Are on-premise firewalls still required if I move to SASE?
It depends on the desired architecture. On-premise firewalls may remain to be used to simply ensure resilient access to SASE services through SD-WAN or may used for LAN segmentation in support of the wider security architecture. Typically requirements for on-premise firewall are greatly reduced which will save licensing costs and management overheads. In some cases only a router may be desirable.
Can SASE enforce identity-based access across multiple cloud providers?
Yes. SASE applies consistent access policies across AWS, Azure, Google Cloud, and other platforms, ensuring that authentication and authorisation are aligned with Zero Trust principles.
How are security policies managed and updated in a SASE environment?
Policies are centralised in a cloud management plane, allowing administrators to apply rules across all users, devices, sites and cloud workloads. Updates propagate automatically without manual configuration on individual endpoints.
How does SASE combine SD-WAN and security services?
SASE integrates networking (SD-WAN) with security controls such as SWG, CASB, FWaaS and ZTNA, delivering both connectivity and protection from a single cloud-managed platform. SD-WAN can also be achieved standalone without SASE to provide for resilient internet capabilities.
How does SASE improve performance for remote users compared to traditional VPNs?
SASE routes traffic through distributed cloud points of presence, reducing latency and improving connection reliability for remote and hybrid teams, while still enforcing security policies.
What is SASE and how does it improve network security?
Secure Access Service Edge (SASE) is a cloud-based security model that combines networking and security services into a single framework. It improves network security by delivering consistent access controls, threat protection, and monitoring regardless of user location. SASE is particularly effective for organisations with remote users, cloud applications, and hybrid infrastructure, as it reduces complexity while improving visibility and control.
What role does Cloud Access Security Broker (CASB) play in a SASE architecture?
CASB monitors and enforces security policies for cloud applications, ensuring data protection, compliance, and visibility into shadow IT activity within a SASE framework.
How does micro-segmentation work within a Zero Trust architecture?
Micro-segmentation divides the network into isolated zones, enforcing strict access control at the application and workload level. This limits lateral movement if an account or device is compromised. Its often fairly simple to further segment user to user communications limiting the “blast radius” in the event of a single user device being compromised.
Can Zero Trust integrate with existing Identity and Access Management (IAM) systems?
Yes. Zero Trust works alongside IAM solutions, enabling strong authentication, single sign-on and centralised policy enforcement without replacing current infrastructure. Its always worth checking that your ZTNA solution of choice supports your existing Identify solution.
How does Zero Trust handle multi-cloud and hybrid environments?
Zero Trust solutions can enforce identity-based policies consistently across on-premises, private and public cloud workloads. Continuous verification ensures secure access regardless of where resources reside. A ZTNA solution may be implemented centrally to do this or through the amalgamation of various ZTNA capable tools depending on the environment and requirements.
How does Zero Trust networking differ from traditional network security?
Traditional network security assumes trust once a user is inside the network, often relying on VPNs and perimeter defences. Zero Trust removes this assumption by continuously verifying users, devices and access requests. Access is granted based on identity, context and risk rather than location. This reduces the risk of credential misuse, limits lateral movement and provides stronger protection for cloud and remote access scenarios.
What is the difference between Zero Trust Network Access (ZTNA) and traditional VPNs?
ZTNA grants access based on identity and device posture rather than network location. Traditional VPNs adopt a "castle and moat” style whereby access is granted once to allow access to internal resources. A ZTNA approach on the other hand continuously reviews access rights, limits lateral movement and provides granular access control to applications rather than the full network.
What methods are used to continuously verify user and device trust?
Verification relies on multiple signals, including device posture, location, user behaviour, access history and threat intelligence. Policies adapt in real-time to reduce risk exposure. Many solutions can even utilise signals from other solutions such as anti-malware or threat intelligence platforms.
What role does a SOC play in secure networking?
A Security Operations Centre (SOC) provides continuous monitoring, detection, and response across network and cloud environments. In a secure networking strategy, a SOC ensures that access controls, segmentation, and configurations remain effective over time. Our purpose-built SOC, known as vSOC, helps identify suspicious behaviour, detect misconfigurations, and respond quickly to incidents, reducing both risk and dwell time.
What is secure networking and why is it important?
Secure networking is an approach to network security that combines modern access controls, monitoring, and architecture to protect users, data, and infrastructure across distributed environments. It is important because traditional perimeter-based security models are no longer effective in cloud-first and hybrid organisations. Secure networking reduces attack surfaces, improves visibility, and limits the impact of breaches by enforcing identity-based access and continuous verification across the network.
Can I speak with a current Data Connect customer before signing up?
Absolutely. While we prioritise our clients’ privacy and security, we’re happy to arrange a direct conversation between you and one of our existing customers. Just get in touch to set up a call.
Where is your Security Operations Centre (SOC) based?
Our SOC is based in the UK, where it's closest to our customers.