoint detection and response, web application firewalls and secure development practices at the application layer, encryption at rest and in transit for data, and multi-factor authentication and privileged access management for identity.

Why consistent implementation is difficult

Understanding security models is one thing. Applying them uniformly across hybrid, multi-cloud, and legacy environments is where most organisations encounter real difficulty.

  • Fragmented visibility. When infrastructure spans on-premises data centres, multiple cloud providers, branch offices, and remote workers, achieving a unified view becomes genuinely hard. AWS flow logs look nothing like Azure Network Watcher data, which differs entirely from on-premises SIEM feeds. Correlating security events across fragmented sources either requires significant manual effort or goes undone. Zero trust requires continuous monitoring of access patterns. SASE depends on real-time traffic analysis. Shared responsibility demands clear audit trails. Without visibility across the full estate, these models remain aspirational.
  • Inconsistent policy enforcement. Traditional security architectures enforce policy at fixed points – typically the perimeter firewall or data centre gateway. In hybrid environments there is no single perimeter. Users accessing resources from home bypass corporate security controls. Applications in AWS communicate with databases in Azure through paths that may not traverse the security stack. SaaS tools are accessed directly from user devices. Policies that work in a data centre become difficult to enforce consistently across cloud and remote access scenarios, creating security gaps and operational inconsistency.
  • Operational complexity and skills gaps. Implementing these models properly requires expertise across networking, security, identity management, and compliance. Managing separate security tools for each environment – cloud-native security groups in AWS, NSGs in Azure, traditional firewalls on-premises, VPNs for remote access – requires constant attention and creates configuration drift. Every additional tool adds licensing cost, training requirements, and integration overhead. Teams become overwhelmed maintaining consistency across fragmented security infrastructure while simultaneously responding to incidents and satisfying compliance audits.
  • Legacy infrastructure and vendor constraints. Many organisations are operating with network infrastructure that was designed before cloud-era security requirements existed. Long contract terms, inflexible architectures, and slow change processes make it difficult to adapt security controls as the environment evolves. When implementing zero trust access for a new cloud application requires months of lead time from a legacy vendor, security architecture cannot keep pace with operational change.

Common misconceptions

  • The cloud provider handles security. Cloud providers secure the infrastructure. Data, applications, and access controls remain the customer’s responsibility. Misconfigured storage, exposed databases, and inadequate access controls are consistently among the most common causes of cloud security incidents – and all of them fall on the customer side of the shared responsibility line.
  • Zero trust means perimeter security is redundant. Zero trust adds continuous verification and least privilege access on top of foundational controls – it does not remove the need for firewalls, DDoS protection, and network segmentation. Both layers work together. Applying zero trust principles does not mean dismantling perimeter defences; it means adding identity-aware verification at every access point while maintaining them.
  • SASE replaces all on-premises security. SASE is powerful for securing cloud and remote access, but most organisations will operate hybrid environments for years. On-premises data centres, legacy applications, and specific compliance requirements mean SASE and traditional security controls will coexist for the foreseeable future. The goal is consistent security posture across both, not the wholesale replacement of one by the other.
  • Compliance equals security. Meeting compliance requirements – ISO 27001, Cyber Essentials Plus, and similar frameworks – demonstrates that baseline controls are in place. Compliance checklists do not guarantee protection against sophisticated threats. Zero trust and defence in depth go further than compliance requirements to address real-world attack patterns. The audit trail that satisfies regulators and the operational security that stops actual threats are both necessary, and they are not the same thing.

Turning models into operational practice

The gap between security theory and security practice closes when three things come together: unified visibility across the full estate, consistent policy enforcement regardless of where traffic originates, and an operating model that does not require security expertise at every point in the infrastructure.

Unified visibility means a single view of connectivity, security events, and traffic flows across cloud environments, data centres, branches, and remote users – giving security teams the access patterns and audit trail that zero trust and compliance frameworks require.

Consistent policy enforcement means applying the same security controls whether a user is in the office, at home, or connecting from a third-party site – and whether traffic is flowing between on-premises systems, cloud environments, or out to the internet. Integrated security that is built into the connectivity layer rather than layered on top of it is what makes this achievable at scale.

A managed operating model addresses the skills and complexity challenge directly. Defence in depth across a hybrid estate does not require in-house expertise across every security technology if the managed service is designed to provide that capability as part of the service.

Cloud Gateway delivers connectivity and security as an integrated platform, with the visibility, policy enforcement, and operational support that makes security models practical rather than aspirational. For more on how the platform supports regulated organisations across these requirements, see our Protect page and our platform page.

Head of Product Engineering

Ben Rees

Related Articles

Want to know more about how we work?